The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Firewall rules examples

Prev Next

Refer to these examples when creating firewall rules.

Create a rule to allow DHCP outgoing on UDP local port 68 to remote port 67

To create a firewall rule that allows you to get an IP address on an interface, we recommend creating two rules. First create a rule to allow DHCP outgoing on UDP local port 68 and remote port 67, then create a rule to allow DNS queries.

  • Rule Name — Type a name for the rule

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Network Protocol — Not applicable

  • Transport Protocol — Select Protocol

  • Select UDP, Local, then type the Port No as 68

  • Select UDP, Remote, then type the Port No as 67



Create a rule to allow DNS queries
  • Rule Name — Type a name for the rule

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Network Protocol — Not applicable

  • Transport Protocol — Select Protocol

  • Select UDP, Remote, then type the Port No as 53



Create a rule to allow access to websites
  • Rule Name — Type a name for the rule

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Network Protocol — Not applicable.

  • Transport Protocol — Select Protocol

  • Select TCP, Remote, then type the Port No as 80



Allow specific remote IP address and port access
  • Rule Name — Type a name for the rule

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • In Network Protocol, select Remote | Subnet, then type the Subnet Mask value

  • Transport Protocol — Select Protocol

  • Select TCP, Remote, then type the Port No

Tip

You can type a single port number, or series of port numbers using a comma, or a range of ports using a hyphen.



Recommended firewall rules

In addition to the default firewall rules, we recommend that you configure these rules:

  • Allow bi-directional NTP port 123 to 123

  • Allow bi-directional NetBIOS name service port 137 to 137

  • Allow outgoing FTP client port 1024-65535 to 21

  • Allow outgoing for POP3, IMAP, SMTP

  • Allow outgoing for RDP

  • Allow outgoing for Idap

  • Allow bi-directional for AFP/SMB, if you are using file sharing