The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Considerations for access rules

Prev Next

The following are the considerations for access rules:

  • You can create user-based access rules only in advanced Firewall policies.

  • You integrate the Manager only with one instance of Trellix Logon Collector. Integration with a redundant Trellix Logon Collector setup is not supported.

  • You cannot add, modify, or delete a user name or user group in the Manager.

  • You can specify only user and user group as the criteria. No other AD properties are supported.

  • Only IPv4 hosts are supported. A rule will not match if the user logs on from an IPv6 host.

  • The following are the limits for user data:

    • Up to 100,000 IP-to-user mappings

    • Up to 75,000 user names

    • Up to 10,000 groups for NS-Series and Virtual IPS Sensors

  • Maximum user-based rule objects that you can use in the Firewall policies per Sensor model is as follows:

    Sensor

    Maximum user-based rule objects

    NS9600 stack (2-node) - 120 Gbps throughput

    7,000

    NS9600 standalone - 60 Gbps throughput

    7,000

    NS9600 standalone - 40 Gbps throughput

    6,000

    NS9600 standalone - 20 Gbps throughput

    5,000

    NS9500 stack - 100 Gbps throughput

    5,000

    NS9500 stack - 60 Gbps throughput

    5,000

    NS9500 stack - 40 Gbps throughput

    5,000

    NS9500 standalone - 30 Gbps throughput

    5,000

    NS9500 standalone - 20 Gbps throughput

    5,000

    NS9500 standalone - 10 Gbps throughput

    2,500

    NS9300

    5,000

    NS9200

    5,000

    NS9100

    2,500

    NS7600 - 20 Gbps throughput

    1,250

    NS7600 - 15 Gbps throughput

    1,250

    NS7600 - 10 Gbps throughput

    1,250

    NS7600 - 5 Gbps throughput

    1,250

    NS7500 - 7.5 Gbps throughput

    1,250

    NS7500 - 5 Gbps throughput

    1,250

    NS7500 - 3 Gbps throughput

    1,250

    NS7350

    1,250

    NS7250

    1,000

    NS7150

    1,000

    NS7300

    1,250

    NS7200

    1,000

    NS7100

    1,000

    NS5200

    750

    NS5100

    750

    NS3600 - 5 Gbps throughput

    1,250

    NS3600 - 3 Gbps throughput

    1,250

    NS3600 - 1 Gbps throughput

    1,250

    NS3500

    500

    NS3200/NS3100

    500

    IPS-VM600

    750

    IPS-VM5000

    750

  • In a Firewall access rule or QoS rule, you cannot specify an IPv4-based rule object for one field and IPv6-based rule objects for other applicable fields. For example, if you select an IPv6-based rule object in the Source Address field, then you cannot specify IPv4-based rule objects for Destination Address or Source User fields. For this example, you can specify only an IPv6-based rule object or other as the value for Destination Address and any for Source User. Recall that User and User Group rule objects are considered as IPv4-based rule objects because Trellix Logon Collector 3.0.11 does not collect user information from IPv6 hosts. Similarly, Country and Host DNS Name are also IPv4-based rule objects.

  • User log off is not monitored.

  • User or user group deletion is not monitored.

  • When you add new users in the AD, modify user groups, or delete user groups you must run the TLC Refresh Users server task manually in Trellix Logon Collector. Then the current data from the AD is available in the Manager.

  • Guest Portal user timeout, by default, is 8 hours.