The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Install a desktop firewall

Prev Next

A desktop firewall on the Manager server is recommended. Certain ports are used by the components of Trellix IPS. Some of these are required for Manager -- Sensor and Manager client-server communication. All remaining unnecessary ports should be closed.

Trellix strongly recommends that you configure a packet-filtering firewall to block connections to ports 8551, 3306, and 8005 of your Manager server. The firewall can either be a host-based or network-based. Set your firewall to deny connections to these ports if the connections are not initiated by the localhost. The only connections that should be allowed are those from the Manager server itself; that is, the localhost. For example, if another machine attempts to connect to port 8551, 3306, and 8005, the firewall should automatically block any packets sent. If you need assistance in blocking these, contact Trellix Technical Support.

Note

Trellix strongly recommends you not to change the firewall settings in the Linux based Manager.

Note

Use a scanning tool, such as Vulnerability Manager, to ensure that there are no ports open other than what is required.

If a firewall resides between the Sensor, Manager, or administrative client, which includes a local firewall on the Manager, the following ports must be opened:

Port # Protocol Description Direction of communication
  • 4167 (high ports) (source port on the Manager for IPv4 communication)
  • 4166 (source port on the Manager for IPv6 communication)
UDP Default SNMPv3 (command channel) Manager<-->Sensor
8500 (destination port on the Sensor) UDP Default SNMPv3 (command channel) Sensor<-->Manager
8501 TCP Proprietary (install channel using SHA256 2048-bit self-signed certificate) Sensor<-->Manager
8502 TCP Proprietary (alert channel/control channel using SHA256 2048-bit self-signed certificate) Sensor<-->Manager
8503 TCP Proprietary (packet log channel using SHA256 2048-bit self-signed certificate) Sensor<-->Manager
8504 TCP Proprietary (file transfer channel) Sensor<-->Manager
8506 TCP Proprietary (install channel for SHA256 2048-bit CA-signed certificates) Sensor<-->Manager
8507 TCP Proprietary (alert channel/control channel using SHA256 2048-bit CA-signed certificates) Sensor<-->Manager
8508 TCP Proprietary (packet log channel using SHA256 2048-bit CA-signed certificates) Sensor<-->Manager
8509 TCP Proprietary (Bulk file transfer channel using SHA256 2048-bit CA-signed certificates) Sensor<-->Manager
8510 TCP Proprietary (Bulk file transfer channel using SHA256 2048-bit self-signed certificates) Sensor<-->Manager
443 TCP HTTPS client-->Manager
80 TCP Web-based user interface client-->Manager
22 TCP SSH Remote console access

Note

If you choose to use non-default ports for the Install port, Alert port, and Log port, ensure that those ports are also open on the firewall.

  • Note that 3306/TCP is used internally by the Manager to connect to the MariaDB database.
  • If you have Email Notification or SNMP Forwarding configured on the Manager, and there is firewall residing between the Manager and your SMTP or SNMP server, ensure the following ports are available as well.

Additional communication ports

Port # Protocol Description Direction of communication
25 TCP SMTP Manager-->SMTP server
49 TCP TACACS+ Integration Sensor-->TACACS+ server
162 UDP SNMP Forwarding Manager-->SNMP server
389 TCP LDAP Integration (without SSL) Manager-->LDAP server
443 TCP Secure communication for MDR Manager 1 -->Manager 2
443 TCP Secure communication for MDR Manager 2-->Manager 1
514 UDP Syslog forwarding (ACL logging) Manager-->Syslog server
636 TCP LDAP Integration (with SSL) Manager-->LDAP server
1812 UDP RADIUS Integration Manager-->RADIUS server

If you have Trellix ePO - On-prem integration configured on Manager, and there is firewall between Manager and the Trellix ePO - On-prem Server, ensure the following port is also allowed through firewall.

Port Description Communication
8443 Trellix ePO - On-prem communication port Manager to Trellix ePO - On-prem server
  • Close all open programs, including email, the Administrative Tools > Services window, and instant messaging before installation to avoid port conflicts. A port conflict may prevent the application from binding to the port in question because it will already be in use.

Note

The Manager is a standalone system and should not have other applications installed.