The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a QoS policy

Prev Next

Prerequisite: For the sake of usability, an option is provided for you to create rule objects when creating the QoS rules. However, a systematic approach is to create the required rule objects before you create the QoS policy.

You create a QoS policy using the QoS rules as the building blocks. Then you need to assign the policy to the required Sensor ports.

Note

Import or export of QoS policies is not supported.

  1. Select Intrusion Prevention → Policy Types → QoS.

    The currently available QoS policies for the domain are listed. This includes the policies inherited from the parent domain. You cannot edit the inherited policies.

  2. Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png.

    The QoS page displays.

  3. Specify the details on the Properties tab.

    Properties option definitions

    Option

    Definition

    Name

    Enter a unique name to easily identify the policy.

    Description

    Optionally describe the policy for other users to identify its purpose.

    Owner

    Displays the admin domain to which the policy belongs

    Visibility

    When selected, makes the policy available to the corresponding child admin domains. However, the policy cannot be edited or deleted from the child admin domains.

    From the drop-down list, select the option for the visibility level of the rule object.

    Available options are Owner and child domains and Owner domain only.

    Editable here

    The status Yes indicates that the policy is owned by the current admin domain.

    Type

    Select the type — advanced or classic. After you save the properties, you cannot change the type.

    Statistics

    Lasted Updated

    Displays the time stamp when the policy was last modified

    Last Updated By

    Displays the user who last modified the policy

    Assignments

    Indicates the number of inline ports to which the policy is assigned

    Diff Serv Tagging Rules

    Displays the number of DiffServ tagging rules currently defined in the policy

    802.1P Tagging Rules

    Displays the number of 802.1P tagging rules currently defined in the policy

    Prompt for assignment after save

    When selected, you are automatically prompted to select the Sensor resources to which you want to assign the policy.

    Save

    Saves the changes made on the Properties tab.

    Note

    This option is visible only when you open an existing policy.

    Next

    Click this to save the changes made on the Properties tab and to access the Diff Serv Rules tab. This button is available only when you create a policy.

    Important

    After you click Next, you cannot change the policy type.

    Cancel

    Reverts to the last saved configuration



  4. Define the QoS rules for Diff Serv and 802.1P in the corresponding tabs.

    You use the rule objects as building-blocks to create a rule. Recall that the Sensor matches the rules in a top-down fashion and does not processes a set of rules after the first match. So make sure the specific rules are defined at the top, and the rules with a broader scope are defined towards the end of the list.

  5. On the Diff Serv Rules and 802.1P Rules tabs, click the appropriate button to insert a new rule.

    QoS rule button definitions

    Option

    Definition

    GUID-002605CA-A671-41C2-AC91-CCE74A6CB27E-low.png

    Inserts a new rule above the currently selected rule

    GUID-01632DAF-E14F-4696-93EF-18654509F3B8-low.png

    Inserts a new rule below the currently selected rule

    GUID-4EEC0D44-C0FE-467B-B1DB-948A06C873A3-low.png

    Clones the currently selected rule

    GUID-D55902DD-BC7E-4406-B464-AA20BE7D2793-low.png

    Deletes the currently selected rule

    GUID-F14FF892-015E-498D-9F2E-D89D5BE11D9A-low.png

    Moves the currently selected rule one row up

    GUID-A171DF4D-79F1-49C1-A8AB-E834EFB1DBAA-low.png

    Moves the currently selected rule one row down



    On the Diff Serv Rules tab, you can select any of the following options for Unclassified Traffic - Diff Serv Value :

    • Set to Zero — To re-tag the unclassified traffic with a zero-value tag

    • Keep the value seen on the wire — To retain the tag that was originally present

    On the 802.1P Rules tab, you can select any of the following options for Unclassified Traffic - 802.1P Value :

    • Set to Zero — To re-tag the unclassified traffic with a zero-value tag

    • Keep the value seen on the wire — To retain the tag that was originally present

    Note

    To search for a specific rule, type the first few letters of the description of the rule in the Search field. The rule containing the description of the typed letter(s) is displayed.

  6. Double-click on the row of an access rule and specify your choices.

    The default Diff Serve rule
    The default Diff Serve rule


    • For advanced QoS policies, change the values of Source Address, Source User, Destination Address, Application, and Effective Time. For classic QoS policies, change Service.

      Note

      In a Firewall access rule or QoS rule, you cannot specify an IPv4-based rule object for one field and IPv6-based rule objects for other applicable fields. For example, if you select an IPv6-based rule object in the Source Address field, then you cannot specify IPv4-based rule objects for Destination Address or Source User fields. You can specify only an IPv6-based rule object or any as the value for Destination Address and any for Source User. Recall that User and User Group rule objects are considered as IPv4 based rule objects because Logon Collector does not collect user information from IPv6 hosts. Similarly, Country and Host DNS Name are also IPv4-based rule objects.

    • In the QoS rules, you can generally add up to 10 rule objects per field.

    QoS rules option definitions

    Option

    Definition

    State

    Displays whether a rule is Enabled or Disabled. Sensor does not apply disabled rules. This option might help you during troubleshooting.

    Description

    Optionally enter additional information about the rule. You can enter a description up to 64 characters long and click OK.

    Source Address

    Select the rule objects corresponding to the source of the traffic from the Available list.

    Note

    The Manager filters the rule objects containing more than 10 entries and lists only those which contain up to 10 entries, since the maximum supported rule object members per rule object in QoS policy is 10.

    Click Add to add a rule object.

    Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

    Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

    Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the rule object from the list.

    Source User

    Select the type of user from the Type drop-down list and then select the rule objects corresponding to the user from the Available list. Click Add to add the selected rule object.

    Note

    This option is for user-based rules. Recall that the Manager receives users and user groups from Logon Server and automatically displays them as rule objects. User groups are listed by default.

    Destination Address

    Select the rule objects corresponding to the destination of the traffic from the Available list.

    Note

    The Manager filters the rule objects containing more than 10 entries and lists only those which contain up to 10 entries, since the maximum supported rule object members per rule object in QoS policy is 10.

    Click Add to add a rule object.

    Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

    Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

    Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the rule object from the list.

    Application

    Select the rule objects corresponding to the application from the Available list.

    Click Add to add a rule object.

    Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

    Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

    Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the rule object from the list.

    You can have Service or Application-related rule objects in a rule but not both.

    Effective Time

    Select the time-based rule objects to specify the time when the Sensor should implement the rule, from the Available list.

    Click Add to add a rule object.

    Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

    Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

    Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the rule object from the list.

    Note

    Time-based rules are implemented using the local time zone of the corresponding Sensor.

    Diff Serv Tag

    This option is seen when you select the Diff Serv Rules tab.

    Select the required DiffServ tag from the drop-down list and click OK.

    802.1P Tag

    This option is seen when you select the 802.1P Rules tab.

    Select the required 802.1P tag from the drop-down list and click OK.

    Prompt for assignment after save

    If you clear this option you can save the policy now and assign it to the Sensor resources as explained in the following section. If you select this option, the Assignments window opens automatically when you save the policy and you can assign the policy to the required Sensor resources.

    Save

    Saves the access rules in the Manager database. The QoS policy is listed in the Quality of Service (QoS) Policies list.

    Cancel

    Reverts to the last saved configuration



    You can follow these steps to clone and edit QoS policies.