The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage Quarantine Zones

Prev Next

When you configure Quarantine at the admin domain and Sensor port level, you need to specify the Quarantine Zone which must be used to quarantine hosts. At the Sensor port level, you can retain the Quarantine Zone configured at the admin domain or override it with a different Quarantine Zone. To enable you to quickly configure Quarantine, some pre-defined Quarantine Zone are provided. If these do not meet your requirements, you can clone them and edit them. If not, create Quarantine Zone according to your requirement.

Notes:

  • You cannot edit or delete the pre-defined Quarantine Zone.

  • The pre-defined Quarantine Zone belongs to the root admin domain and is visible to all the child admin domains.

  • Syslog forwarding is not enabled for the access rules of the pre-defined Quarantine Zone.

  • You cannot edit or delete a Quarantine Zone defined at a parent domain.

  • You cannot delete a Quarantine Zone if it is applied to a domain or Sensor port.

  • A configuration update of the Sensors is required for the changes to a Quarantine Zone to take effect.

  • You can create or edit rule objects even when creating an access rule. However, for the sake of explanation, this section assumes that you have created the required rule objects prior to creating the access rules.

  1. Click the Policy tab.

  2. From the Domain drop-down list, select the domain you want to work in.

  3. Select Intrusion Prevention → Objects → Quarantine Zones.

    Option

    Definition

    Name

    Displays the name of the Quarantine Zone

    Description

    Displays the description of the Quarantine Zone

    Ownership and Visibility

    Owner Domain

    Indicates the admin domain to which a Quarantine Zone belongs. All the default Quarantine Zones belong to the root admin domain.

    Visibility

    Indicates the visibility level of the domain

    Editable here

    The status Yes indicates that the policy is owned by the current admin domain.

    Last Updated

    Time

    Displays the time when the Quarantine Zone was last modified

    By

    Displays the user who modified the Quarantine Zone

    New

    Creates a Quarantine Zone

    Copy

    Clones a Quarantine Zone

    Edit

    Displays the details of a Quarantine Zone. You can also edit a Quarantine Zone belonging to the current admin domain.

    Delete

    Deletes a custom Quarantine Zone belonging to the current admin domain

    You can sort the list in ascending or descending order based on any of the columns by clicking on the column heading. You can also view the Columns option to enable or disable the display of the columns by selecting or deselecting the relevant check-boxes.

  4. To create a Quarantine Zone, click New.

  5. Specify the details on the Properties tab.

    Option

    Definition

    Name

    Enter a unique name to easily identify the Quarantine Zone.

    Description

    Describe the Quarantine Zone for other users to identify its purpose.

    Owner

    Displays the admin domain to which a Quarantine Zone belongs

    Visibility

    When selected, makes the Quarantine Zone available to the corresponding child admin domains. However, the Quarantine Zone cannot be edited or deleted from the child admin domains.

    Editable here

    The status Yes indicates that the policy is owned by the current admin domain.

    Statistics

    Lasted Updated

    Displays the timestamp when the Quarantine Zone was last modified

    Last Updated By

    Displays the user who last modified the Quarantine Zone

    Rules

    Displays the number of access rules currently defined in the Quarantine Zone

    Next

    Saves the changes made on the Properties tab and displays the Access Rules tab

    Cancel

    Reverts to the last saved configuration

  6. On the Access Rules tab, click the appropriate button to insert a new rule.

    Option

    Definition

    GUID-002605CA-A671-41C2-AC91-CCE74A6CB27E-low.png

    Inserts a new rule above the currently selected rule

    GUID-01632DAF-E14F-4696-93EF-18654509F3B8-low.png

    Inserts a new rule below the currently selected rule

    GUID-4EEC0D44-C0FE-467B-B1DB-948A06C873A3-low.png

    Clones the currently selected rule

    GUID-D55902DD-BC7E-4406-B464-AA20BE7D2793-low.png

    Deletes the currently selected rule

    GUID-F14FF892-015E-498D-9F2E-D89D5BE11D9A-low.png

    Moves the currently selected rule one row up

    GUID-A171DF4D-79F1-49C1-A8AB-E834EFB1DBAA-low.png

    Moves the currently selected rule one row down

  7. Double-click on each column of the access rule and specify your choices.

    Option

    Definition

    State

    Displays whether an access rule is enabled or disabled. Sensor does not apply disabled rules. This option might help you during troubleshooting.

    Description

    Optionally enter additional information about the rule. This might help you to easily understand the logs forwarded to the syslog server.

    Destination

    Select the IPv4 Endpoint or the IPv4 Network rule object.

    Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

    Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

    Service

    Restricts traffic based on the IP protocol, ICMP codes, or the TCP/UDP port numbers.

    Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

    Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

    Response

    Specify if the Sensor should allow or block traffic that matches the rule. Select Drop to discard the traffic or click or select Permit to pass the traffic.

    Consider that you want to log the matched traffic details only for specific access rules. Then, select Log to Syslog? for those rules.

    Note

    Ensure that in the Logging page of the Sensor, the Log traffic only if the matched rule is configured to log option is selected for the Logging field.

    The Log to Syslog? option has no impact if you select any other option for the Logging field in the Logging page.

    OK

    Saves the Quarantine Zone access rules in the Manager database. The Quarantine Zone is listed in the Quarantine Zones list.

    Save

    Saves all the Quarantine Zone access rules

    Cancel

    Reverts to the last saved configuration

    Following the steps above, you can Copy, Edit or Delete the custom Quarantine Zone.