Trellix IPS enables you to quarantine your network hosts when required.
There are two ways to quarantine hosts:
- Configure the Sensor to quarantine hosts automatically when they generate specific attacks.
- Manually quarantine specific hosts that are listed in the Attack Log page.
- You can manually add endpoints to quarantine from the Quarantine page.
You might see the following issues while quarantining:
- When you quarantine a host from attack log but the host is not listed in the quarantine page, and the host is stuck.
- Quarantine page has a host that is not deleted after the expiry time. You might also see an error when manually deleting a host from the Quarantine page.
To confirm if it is a quarantine issue, put the Sensor in Layer 2 or add the host IP address to the Quarantine Exceptions list and check if the issue is resolved. If the issue is not resolved, contact Trellix Support.