The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Customize Quarantine browser message

Prev Next

When the quarantined host tries to access network resources outside its assigned Quarantine Zone, a Quarantine browser message is displayed to the host. Manager provides a built-in Quarantine browser message, which can be customized according to your requirements.

  1. Click the Devices tab.

  2. From the Domain drop-down list, select the domain you want to work in.

  3. Select Global → IPS Device Settings → Quarantine → Browser Messages.

    Customize Quarantine browser message
    Customize Quarantine browser message


  4. To edit and customize the built-in browser message select Quarantine and then click Customize.

  5. In the Customize Browser Message page, edit the default content according to your requirement.

    Option

    Definition

    Message Text

    Displays the current format for the message.

    Content-Specific Variables

    Click the following to insert the corresponding variable in the Message Text field.

    • Health Level — Indicates whether the host is in good health based on its compliance with your organization's security policies. For example, a host is in good health if it has the required security applications and patches as mandated by your policies.

    • Host Name — Indicates the name of the quarantined host.

    • IP Address — Indicates the IP address of the quarantined host.

    • MAC Address — Indicates the IP address of the quarantined host.

    • Network Access Zone — Indicates the name of the network access zone to which the host is restricted to for the quarantine period.

    • Sensor Name — The Sensor that is quarantining the host.

    • User Name — The user logged on to the host at the time of quarantine.

    • Attack ID — The Trellix-assigned universally unique hexadecimal value of the attack that caused the host to be quarantined.

    • Attack Name — Trellix-assigned named to the attack that caused the host to be quarantined.

    • Quarantine Time — The start time of the quarantine.

    • Duration — The time period for which the host is quarantined.

    Save

    Saves the changes made to the browser message.

    Reset

    Reverts to the default browser message. If you click this button, even the saved customizations are lost.

    View

    Click to view how the browser message appears for the user. The remediation portal IP is displayed if you have configured those details in the Manager already.

    Cancel

    Click to revert to the last saved version of the browser message.