The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage Ignore Rules

Prev Next

Ignore Rules are rules that filter attacks/attack responses in IPv4 or IPv6 traffic, based on source IP address, destination IP address, or both. When Ignore Rules are assigned to an attack definition, that attack is ignored when seen between the source and destination. No alert is generated and none of the configured response action is taken.

In the Manager, you can define Ignore Rules from the Policy tab and assign them to domains, Sensors and Sensor interfaces. Ignore Rules assigned at the domain level are associated with all Sensors belonging to that domain. Similarly, Ignore rules assigned at the Sensor level are associated with all ports and interfaces/subinterfaces belonging to that Sensor.

Note

When domain-level Ignore rules settings are overridden at the Sensor level, behavior of other resources belonging to that Sensor and using the same rule objects is also affected.

You can define the following types of Ignore Rules in the Manager:

  • IPv4 — IPv4 Ignore Rules without any source/destination port settings

  • IPv6 — IPv6 Ignore Rules without any source/destination port settings

  • TCP/UDP port — Ignore Rules with only source/destination port settings

  • IPv4 with TCP/UDP port — IPv4 Ignore Rules with source/destination port settings

  • IPv6 with TCP/UDP port — IPv6 Ignore Rules source/destination port settings

You can now use rule objects (network objects) to define Ignore Rules at the domain and Sensor levels. This provides a unified way to define various features in the Manager using the rules that are used in the firewall quarantine zones. The rule objects that allow you to define Ignore Rules for the Source or Destination IP address settings are the following:

  • IPv4 Endpoint or IPv6 Endpoint address — You can create a list of source and destination IPv4 addresses that you want to use in a rule. You can specify up to 10 addresses in a Rule Object.

  • IPv4 Address Range or IPv6 Address Range — You can create a list of IPv4 or IPv6 address ranges to use in an Ignore rule. In the rule, you can specify an IPv4 or IPv6 address range as the source or destination of traffic. For example, you may want to apply a rule to traffic from IPv4 addresses ranging from 10.1.1.1 to 10.1.1.25. You can specify up to 10 ranges in a Rule Object.

  • IPv4 Network or IPv6 Network — You can create a list of CIDRs to use in an Ignore rule. In that rule, you can specify a CIDR as the source or destination of traffic. For example, you might want to apply a rule on the traffic targeted for 172.16.225.0/24 network. The three reserved IPv4 ranges according to RFC 1918 and reserved IPv6 address block according to RFC 4193 are provided as default networks. You can specify up to 10 CIDRs in one Rule Object.

  • Network Group (Network Group for Exception Object) — You can combine one or more Host IP addresses, IP address ranges, or Networks to form a Network Group. For example, you can combine multiple IPv4 addresses or IPv6 ranges to form a Network Group rule object. You can specify up to 10 items in one Network Group Rule Object.

Note

The Ignore rules feature is unsupported with X-Forwarded-For (XFF) header parsing feature for HTTP or HTTPS traffic.

To use Ignore Rules, select Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Ignore Rules.

You can perform the following tasks:

  • Edit Ignore Rules. This includes adding, cloning, viewing, and deleting rules.

  • Manage Ignore Rule assignments.

  • Manage Ignore Rules.

  • Export Ignore Rules.

  • Import Ignore Rules.