The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add a rule object

Prev Next

You can create custom rule objects to use within the Firewall and QoS policies, Ignore Rules, SSL Decryption Exclusions, Quarantine Zones, and NTBA Communication Rules.

Following table lists the maximum count of rule object items (Rule Members) that can be added under each rule object type:

Rule Object type

Rule Members (Maximum count)

Host DNS Name

5000

IPv4 Address Range

20000

IPv4 Endpoint

140000

IPv4 Network

140000

IPv6 Address Range

20000

IPv6 Endpoint

140000

IPv6 Network

140000

Application Group, Application on Custom Port, Finite Time Period, Network Group, Network Group for Ignore Rules, Recurring Time Period, Recurring Time Period Group, Service, Service Group, Service Range

10

Note

The rule member count specified in the above table is applicable only for Firewall policy. For QoS policy, Ignore Rules, SSL Decryption Exclusions, and NTBA Communication Rules, the maximum rule member count applicable for each rule object type is 10. For Quarantine Zones, only one rule member should be assigned per rule object.

Note

If you are using a Manager running on or before version 10.1.7.55 and a Sensor running on or before 10.1.5.153, the maximum count of rule members you can add under each rule object type is 10.

Note

The above rule object count specified for IPv4/IPv6 based rule objects is also applicable for Central Managers. Central Managers running on or before version 10.1.7.55, however, support only 10 rule members per each rule object.

Note

If you are using a Central Manager, do not add more than 10 entries in the Central Manager Rule Objects which are associated with QoS policies, Ignore Rules, SSL Decryption Exclusions, Quarantine Zones or Quarantine Exceptions in a Manager.

Steps:

  1. Click the Policy tab.

  2. From the Domain drop-down list, select the domain you want to work in.

  3. Select Intrusion Prevention → Objects → Rule Objects.

    Rule Objects for the selected admin domain are listed.

  4. Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png. This displays two tabs, namely the Properties tab and the Rule Members tab.

    Note

    An additional Adaptive (Ignore Rules only) tab appears while adding IPv4 and IPv6 based rule objects.

    Selecting Criticality for each of your assets
    Selecting Criticality for each of your assets


    The following table describes the options in the Properties tab that are common to all rule objects.

    Option

    Definition

    Name

    Enter a unique name to easily identify the rule object.

    Description

    Enter the description for the rule object.

    Type

    From the drop-down list, select the type of rule object you want to create.

    For information on a specific object type, refer to the corresponding sub-section.

    Criticality

    [Optional] If you have chosen rule object type as IPv4 Endpoint or IPv6 Endpoint, you can specify the Criticality of that host by selecting Low, Medium or High from the drop-down list. By default, criticality is Low. Determining criticality of a host enables you to categorize all IPv4 Endpoint and IPv6 Endpoint addresses based on their importance to your organization.

    Owner

    Indicates the admin domain to which a rule object belongs. All the default rule objects belong to the root admin domain.

    Visibility

    From the drop-down list, select the option for the visibility level of the rule object. The available options are Owner and child domains and Owner domain only.

    Editable Here

    Yes indicates that the rule object is a custom rule object belonging to the current admin domain. If it is No, you cannot edit the rule object because it is a default rule object or a custom rule object defined at a parent admin domain.

    Last Updated

    Displays the date and time when a rule object was last updated

    Last Updated By

    Displays the user who modified a rule object

    Once you assign criticality to a rule object and an alert involving it is raised, the criticality that you assigned shows up under specific columns in Attack Log. These columns are labeled Attacker Risk and Target Risk. Attacker Hostname and Target Hostname displays the names of the rule object.

    Display of attacker risk
    Display of attacker risk


  5. Enter the rule object options based on rule object you have selected in the Type drop-down list. For information on the subsequent steps to add a rule object, refer to the corresponding sub-sections.