The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable Quarantine for an admin domain

Prev Next

Use the Quarantine Configuration Wizard to configure the default Quarantine settings for an admin domain. That is, these settings are available for the child domains as well as the Sensors managed by the admin domain. Then, you can inherit or customize these settings at the child-domain level and Sensor level.

  1. Click the Devices tab.

  2. From the Domain drop-down list, select the domain you want to work in.

  3. Click the Global tab.

  4. Select IPS Device Settings → Quarantine → Default Port Settings.

    The Quarantine Configuration Wizard opens.

  5. Configure Quarantine at the admin-domain level using the Quarantine Configuration Wizard.

    Note

    Throughout this wizard, click Next to proceed to the next page. Click Cancel to exit the wizard without saving the changes.

    Quarantine settings using the wizard
    Quarantine settings using the wizard


    Option

    Definition

    Inherit From Parent Domain

    When selected, the settings from the parent domain are applied. Click Finish and no further configuration is required. However, in the parent domain, you must have selected Visible to Child Admin Domains.

    To use a different configuration for this domain, deselect Inherit From Parent Domain.

    Note

    This is not applicable to the root admin domain.

    Visible to Child Admin Domain

    When selected, a child domain is able to use the same Quarantine settings.

    Would you like to quarantine endpoints that attempt intrusions?

    When selected, enables the Quarantine feature for this admin domain.

    Would you like to intercept HTTP requests from quarantined endpoints and respond with a browser message explaining why they have been quarantined?

    Enables redirection to the Quarantine browser message and subsequently to the Remediation Portal.

    Quarantine Zone

    Lists the quarantine zones that are available for the admin domain.

    Release Logic

    • Automatic Release After a Specific Amount of Time — The Sensor automatically releases the host from quarantine after the time period you specify in the Release After field.

    • Keep in Quarantine Until Explicit Released — The Sensor quarantines the host until you manually release it.

    Release After

    Enter the quarantine time period (between 5 and 60 minutes), if you had selected Automatic Release After a Specific Amount of Time in the Release Logic field.

    Quarantine Exceptions

    Displays the details of the hosts and networks for which you do not want to quarantine.

    Note

    At the Sensor level, you can inherit this list and append more entries or configure a different quarantine exception list for that Sensor.

    • New — Adds a new record to the quarantine exception list.

      • Type — Select based on how you plan to create the quarantine exception record. You can choose to enter the IPv4/IPv6 address of the host to be excluded, IPv4 network to be excluded, or select a IPv4 Endpoint, IPv4 Endpoint or IPv4 Network rule object.

      • Value — Based on your selection in the Type field, enter the IP address, network, or choose the rule object.

      • Description — Optionally, enter any notes regarding the quarantine exception record.

    • Edit — Select a record in the quarantine exception table and click this button to make changes to the Value and Description fields of that record.

    • Delete — Select a record in the quarantine exceptions table and click this button to delete it from the Manager database.

    • Import — If you have too many entries, then you can import them from a .csv file.

    Finish

    Saves the Quarantine configuration to the Manager database and exits the wizard.

    Note

    You must do a configuration update to the Sensors for these changes to take effect.