The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create timed groups on a client system

Prev Next

You can create Firewall timed groups to restrict Internet access until a client system connects over a VPN.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Firewall on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Firewall on the Settings page.

  3. Create a Firewall group with default settings that allow Internet connectivity. For example, allow port 80 HTTP traffic.

  4. In the Schedule section, select how to enable the group.

    • Enable schedule — Specifies a start and end time for the group to be enabled.

    • Disable schedule and enable the group from the Trellix system tray icon — Allows users to enable the group from the Trellix system tray icon and keeps the group enabled for the specified number of minutes.

      If you allow users to manage the timed group, you can optionally require that they provide a justification before enabling the group.

  5. Click OK to save your changes.

  6. Create a connection isolation group that matches the VPN network to allow needed traffic.

    Tip

    Best practice: To allow outbound traffic from only the connection isolation group on the client system, don't place any Firewall rules below this group.

  7. Click Apply.