The following are the considerations for access rules:
You can create user-based access rules only in advanced Firewall policies.
You integrate the Manager only with one instance of Trellix Logon Collector. Integration with a redundant Trellix Logon Collector setup is not supported.
You cannot add, modify, or delete a user name or user group in the Manager.
You can specify only user and user group as the criteria. No other AD properties are supported.
Only IPv4 hosts are supported. A rule will not match if the user logs on from an IPv6 host.
The following are the limits for user data:
Up to 100,000 IP-to-user mappings
Up to 75,000 user names
Up to 10,000 groups for NS-Series and Virtual IPS Sensors
Maximum user-based rule objects that you can use in the Firewall policies per Sensor model is as follows:
Sensor
Maximum user-based rule objects
NS9600 stack (2-node) - 120 Gbps throughput
7,000
NS9600 standalone - 60 Gbps throughput
7,000
NS9600 standalone - 40 Gbps throughput
6,000
NS9600 standalone - 20 Gbps throughput
5,000
NS9500 stack - 100 Gbps throughput
5,000
NS9500 stack - 60 Gbps throughput
5,000
NS9500 stack - 40 Gbps throughput
5,000
NS9500 standalone - 30 Gbps throughput
5,000
NS9500 standalone - 20 Gbps throughput
5,000
NS9500 standalone - 10 Gbps throughput
2,500
NS9300
5,000
NS9200
5,000
NS9100
2,500
NS7600 - 20 Gbps throughput
1,250
NS7600 - 15 Gbps throughput
1,250
NS7600 - 10 Gbps throughput
1,250
NS7600 - 5 Gbps throughput
1,250
NS7500 - 7.5 Gbps throughput
1,250
NS7500 - 5 Gbps throughput
1,250
NS7500 - 3 Gbps throughput
1,250
NS7350
1,250
NS7250
1,000
NS7150
1,000
NS7300
1,250
NS7200
1,000
NS7100
1,000
NS5200
750
NS5100
750
NS3600 - 5 Gbps throughput
1,250
NS3600 - 3 Gbps throughput
1,250
NS3600 - 1 Gbps throughput
1,250
NS3500
500
NS3200/NS3100
500
IPS-VM600
750
IPS-VM5000
750
In a Firewall access rule or QoS rule, you cannot specify an IPv4-based rule object for one field and IPv6-based rule objects for other applicable fields. For example, if you select an IPv6-based rule object in the Source Address field, then you cannot specify IPv4-based rule objects for Destination Address or Source User fields. For this example, you can specify only an IPv6-based rule object or other as the value for Destination Address and any for Source User. Recall that User and User Group rule objects are considered as IPv4-based rule objects because Trellix Logon Collector 3.0.11 does not collect user information from IPv6 hosts. Similarly, Country and Host DNS Name are also IPv4-based rule objects.
User log off is not monitored.
User or user group deletion is not monitored.
When you add new users in the AD, modify user groups, or delete user groups you must run the TLC Refresh Users server task manually in Trellix Logon Collector. Then the current data from the AD is available in the Manager.
Guest Portal user timeout, by default, is 8 hours.