The predefined firewall groups include needed rules, such as core networking rules to allow Trellix applications.
Note
If a firewall group has no rules defined, it appears in gray to indicate that the group is empty.
Firewall group | Description |
|---|---|
Trellix core networking | Contains the core networking rules provided by Trellix and includes rules to allow Trellix applications and DNS.
|
Admin-defined | Contains rules defined by the administrator at the management server. This group appears on the Trellix Endpoint Security (ENS) Client only if the client system is managed by Trellix ePO - On-prem. In this case, the group displays Enabled even if it contains no rules.
|
User-defined | Contains rules defined on the Trellix Endpoint Security (ENS) Client. This group displays Enabled even if it contains no rules. Because these rules are created on the client system, these rules might be overwritten when the policy is enforced, depending on policy settings. |
Adaptive | Contains client exception rules that are created automatically when the system is in Adaptive mode. This group displays Enabled even if Adaptive mode is not enabled and the group contains no rules. Once Adaptive mode is enabled, the group is populated with automatically generated rules. Because these rules are created on the client system, these rules might be overwritten when the policy is enforced, depending on policy settings. |
Default | Contains default rules provided by Trellix.
|