The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding Rules to a Network Whitelist Using the CLI

Prev Next

Use the CLI commands in this procedure to add an IP address or subnet by configuring a policy configuration rule to a network whitelist. You enter each rule separately. You can add up to 256 network whitelist rules.

Note

After you add a rule to a network whitelist, use the policymgr refresh-policy command in the CLI configuration mode to refresh the policy configuration.

To add a rule to a network whitelist:
  1. Go to CLI configuration mode.

    hostname > enable hostname # configure terminal

  2. To add the policy configuration for the destination IP address:

    hostname (config) # policymgr network dst <IPAddress> <maskLength>{allow | interface <interfaceType> | vlan <vlanID}

    • <IPAddress> is the destination IP address that matches the defined IP address or mask.

    • <maskLength> is the valid Classless Inter-Domain Routing (CIDR) mask for the host prefix.

    • allow is the policy action to allow traffic from the specified host, network, or VLAN.

    • interface <interfaceName> is the name of the interface to apply the network whitelist.

    • vlan <vlanID> is the VLAN identification number to add to the network whitelist. The default value is "ALL". The range is from 1 to 4094.

  3. To add the policy configuration for the source IP address:

    hostname (config) # policymgr network src <IPAddress> <maskLength>{allow | interface <interfaceType> | vlan <vlanID}

    • <IPAddress> is the source IP address that matches the defined IP address or mask.

    • <maskLength> is the valid CIDR mask for the host prefix.

    • allow
      is the policy action to allow traffic from the specified host, network, or VLAN.
    • interface <interfaceName> is the name of the interface to apply the network whitelist.

    • vlan <vlanID> is the VLAN identification number to add to the network whitelist. The default value is "ALL". The range is from 1 to 4094.

  4. To add the policy configuration for the host IP address:

    • <IPAddress> is the source IP address or destination IP address that matches the defined IP address or mask.

    • <maskLength> is the valid CIDR mask for the host prefix.

    • allow
      is the policy action to allow traffic from the specified host, network, or VLAN.
    • interface <interfaceName> is the name of the interface to apply the network whitelist.

    • vlan <vlanID> is the VLAN identification number to add to the network whitelist. The default value is "ALL". The range is from 1 to 4094.

    • monitor
      is the policy action to monitor and allow traffic from the specified host, network, or VLAN.
  5. Repeat the previous step for each additional rule you want to add.

  6. Save your changes.

    hostname (config) # write memory

  7. Refresh the policy configuration.

    hostname (config) # policymgr refresh-policy

  8. Verify the configuration for a network whitelist.

    hostname (config) # show policymgr networks

Example

This example shows how to add the policy configuration for the destination IP address mask length to a network whitelist.

hostname (config) # policymgr network dst 23.1.1.2/32 interface ALL allowhostname (config) # policymgr refresh-policy

This example shows how to add the policy configuration for the source IP address and mask length to a network whitelist.

hostname (config) # policymgr network src 23.1.1.1/32 interface ALL allow hostname (config) # policymgr refresh-policy

This example shows how to add the policy configuration for the host IP address and mask length to a network whitelist.

hostname (config) # policymgr network host 1.1.1.1/32 interface ALL allow

hostname (config) # policymgr refresh-policy

hostname (config) # show policymgr networks

Whitelist Entries: 3 / 256

Whitelist:
VLAN    INTF    MONITOR    IP            MODE(source|destination|host)
ALL     ALL     no         1.1.1.1/32    host
ALL     ALL     n/a        23.1.1.1/32   src 
ALL     ALL     n/a        23.1.1.2/32   dst