The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Guidelines for using alert policy exceptions

Prev Next

Be aware of the usage guidelines and caveats described in the following paragraphs.

General Usage Guidelines

  • $HOME_NET—A set of alert policy exceptions can support more granular applications of alert action overrides than the homenet address or mask for Snort custom rules. See Custom rules and the homenet command in the CLI Command Reference.

  • Usage statistics—Use CLI commands to see the number of alert policy exceptions applied. See Viewing the list of alert policy exceptions using the CLI .

  • Logically ANDed terms—The match terms of an alert policy exception are matched using implicit AND operators. Logical OR operators are not available.

  • Attack direction-agnostic addresses—Alert policy exceptions do not refer "victim" and "attacker" IP addresses. Alert policy exceptions are defined using "source" and "destination" addresses as present in the packet, and attack direction is not considered.

  • Matching order—In cases where alert policy exceptions overlap or conflict, the following matching order determines which exception is applied:

    signature ID > signature name > attack category > all signatures

  • Longest prefix match—For matching source or destination addresses, the one with the longest prefix is most specific. For example, the following ruleset blocks traffic for the same signature when seen from a specific subnet. Rule 2 is more specific than Rule 1.

    Rule 1: SigID=900000 SrcIP=10.1.0.0/16 DstIP=ANY Intf=ALL Action=Block

    Rule 2: SigID=900000 SrcIP=10.1.1.1/32 DstIP=ANY Intf=ALL Action=Suppress

  • Supported alerts—Alert policy exceptions support the following attack categories:

    1. Infection Match

    2. Domain Match

    3. Malware Callback

    4. Riskware

    5. IPS

    6. Reconnaissance

    7. Local Signature

  • Supported addresses—Alert policy exceptions support both IPv4 and IPv6 addresses.

General limitations

  • Alerts not supported—Alerts for the following attack categories are not supported:

    1. Malware Objects

    2. Web Infections

    3. SmartVision

    SmartVision rules can be whitelisted separately. See "Managing Noisy SmartVision Alerts" in the Network Security SmartVision Feature Guide.

  • Maximum rules—Up to 2500 alert policy exceptions are supported per appliance.

Caveats for blocking actions

The following paragraphs describe how alert policy exceptions interact with inline blocking.

Override Actions That Entail Blocking Are Supported on Inline Blocking Deployments Only

Alert policy exceptions support the following override actions only for interfaces configured for inline blocking mode on appliances deployed inline:

  • Block—Forced blocking of matched traffic.

  • UnBlock—Allowing matched traffic.

  • Suppress & Unblock—Suppression of alert notifications and event logging while at the same time allowing matched traffic.

The alert policy exception Suppress and Default override actions are not dependent on inline blocking mode and inline deployment.

Multiple signature rules are more precise than a signature ame

For an alert policy exception that applies an UnBlock override action, Trellix recommends that you specify a signature ID rather than a signature name. Otherwise, the alert policy exception may allow more traffic to pass than you intend.

Caveats for IPS Rules

The following paragraphs describe how alert policy exceptions interact with IPS rules.

Only Suppression Is Supported for Reconnaissance Activity and Brute-Force Attack Rules

When an alert policy exception matches traffic for an IPS rule that detects reconnaissance activity or brute-force attacks, only suppression is supported as an override activity.

IPS Blocking Mode "Disabled" and "All" Take Precedence Over Alert Policy Exceptions

When the appliance is deployed inline and for interfaces configured for inline blocking mode, IPS blocking mode can be used to deny or force blocking of traffic matched by IPS rules. IPS blocking mode is enabled by default. The other two IPS blocking modes take precedence over alert policy exceptions:

  • When IPS blocking mode is disabled, all matched IPS rules—including those with alert policy exceptions that specify forced blocking—act as detection-only rules.

  • When IPS blocking mode is all, all matched IPS rules—including those with alert policy exceptions that specify "UnBlock"—act as blocking rules. In addition, IPS alert notifications are generated and IPS events are logged.

For more information, see "Action Overrides to All IPS Rules" in the Network Security IPS Feature Guide and the ips blockmode command in the CLI Command Reference.