The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring non-standard ports

Prev Next

When the destination IP address is listening for a protocol on a port that is not standard, that port is called a non-standard port. For example, HTTP by default uses port 80 or 8080; therefore, a Sensor reading a packet with port 80 or 8080 attempts to decode that traffic as HTTP traffic. However, if a user is running an HTTP server on port 2560, it is recommended that the user add this non-standard port parameter. This protects the system from experiencing any false positives from unrecognized port-protocol communication and having malicious activity sent through a "back door."

Note

This note is relevant only if you are using the default Service rule objects for features such as Quarantine, Firewall Access Rules, and QoS. The Sensor considers all the standard ports as well as non-standard port numbers that you have defined in the Non-Standard Ports page when detecting a protocol. Port numbers are irrelevant if you are using the Application Rule Objects to detect protocols.

You can configure the non-standard ports for the admin domain. These port numbers are inherited by all the Sensors in the admin domain as well as by Sensor ports allocated to a child domain. At the Sensor level, you can append more port numbers to the inherited list. However, you cannot edit or delete the inherited list at the Sensor level. You can define non-standard port numbers at the Sensor level even if you have not configured any at the domain level.