The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Prepare your network

Prev Next

Before installing Trellix DLP Discover software, you must configure the network, define administrators, and deploy the needed software.

  1. Configure any intermediary firewalls or policy-enforcing devices to allow the specified ports for network communication.

    All listed protocols use TCP only, unless noted otherwise. For information about ports that communicate with ePO - On-prem , see article 000006527.

    Trellix DLP Discover default ports

    Port, protocol

    Use

    • 137, 138, 139 — NetBIOS

    • 445 — SMB

    CIFS scans

    • 80 — HTTP

    • 443 — SSL

    Box and SharePoint scans

    SharePoint servers might be configured to use non-standard HTTP or SSL ports. If needed, configure firewalls to allow the non-standard ports.

    53 — DNS (UDP)

    DNS queries

    • 1801 — TCP

    • 135, 2101*, 2103*, 2105 — RPC

    • 1801, 3527 — UDP

    * Indicates that the port numbers might be incremented by 11 depending on the available ports at initialization.

    For more information, see Microsoft KB article 178517.

    Note

    MSMQ uses these ports only for internal communication. Nothing needs to be opened on the network firewall, but the local or host firewall needs to allow these communications.

    Microsoft Message Queuing (MSMQ)

    1433

    Microsoft SQL

    1521

    Oracle

    3306

    MySQL

    50000

    DB2



  2. Create users and groups for administrative assignments.

  3. Deploy Trellix Agent to the servers.

  4. Install Microsoft Internet Information Services (IIS) on the DLP Servers.