The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure stateless access rules

Prev Next

Prerequisites:

  • You have created an advanced or classic Firewall policy to which you want to add stateless access rules.

  • You have created the rule objects, especially the service or service group rule objects, required to create your stateless access rules.

Create stateless access rules to allow or block certain traffic without deeper inspection.

  1. Select Intrusion Prevention → Policy Types → Firewall.

  2. Double-click the Firewall policy in which you want to add the stateless rules.

  3. In the Firewall window, click Access Rules.

  4. Select the top-most rule and click GUID-002605CA-A671-41C2-AC91-CCE74A6CB27E-low.png.

    Note

    It is recommended to have the stateless rules above any of the other rules.

  5. Optionally, double-click the Description field to describe the rule.

  6. Select the appropriate values for Source Address, Source User, Destination Address, Effective Time, and Direction.

  7. For Application, select the required Service and Service Group rule objects.

  8. In the Response column, select Stateless Drop or Stateless Ignore.

  9. Click Save.

  10. Update the Sensor configuration for the rule to be enforced.

    You cannot log the packets that matched a stateless access rule. However, you can view the number of packets dropped by using the show inlinepktdropstats <monitoring port> command on the Sensor CLI. You cannot view the number of packets that were ignored according to stateless access rules.

    Count of packets dropped according to stateless access rules
    Count of packets dropped according to stateless access rules