The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to block attacks

Prev Next

The ability to drop and deny traffic is available only with a Sensor running in inline mode. The most efficient way to block exploits is to customize one or more of the pre-defined IPS policies to pro-actively drop malicious traffic. One of the pre-configured policies includes this functionality by default. The Default Prevention policy is automatically applied to Sensor interfaces when the Sensor is first added to the Manager. This policy contains a number of attacks that Trellix IPS has categorized as "recommended for smart blocking" (RFSB), and which are pre-configured with the drop attack packets response.

With other provided policies, the default Sensor response is to send alerts and log packets.

The first step towards prevention is typically to block attacks that have not caused false positives, have a high severity level, and have a low benign trigger probability. When you know which attacks you want to block, you can configure your policy to perform the drop attack packets response for those attacks.

From 11.1 Update 3 version and above, Trellix IPS Manager enables users to choose attacks that they want to be automatically blocked by the IPS Sensor. Users can define and store one or more customizable rules for blocking attacks as per their network requirements during attack set profile configuration. When the same attack set profile is used in the IPS policy, the Manager automatically correlates the blocking criteria set by the user with the new and existing attack signatures. As the attack set profile mapped to the IPS policy stores the user-defined blocking criteria for attacks, it is automatically applied to any new/modified attack definitions included in any signature set update that match the set criteria. This eliminates the requirement of repeated manual intervention and provides user-customizable and automated attack blocking mechanism that further enhances network security. For more information, refer to the section How to automate blocking of attacks based on user-defined blocking strategy.