The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure Endpoint Reputation for an admin domain

Prev Next

Prerequisite: If the Manager is not integrated with Trellix GTI Lookup, you can see the following message: Please enable sending of Alert Data Details on the Participation page to make integration with GTI Lookup available. Select Integration → Global Threat Intelligence to enable the integration.

If you configure Endpoint Reputation at an admin domain, you can inherit these settings for the interfaces of the Sensors in this domain. You can also customize these settings for specific interfaces.

  1. In the Manager, go to Policy → <Admin_Domain_Name> → Intrusion Prevention → Policy Types → Inspection Options.

    The Inspection Options page is displayed.

    GUID-778F8939-C468-4C97-B3CC-8A35B15B82F9-low.png
  2. Double-click a policy for which you want to configure Endpoint Reputation.

    To add a new policy, click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png. Using either action, a page with the policy details appears with the Properties tab selected.

  3. Update the following fields as applicable:

    Option

    Definition

    Name

    Enter a unique name to easily identify the policy.

    Description

    Optionally describe the policy for other users to identify its purpose.

    Owner Domain

    Displays the admin domain to which the policy belongs

    Visibility

    When selected, makes the policy available to the corresponding child admin domains. However, the policy cannot be edited or deleted from the child admin domains.

    From the drop-down list, select the option for the visibility level of the rule object.

    Available options are Owner and child domains and Owner domain only.

    Editable here

    The status Yes indicates that the policy is owned by the current admin domain. This field is uneditable.

    Statistics

    Lasted Updated

    Displays the time stamp when the policy was last modified. This field is uneditable.

    Last Updated By

    Displays the user who last modified the policy. This field is uneditable.

    Assignments

    Indicates the number of inline ports to which the policy is assigned

    Prompt for assignment after save

    If you deselect this option you can save the policy now and assign it to the Sensor resources as explained in the following section. If you select this option, the Assignments window opens automatically when you save the policy and you can assign the policy to the required Sensor resources.

    Cancel

    Reverts to the last saved configuration

  4. Click Next.

    The screen shifts to the Inspection Options tab. By default, the Traffic Inspection tab is selected.

  5. Click the GTI Reputation Services tab. Endpoint Reputation Analysis is used to influence SmartBlocking decisions, create connection limiting rules, or to take action when a connection to or from a high-risk endpoint is seen on your network.

    GUID-B38DB446-4E4D-4168-93FC-0B4CC226636E-low.png

    On the Endpoint tab, configure the following fields:

    Option

    Definition

    Endpoint Reputation Analysis

    Select any of the following options:

    • Disabled

    • Inbound only

    • Outbound only

    • Inbound and Outbound

    Use Endpoint Reputation to Influence SmartBlocking

    Select Enabled to enable endpoint reputation to Influence SmartBlocking. Select Disabled to disable the option.

    Exclude Internal Endpoints from GTI Lookups

    Select Enabled to exclude internal endpoints from Trellix GTI Lookups. Select Disabled to disable the option.

    CIDRs Excluded from Endpoint Reputation Lookups

    New CIDR

    Enter the new CIDR and click Add to add to the CIDR list to be excluded.

    Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the CIDR from the list.

    Note

    The CIDR exclusion list is shared by Advanced Callback Detection and Endpoint Reputation Analysis .

    Protocols Excluded from Endpoint Reputation Lookups

    In the drop-down list, select the protocol to be excluded from Trellix GTI Lookups and click Add. The selected protocol is displayed in the field below.

    Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the protocol from the list.

    Prompt for assignment after save

    When selected, you are automatically prompted to select the Sensor resources to which you want to assign the policy.

  6. Click Save to confirm your settings.

    Clicking Cancel reverts to the last saved configuration.