The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Considerations for Quarantine rule creation

Prev Next

Quarantine rule creation exceptions

Review the considerations in this section before you create the rules for Quarantine.

Quarantine actions are ignored even if these are enabled at the policy and port level in the following scenarios:

  • The host IP has been added or if it is part of the exclusion list that was configured from the Manager. The exclusion list can be configured as an IP CIDR or a specific IP address. If the source IP generating the attack is a part of the quarantine exception list, this indicates that the host is trusted and hence would not get quarantined.

  • An ignore rule has been configured, which prevents the alert from being raised for a detected attack. If the ignore rule sorts the alert, the Quarantine action is not executed for this attack, and the source IP is not quarantined.

Quarantine access rules and Firewall access rules

Quarantine access rules are configured as part of Quarantine Zones. These rules regulate traffic from a quarantined host. Firewall access rules are configured to regulate traffic in inline mode from all hosts.

Review the following to understand the interaction between Quarantine and Firewall access rules:

  • Quarantine drop gets precedence over a Firewall permit action.

  • Firewall drop gets precedence over the Quarantine permit action.

  • Firewall drop over-rides even if the host is in the quarantine exception list.

    Note

    Quarantine exception list only indicates that the hosts are excluded from being quarantined, but do not prevent them from being subjected to Firewall access rules.

Quarantine with ignore rules and exclusion

  • When ignore rule is enabled, no Quarantine action occurs, that is, the host is not quarantined.

  • If an IP address is a part of the quarantine exception list, the host is not quarantined, but traffic is still subjected to Firewall access rules.