The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add a proxy rule

Prev Next

To add a proxy rule, perform the following steps:

  1. Select Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.

  2. In the Inbound tab, select Inbound Proxy Rules tab.

  3. Click GUID-002605CA-A671-41C2-AC91-CCE74A6CB27E-low.png to add a rule above the selected rule.

    Click GUID-01632DAF-E14F-4696-93EF-18654509F3B8-low.png to add a rule below the selected rule.

    The rule details pane opens.

  4. Enter the name of the rule.

  5. Enter the IPv4 or IPv6 CIDR of the web server you wish to protect.

  6. Enter the comment for the rule.

  7. Select the web server certificate from the drop down in the Web Server Certificates pane.

  8. Click Add.

  9. (Optional) Click Set as default to set the selected web server certificate as default certificate.

    The Installed On pane displays the Sensor on which the web server certificate is saved on.

    Important

    From 11.1 Update 8 release, once Inbound Proxy is enabled, all Inbound traffic will be decrypted; a proxy rule with a specific web server IP is not required for proxy decryption.

    Note

    If you do not specifically set a default, the first certificate in the list is set as the default certificate.

    Note

    If the server supports Server Name Indication (SNI), multiple certificates must be available in the Sensor.

  10. Click Save to save the rule order details.