The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Manage rule objects

Prev Next

You use rule objects to define Firewall and QoS policies, Ignore Rules, Outbound SSL Decryption Exclusions, Quarantine Zones, and NTBA Communication Rules. To manage the rule objects, go to Policy → <Admin Domain Name> → Intrusion Prevention → Objects → Rule Objects.

Option Definition
Rule Objects Displays the rule objects according to the filter criteria. Click a column heading to sort the table in ascending or descending order.
  • Name — Indicates the name of the rule objects
  • Description — Indicates the description of the rule object
  • Type — Indicates the rule object type
  • Owner Domain — Indicates the admin domain to which a rule object belongs. All the default rule objects belong to the root admin domain.
  • Visibility — Indicates the visibility settings of settings to the domains, whether it is visible only to the owner domain or to both owner and child domains
  • Editable here — Yes indicates that the rule object is a custom rule object belonging to the current admin domain. If it is No, you cannot edit the rule object because it is a default rule object or a custom rule object defined at a parent admin domain.
Object Type Filters rule objects in the list.
  • Default Objects Only — Trellix pre-defined these rule objects. For example, the Application and Country are default rule objects. You cannot define these rule objects.
  • Custom Objects Only — You need to define these rule objects. For example, you need to define the Host DNS Name rule object.
  • Custom and Default Objects — When selected, it displays both the predefined and user defined rule objects. For example, IPv4 Network Rule Object has the 3 reserved private networks pre-defined, but you can also create your Network rule objects.
Rule Object Type Select the rule object type that you want to view.
Search Type your search criteria in the field to find rule objects with matching elements. For example, type google to list the rule objects containing google as part of their names.
icon Creates a custom rule object
icon Clones a rule object. You cannot clone default rule objects other than the IPv4 network rule objects.
icon Deletes a custom rule object belonging to the current admin domain
Save as CSV Saves the rule objects for the rule object type selected
To view or edit a rule object Double-click the rule object belonging to the current admin domain.

In the Manager, each rule object type has an associated icon for easy identification. The following table lists the rule objects and the corresponding icons.

Rule object icons
Icon Rule Object
Application
Application Group
Application on Custom Port
Country (displays the country's flag. So, the icon varies for each country)
Finite Time Period
Host DNS Name, IPv4 Endpoint, and IPv6 Endpoint
IPv4 Address Range and IPv6 Address Range
IPv4 Network and IPv6 Network
Network Group (Network Group for Exception Object)
Recurring Time Period
Recurring Time Period Group
Service
Service Group and Service Range (Service Range is applicable only to QoS policies).

Note

You cannot clone a default rule object except for Network. You cannot edit or delete any default rule object. You can edit or delete custom rule objects only at the admin domain where they were created.