The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

High-level steps for configuring Quarantine

Prev Next

This section explains about the requirements and the high-level steps for configuring Quarantine.

Requirements for Quarantine

The following are the resources that you would need to implement Quarantine. However, recall that these requirements depend on how you want to customize Quarantine.

  • Trellix IPS involving an NS-series Sensor with the required monitoring ports in inline mode.

  • Optionally, you can configure the Sensor to redirect a quarantined host to a remediation portal from where the user can download and apply the required software to make the host compliant with your security policies. These are software such as the virus scanner, DAT files, Microsoft service packs, and so on. To remediate hosts, you need to define an internal web server that contains links to download these software.

  • To quarantine a host, a Sensor uses ACL-type rules and restricts the access for the host. When the traffic from a quarantined host matches an ACL rule, you can log the details to a syslog server. By logging the matched traffic, you can know what a host attempted to access when being quarantined. To do this, you need a syslog server.

High-level steps

Note that not all of the following steps are mandatory. Configuration requirement is based on how you want to customize Quarantine. For example, the first step of creating Rule Objects is required only if you plan to create a customized quarantine zone or use Rule Objects to create Quarantine Exceptions.

  1. If you plan to modify the default quarantine zone or create some on your own, you need to define the required Rule Objects in the admin domain. Rule Objects are building blocks with which you define quarantine zone Access Rules. You can also use Rule Objects to create Quarantine Exceptions. The procedures to create Rule Objects and their use are the same as in the other Trellix IPS features such as Firewall, QoS, and Exceptions.

  2. If you want the details of the traffic that matched a quarantine zone access rule to be forwarded to a syslog server, do the following:

    1. Configure the details of the syslog server at the admin domain.

    2. Enable syslog forwarding on the Sensor.

  3. You can configure the Sensor to display the quarantine details when a host attempts to access something outside the quarantine zone. You can choose the default browser message or customize it to suit your requirements.

  4. If you have set up a remediation portal, you can configure those details at the domain level.

  5. Configure Quarantine at the domain level. You can inherit the configuration from the parent domain or customize it. You can also customize specific configurations and retain the parent-domain configuration for the remaining.

  6. Configure Quarantine for the required inline ports. You can inherit the configuration from the domain or customize it for the port. You can also customize specific configurations and retains the domain-level configuration for the remaining.

  7. For automatic quarantining of attacking hosts, enable Quarantine for the required attacks in the IPS and Reconnaissance policies applied on the Sensor monitoring port. Also, factor in the direction of the attack and the port when you enable Quarantine. Consider that you want to enable Quarantine only on the inside port for a particular attack. Then, enable Quarantine for the attack in the outbound direction only.

  8. View the details of the quarantined hosts in Attack Log and Dashboard.