The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage proxy rules

Prev Next

When using proxy mode, you need to configure a proxy rule for the web server you wish to protect and their certificate and key. Trellix IPS Manager supports PKCS12 keys with file suffixes ".pkcs12", ".p12", or ".pfx". This can be configured on the Internal Web Server Certificates tab of the SSL Decryption page. Proxy rules are used by the Sensor to identify the web servers that are to be protected. The rule contains the IP address and the web certificate of the server. When the sensor detects SSL traffic which contains the IP address of a server that has a proxy rule defined, then the Sensor intercepts and decrypts the traffic.

To manage a proxy rule, perform the following steps:

  1. Select Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.

  2. In the Inbound tab, select Inbound Proxy Rules tab.

    Inbound Proxy Rules tab contains the following:

    Option

    Definition

    Rule Name

    Name of the proxy rule

    Destination Web Servers

    Specifies the IPv4 or IPv6 CIDR of the destination web server

    Web Server Certificates

    SSL certificates of the corresponding web servers

    Installed On

    The Sensor that has the certificate

    Last Updated

    Time - Specifies the time when the exception was last modified

    By - Displays the user who modified the exception

    Comments

    Additional comment specified for the exception

    GUID-002605CA-A671-41C2-AC91-CCE74A6CB27E-low.png

    Add rule before the selected rule.

    GUID-01632DAF-E14F-4696-93EF-18654509F3B8-low.png

    Add rule after the selected rule.

    GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png

    Delete the selected rule.

    GUID-F14FF892-015E-498D-9F2E-D89D5BE11D9A-low.png

    Move the selected rule up.

    GUID-A171DF4D-79F1-49C1-A8AB-E834EFB1DBAA-low.png

    Move the selected rule down.

    Save as CSV

    Export the proxy rules in CSV format.

    GUID-BDA9199A-1BDD-4534-9ACA-28F382052F55-low.png