The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Controlling traffic inspection

Prev Next

You can control the incoming and outgoing network traffic that a Virtual Probe sends to the Sensors for inspection. Based on your requirement, you can configure which traffic needs to be inspected and which traffic need not be inspected.

After you install the Virtual Probe on a virtual machine, a file is available for configuring the traffic inspection.

  • On a Linux system, the file is opt/trellix/etc/nftables_excludes.json
  • On a Windows system, the file is C:\Program Files (x86)\TrellixVIPS\winpkfilter_excludes.json

The file specifies configuration rules in following JSON format:

{
    "table_config" : {
	…
    },
    "input" : [
	…
    ],
    "output" : [
	…
    ]
} 

Description of sections in the configuration file:

Section Description
table_config Defines the global parameters used for traffic inspection

Note

Do not change the values in this section.

input Contains inspection rules for the incoming traffic
output Contains inspection rules for the outgoing traffic

The following example shows the configuration to exclude the incoming iSCSI traffic from inspection.

{
    "action": "bypass",
    "direction": "incoming",
    "network_protocol": "ipv4",
    "transport_protocol": "tcp",
    "src_address": "192.168.200.0",
    "src_mask": 24,
    "src_first_port": 3260,
    "src_last_port": 3260,
    "comment": "Exclude incoming iSCSI traffic from 192.168.200.0 from interception"
} 

The following example shows the configuration to exclude the incoming iSCSI traffic from inspection.

Field Description
action Action to be taken for the network traffic.

Set the value to bypass to exclude the traffic from being sent to the Sensor for inspection.

direction Direction of the network traffic.
  • Set the value to incoming to apply the rule for incoming traffic.
  • Set the value to outbound to apply the rule for outgoing traffic.

Note

  • Specify rules for the inbound traffic in the input section.
  • Specify rules for the outbound traffic in the output section.
network_protocol Network protocol for which the rule applies. The supported value is ipv4.
transport_protocol Transport protocol for which the rule applies. The supported values are udp and tcp.
src_address (optional) IP address of the system from which the traffic originates.

This field is optional. If specified, the value should be either a host or network address specified in IPv4 dotted notation. For example, 10.1.1.0 for 192.168.232.19.

src_mask Number of significant bits set in the mask.

If src_address is a host address, set the value to 32.

src_first_port (optional) Starting port number from the range of ports for which the network traffic should be inspected.

To specify a single port, set both src_first_port and src_last_port to the same value. Neither value can be 0.

The value of src_first_port should be less than the value of src_last_port.

src_last_port (optional) Ending port number from the range of ports for which the network traffic should be inspected.

Note

Similar to the src_* fields, you can specify the following fields to control traffic for the destination addresses:

  • dest_address
  • dest_mask
  • dest_first_port
  • dest_last_port
comment A brief description of the rule.

Note

The value should be string and cannot have embedded newline characters.

Note

Both the input and output sections contain a rule that has the action field set to intercept. Do not edit this rule. This rule should always be the last rule in both the input and output sections. There are several rules in the file by default. Modifying or removing the default rules may cause instability in the system. Add new rules before the default rules.

The following is a sample nftables_excludes.json file:

{
        "table_config" : {
        "table_type" : "inet",
        "table_name" : "mcafee",
        "input_type" : "filter",
        "input_hook" : "input",
        "input_policy" : "accept",
        "output_type" : "filter",
        "output_hook" : "output",
        "output_policy" : "accept"
    },
    "input" : [
        {
            "action": "bypass",
            "direction" : "incoming",
            "transport_protocol" : "tcp",
            "dest_first_port" : 10004,
            "dest_last_port" : 10004,
            "flags" : 16,
            "comment" : "Exclude incoming Statistics requests"
        },
        {
            "action": "bypass",
            "direction" : "incoming",
            "transport_protocol" : "tcp",
            "dest_first_port" : 5901,
            "dest_last_port" : 5901,
            "flags" : 16,
            "comment" : "Exclude incoming VNC traffic from interception"
        },
        {
            "action": "intercept",
            "first_queue_number" : 1,
            "last_queue_number" : 1,
            "direction" : "incoming",
            "flags" : 16,
            "comment" : "Queue everything else that's incoming"
        }
    ],
    "output" : [
        {
            "action": "bypass",
            "direction" : "outbound",
            "transport_protocol" : "tcp",
            "src_first_port" : 10004,
            "src_last_port" : 10004,
            "flags" : 16,
            "comment" : "Exclude outgoing statistics traffic from interception"
        },
        {
            "action": "bypass",
            "direction" : "outbound",
            "transport_protocol" : "tcp",
            "src_first_port" : 5901,
            "src_last_port" : 5901,
            "flags" : 16,
            "comment" : "Exclude outgoing VNC traffic from interception"
        },
        {
            "action": "bypass",
            "direction" : "outbound",
            "transport_protocol" : "tcp",
            "dest_first_port" : 21,
            "dest_last_port" : 21,
            "flags" : 16,
            "comment" : "Bypass outgoing ftp"
        },
        {
            "action": "intercept",
            "first_queue_number" : 1,
            "last_queue_number" : 1,
            "direction" : "outbound",
            "flags" : 16,
            "comment" : "Queue everything else that's outbound"
        }
    ]
}