The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to block IP-spoofed packets

Prev Next

When enabled, the anti-spoofing option drops packets containing invalid source IP addresses. Trellix IPS determines the validity of a source IP address by comparing it against a configured list of internal networks. Thus, as a pre-requisite, you must define CIDR blocks for every internal network that will send traffic through the Sensor interface in question. Without a comprehensive set of CIDR blocks defined, especially if outbound anti-spoofing is enabled, Trellix IPS may block valid packets.

Anti-spoofing is available only for Sensors in inline mode.

How Trellix IPS determines the validity of a packet depends directly on the direction of that packet:

  • Inbound — When a packet arrives on the outside interface, its source IP address is compared to the CIDR blocks associated with the interface. If the source IP address of the inbound packet matches one of the CIDR blocks, the packet is considered spoofed and dropped.

  • Outbound — When a packet arrives on the inside interface, its source IP address is compared to the CIDR blocks associated with the interface. If the source IP address of the outbound packet does not match one of the CIDR blocks, the packet is considered spoofed and dropped.