The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a protected group in the Manager with traffic source as Traffic Mirroring

Prev Next

To protect VMs, each VM needs to be part of a protected VM group. The definition of the group contains the following:

Prerequisites:

  • VM membership by subnets they belong to.

  • Cluster that should inspect traffic from these VMs.

  • The security policy that applies to these VMs.

To create a Protected Group, perform the following steps:

  1. Login to the Trellix IPS Manager instance.

  2. Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Manager.

  3. Select the vIPS Protected Groups tab.

    vIPS Protected Groups
    vIPS Protected Groups


    Description of columns in the vIPS Protected Group tab.

    Options and descriptions in the vIPS Protected Group tab

    Option

    Description

    Protected Group

    • Name — Name of the Protected Group.

      Note

      The minimum length for the name is 1 character. The name can contain up to 50 alphanumeric (upper or lower case letters) characters, including hyphens and underscores. The name must begin with a letter.

    • Description — Description of the Protected Group.

      Note

      The minimum length for description is 1 character. The maximum allowed character length is 255 characters.

    • Inspection Mode — Mode of inspection. Displays the mode as IPS.

    vIPS Cluster

    The cluster of instances for which the Protected Group applies.

    Traffic Source

    Select GWLB Mirroring as the traffic source for the Protected Group.

    vIPS Controller

    Controller for the Protected Group.

    Note

    This does not apply to GLWB.

    Individual Policy Assignments

    • IDS — IDS policy is applicable to the Protected Group.

    • Advanced Malware — Malware policy applicable for the Protected Group.

    • Inspection Options — Inspection policy applicable for the Protected Group.

    • Connection Limiting — Connection limiting policy applicable for the Protected Group.

    • Firewall — Firewall policies applicable for the Protected Group.

    GUID-0E47A2C8-D361-4090-B96C-F756BAC98E17-low.png

    Refresh the status of all the Protected Groups.

    Search

    Enter the keyword to search the required Protected Group.

    GUID-B9B906D7-0A24-439D-9CCA-7E3B57735B45-low.png

    Create a new Protected Group.

    GUID-DDEB30D1-8F15-44F5-A05F-3D3C59BD2E8F-low.png

    Deletes a Protected Group.

    Save as CSV

    Creates a .csv list of the list of Protected Groups.



  4. To add a Protected Group, click GUID-B9B906D7-0A24-439D-9CCA-7E3B57735B45-low.png. Enter the details for the Protected Group, in the Details window.

    Note

    For each account you wish to secure, Trellix recommends you create a separate protected group for different accounts. In the event of an attack, this will help in identifying the account that was attacked.

    Option descriptions

    Option

    Description

    Details

    Details of the Protected Group.

    • Protected Group Name — Name of the Protected Group.

      Note

      The minimum length for the name is 1 character. The name can contain up to 50 alphanumeric (upper or lower case letters) characters, including hyphens and underscores. The name must begin with a letter.

    • Description — A brief description of the Protected Group.

      Note

      The minimum length for description is 1 character. The maximum allowed character length is 255 characters.

    • Inspection Mode — Mode of inspection. You can select IPS.

    vIPS Cluster

    Specify the Cluster for the Protected Group.

    To create a new Cluster or edit an existing Cluster, see Create a Cluster in the Manager for AWS.

    Member VMs

    Specify the VMs/Instance subnet for the Protected Group.

    Click Add to add the subnet CIDRs that you want to include in this Protected Group.

    Member Accounts

    Specify the accounts to narrow down the selection of VMs. Leave blank to include VMs in all accounts accessible to the controller.

    Trellix Virtual IPS Controller

    Specify the Controller for the Protected Group.

    Click Add to add a Controller that you want to include in this Protected Group.

    Note

    This does not apply to GWLB.

    Policy Group

    Specify the Policy Group.

    IDS

    Specify the IDS policy for the Protected Group.

    Advanced Malware

    Specifies the Malware policy for the Protected Group.

    • Inbound Policy — Select the Malware policy for inbound traffic.

    • Outbound Policy — Select the Malware policy for outbound traffic.

    Inspection Options

    Specify the Inspection policy for the Protected Group.

    Connection Limiting

    Specify the Connection Limiting policy for the Protected Group.

    Firewall

    Specify the Firewall policy for the Protected Group.

    • Interface Policy — The type of firewall policy.

    • Effective Rules —

      • Click on Inbound to view the inbound rules for the selected interface policy.

      • Click on Outbound to view the outbound rules for the selected interface policy.



    Note

    To create a new policy or to edit an existing policy, see the Trellix Intrusion Prevention System Product Guide.

  5. Click Save.

    On successful save, the Protected Group information is displayed in the vIPS Protected Groups tab.

    Details panel
    Details panel