The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to block attacks

Prev Next

The ability to drop and deny traffic is available only with a Sensor running in inline mode. The most efficient way to block exploits is to customize one or more of the pre-defined IPS policies to pro-actively drop malicious traffic. One of the pre-configured policies includes this functionality by default. The Default Prevention policy is automatically applied to Sensor interfaces when the Sensor is first added to the Manager. This policy contains a number of attacks that Trellix IPS has categorized as "recommended for smart blocking" (RFSB), and which are pre-configured with the drop attack packets response.

With other provided policies, the default Sensor response is to send alerts and log packets.

The first step towards prevention is typically to block attacks that have not caused false positives, have a high severity level, and have a low benign trigger probability. When you know which attacks you want to block, you can configure your policy to perform the drop attack packets response for those attacks.