The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add endpoints to quarantine

Prev Next

You can quarantine endpoints to block all the traffic originating from the specified IP address seen on the selected device for the selected time. While adding an endpoint to quarantine, you can also re-direct the quarantined endpoint to the configured remediation portal.

  1. Click the Analysis tab and select the domain from the Domain drop-down list.

  2. Select Quarantine. The Quarantine page is displayed.

  3. Click Add. The Add to Quarantine pop-up is displayed.

    Add to Quarantine
    Add to Quarantine


  4. Update the following fields:

    Option

    Definition

    IP Address

    Enter the IP address of the endpoint.

    Device

    Select the specific device of the endpoint whose traffic originating from the IP address you want to block.

    Quarantine Duration

    Select the quarantine duration from the drop-down list.

    Remediate

    Select the checkbox to redirect the configured endpoint to the configured remediation portal.

    Note

    You can configure the remediation portal settings in Devices → Global → IPS Device Settings → Quarantine → Remediation Portal.

    Remediation cannot be configured for IPv6 address. The checkbox and the information icon for remediation is not displayed if you enter an IPv6 address in the IP Address field.

  5. Click Quarantine. The endpoint is added and displayed in the Quarantine page.