The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Firewall policies

Prev Next

Firewall policies are ordered rules for permitting and denying traffic from reaching a Sensor's IPS/IDS engine and continuing on through the network. Firewall policies can maximize a Sensor's detection and prevention capabilities by preventing, that is dropping or rejecting, specified traffic without requiring full inspection.

In Trellix IPS, a Firewall policy consists of an ordered set of rules that govern what traffic is allowed to pass to a Sensor's inspection engine and beyond. These rules also govern which traffic should be denied, that is either dropped from the network or rejected (TCP traffic only). Thus, this feature enables the Sensor to preemptively drop any traffic by denying access to the inspection engine and beyond.

You can enforce policies based on various parameters. You can base it on the application, Windows Active Directory (AD) user names and user groups, the source or destination country of the traffic, the source or destination network, the source or destination host, and so on.

You can control the traffic both at a broader as well as at a granular level. For example, you can deny all TCP traffic that is using a specific port. You can also define a policy to prevent specific users from accessing specific social-networking sites between 9 am and 5 pm on all week days. Thus, Firewall policies provides you with very flexible options to control the traffic that is entering or leaving your network.

Note

The Firewall feature of Trellix IPS is independent of Trellix Firewall Enterprise. This section discusses only the Firewall feature of Trellix IPS.

The Sensor can perform both stateful and stateless inspection of traffic based on the response action configured. For stateful inspection, the Sensor checks either the source and destination IP addresses, or source and destination ports, or the application, or user name. In case of stateless inspection, based on either the source and destination IP addresses, or source and destination ports, the Sensor inspects the traffic on per packet basis. The packets are then either dropped or ignored depending on the response action configured.

Advantages of Firewall policies

Some of the advantages of using Firewall policies are as follows:

  • It can provide you visibility to a very granular level. For example, you can identify the users who are trying to use a blocked application, such as Facebook.

  • You can enforce different policies based on time. For example, you can allow gaming applications on weekends but block them during weekdays.

  • You can control traffic based on geographical locations.

  • You can control specific phases of an application. For example, you can allow chatting using Yahoo! Messenger but deny file transfers.

  • You can enforce different policies for different sub-networks within your enterprise network. For example, you can have very stringent policies for your finance network compared to your engineering network.

  • You can choose to enforce IPS on the allowed traffic, thus fully securing your network. Conversely, you can use the Firewall policies to exempt specific traffic from IPS inspection.