The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert policy exception actions

Prev Next

The following table describes the actions you can specify in an alert policy exception:

Action

Description

Block

Forces blocking of traffic through the specified interfaces, destination IP addresses, and source IP addresses that matches the specified rule, vulnerability, or attack category.

Note

This action is available when the appliance is deployed inline and for interfaces configured for inline blocking mode.

UnBlock

Disables blocking of traffic through the specified interfaces, destination IP addresses, and source IP addresses that matches the specified rule, vulnerability, or attack category.

Note

This action is available when the appliance is deployed inline and for interfaces configured for inline blocking mode.

Suppress

Suppresses notifications and event logging for traffic through the specified interfaces, destination IP addresses, and source IP addresses that matches the specified rule, vulnerability, or attack category.

Matched traffic is handled according to the blocking action specified in the rule definitions.

Suppress & Unblock

Suppresses notifications and event logging and also disables blocking of traffic through the specified interfaces, destination IP addresses, and source IP addresses that matches the specified rule, vulnerability, or attack category.

Note

This action is available when the appliance is deployed inline and for interfaces configured for inline blocking mode.

Default

Honors the action specified by the matched rules for traffic through the specified interfaces, destination IP addresses, and source IP addresses.