The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Predefined firewall rule groups on a client system

Prev Next

The predefined firewall groups include needed rules, such as core networking rules to allow Trellix applications.

Note

If a firewall group has no rules defined, it appears in gray to indicate that the group is empty.

Firewall group

Description

Trellix core networking

Contains the core networking rules provided by Trellix and includes rules to allow Trellix applications and DNS.

Note

You can't change or delete rules in this rule group. If you need to, you can create a duplicate of the group, make changes to the rules, then select the Disable Trellix core networking rules option in the Firewall Options policy to disable the group. But, this might disrupt network communications on the client system.

Admin-defined

Contains rules defined by the administrator at the management server.

This group appears on the Trellix Endpoint Security (ENS) Client only if the client system is managed by ePO - On-prem. In this case, the group displays Enabled even if it contains no rules.

Note

These rules can't be changed or deleted on the Trellix Endpoint Security (ENS) Client.

User-defined

Contains rules defined on the Trellix Endpoint Security (ENS) Client.

This group displays Enabled even if it contains no rules.

Because these rules are created on the client system, these rules might be overwritten when the policy is enforced, depending on policy settings.

Adaptive

Contains client exception rules that are created automatically when the system is in Adaptive mode.

This group displays Enabled even if Adaptive mode is not enabled and the group contains no rules. Once Adaptive mode is enabled, the group is populated with automatically generated rules.

Because these rules are created on the client system, these rules might be overwritten when the policy is enforced, depending on policy settings.

Default

Contains default rules provided by Trellix.

Note

These rules can't be changed or deleted.