The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage rule objects

Prev Next

You use rule objects to define Firewall and QoS policies, Ignore Rules, SSL Decryption Exclusions, Quarantine Zones, and NTBA Communication Rules. To manage the rule objects, go to Policy → <Admin Domain Name> → Intrusion Prevention → Objects → Rule Objects.

Option

Definition

Rule Objects

Displays the rule objects according to the filter criteria. Click a column heading to sort the table in ascending or descending order.

  • Name — Indicates the name of the rule objects

  • Description — Indicates the description of the rule object

  • Type — Indicates the rule object type

  • Owner Domain — Indicates the admin domain to which a rule object belongs. All the default rule objects belong to the root admin domain.

  • Visibility — Indicates the visibility settings of settings to the domains, whether it is visible only to the owner domain or to both owner and child domains

  • Editable here — Yes indicates that the rule object is a custom rule object belonging to the current admin domain. If it is No, you cannot edit the rule object because it is a default rule object or a custom rule object defined at a parent admin domain.

Object Type

Filters rule objects in the list.

  • Default Objects Only — Trellix pre-defined these rule objects. For example, the Application and Country are default rule objects. You cannot define these rule objects.

  • Custom Objects Only — You need to define these rule objects. For example, you need to define the Host DNS Name rule object.

  • Custom and Default Objects — When selected, it displays both the predefined and user defined rule objects. For example, IPv4 Network Rule Object has the 3 reserved private networks pre-defined, but you can also create your Network rule objects.

Rule Object Type

Select the rule object type that you want to view.

Search

Type your search criteria in the field to find rule objects with matching elements. For example, type google to list the rule objects containing google as part of their names.

GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png

icon

Creates a custom rule object

GUID-717A81EC-A913-4C2F-B61C-0129ED30387A-low.png

icon

Clones a rule object. You cannot clone default rule objects other than the IPv4 network rule objects.

GUID-9A719AD5-F6BE-4CD4-9311-CC6655DF9B70-low.png

icon

Deletes a custom rule object belonging to the current admin domain

Save as CSV

Saves the rule objects for the rule object type selected

To view or edit a rule object

Double-click the rule object belonging to the current admin domain.

In the Manager, each rule object type has an associated icon for easy identification. The following table lists the rule objects and the corresponding icons.

Rule object icons

Icon

Rule Object

GUID-865A0818-27EC-4BF2-B2F3-3194132ECE43-low.png

Application

GUID-3B3359ED-B9CD-4DC0-9F3A-AD86A7FB13F0-low.png

Application Group

GUID-43AA5798-7BEB-4B6D-9823-A4F8C2EAA838-low.png

Application on Custom Port

GUID-C7B73725-879F-4134-8D19-3637AB889305-low.png

Country (displays the country's flag. So, the icon varies for each country)

GUID-9BB0D9CA-29B0-4AC5-AD9A-D06EA146082B-low.png

Finite Time Period

GUID-A020136A-CC09-4EF7-93DE-EF44D7A29378-low.png

Host DNS Name, IPv4 Endpoint, and IPv6 Endpoint

GUID-78F07A0F-F120-43C3-AC52-2477A874EBEE-low.png

IPv4 Address Range and IPv6 Address Range

GUID-0BC6CFE7-DD84-439E-A44E-7AD06E222447-low.png

IPv4 Network and IPv6 Network

GUID-54A52AA8-1967-4856-90E2-B844AA571B05-low.png

Network Group (Network Group for Exception Object)

GUID-5A738BD0-6774-4F1F-9942-756F7270FB2A-low.png

Recurring Time Period

GUID-1DC575B8-96C2-4E33-9C95-9F27FEDF0F6C-low.png

Recurring Time Period Group

GUID-64947B35-94CA-4403-BDD6-228767679843-low.png

Service

GUID-946970C1-B544-427D-9438-AA7FC8CA1D6E-low.png

Service Group and Service Range (Service Range is applicable only to QoS policies).



You cannot clone a default rule object except for Network. You cannot edit or delete any default rule object. You can edit or delete custom rule objects only at the admin domain where they were created.