The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure the Firewall allowed and blocked traffic logging for managed systems

Prev Next

Follow these steps to enable Firewall allowed or blocked traffic logging in managed systems.

  1. Log on to ePO - On-prem as an administrator.

  2. Go to Menu > Policy Catalog > Endpoint Security Firewall.

  3. In the Endpoint Security Firewall page, click Policy Category > Options > My Default.

    Click Show Advanced on the top left corner of the page.

  4. In the Tuning Options section, enable these options:

    • Enable Log all allowed traffic

    By Default, Log all blocked traffic is enabled. Save this policy.

  5. Navigate to System Tree, and click on the Assigned Policies tab and in the Product section, select Endpoint Security Firewall.

  6. Select Endpoint Security Firewall from the Product list, then click Edit Assignment.

    In the next page, click Break inheritance and assign the policy > My Default > Assigned Policy and select the Save option.

  7. In the System Tree page, select the system to assign the policy. Click Wake Up Agents, and select Force complete policy and task update and select OK.

Endpoint Security Firewall Policy by default gets enforced on the managed system.