The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring domains for the predefined Trellix whitelist category

Prev Next

The following topics explain how to configure the domains for the predefined Trellix whitelist category using the appliance Web UI:

A predefined Trellix exclusion list is used to exclude the domains from decryption. For example, some websites require mutual authentication between the client and server. The websites for mutual authentication can be included in the predefined exclusion list. If applications pin a public key to websites that they are connected to, these websites can also be included in the predefined exclusion list. The Network Security appliance receives a list of updated domains from the DTI Cloud through security content updates. By default, HTTPS traffic is not decrypted if it matches a particular domain in the predefined exclusion list. When the predefined Trellix exclusion option is disabled, the appliance will not exclude the domains in the predefined exclusion list from decryption.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • Validate DTI access on the Network Security appliance by using the show fenet status command. For details about how to validate DTI access, see the Network Security System Administration Guide.

  • A CONTENT_UPDATES license for security content updates