The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage rule objects for Quarantine

Prev Next

You use rule objects to define quarantine zone access rules and quarantine exceptions.

Icon/Option

Definition

Rule object

Displays the rule objects according to the filter criteria. Click a column heading to sort the table in ascending or descending order.

  • Name — Indicates the name of the rule objects.

  • Description — Indicates the description of the rule object.

  • Type — Indicates the rule object type.

  • Owner Domain — Indicates the admin domain to which a rule object belongs. All the default rule objects belong to the root admin domain.

  • Visibility — Indicates the visibility settings of settings to the domains, whether it is visible only to th owner domain or to both owner and child domains.

  • Editable here — Yes indicates that the rule object is a custom rule object belonging to the current admin domain. If it is No, you cannot edit the rule object because it is a default rule object or a custom rule object defined at a parent admin domain.

Object Type

Filters rule objects in the list.

  • Default Objects Only — Trellix pre-defined these rule objects. For example, the Application and Country are default rule objects. You cannot define these rule objects.

  • Custom Objects Only — You need to define these rule objects. For example, you need to define the Host DNS Name rule object.

  • Custom and Default Object — When selected, it displays both the predefined and user defined rule objects. For example, IPv4 Network Rule Object has the 3 reserved private networks pre-defined, but you can create your Network rule objects as well.

Rule Object Type

Select the rule object type that you want to view.

Search

Type your search criteria in the field to find rule objects with matching elements. For example, type

to list the rule objects containing google as part of their names.

GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png

icon

Creates a custom rule object.

GUID-717A81EC-A913-4C2F-B61C-0129ED30387A-low.png

icon

Clones a rule object. You cannot clone default rule objects other than the IPv4 network rule objects.

GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png

icon

Deletes a custom rule object belonging to the current admin domain.

To view or edit a rule object

Double-click the rule object belonging to the current admin domain.

Rule objects are mappings to one or more components related to your network traffic. However, for Quarantine you can map a rule object only to one component. So, for example, you can specify an IPv4 address as a rule object. Then you can create a quarantine zone access rule in which you specify this rule object as the destination. Every time you want to refer to this IP address in your quarantine zone access rules or quarantine exceptions, you can use this rule object.

Important

In features such as Advanced Firewall policies, you can specify multiple rule objects per component of an access rule. For example, you can specify multiple rule objects as the destination of the traffic. In case of quarantine zone access rule, you can specify only one rule object per component. Also, the rule object that you use in the quarantine zone access rule can have only one item in it. For example, the IPv4 Endpoint rule object that you want to use in quarantine zone access rule can only contain one IPv4 address in it. However, the IPv4 Endpoint rule object for quarantine exception list can contain up to 10 IPv4 addresses.

Rule objects for Quarantine

Relevant for quarantine zone?

Relevant for quarantine exception?

IPv4 Endpoint: Use this rule object to refer to IPv4 addresses in quarantine zone access rules and quarantine exception list.

Yes

Yes

IPv6 Endpoint: Use this rule object to refer to IPv6 addresses in quarantine exception list.

No

Yes

IPv4 Network: Use this rule object to refer to the CIDRs to use in quarantine zone access rules and quarantine exception lists. In a quarantine zone access rule, you can specify a CIDR as the destination of traffic. For example, you might want to apply a rule on the traffic targeted for 172.16.225.0/24 network. Default IPv4 Network rule objects are available for the three reserved IPv4 ranges according to RFC 1918. You can specify up to 10 CIDRs in one rule object for quarantine exception lists.

Yes

Yes

Service: To restrict traffic based on the IP protocol, ICMP codes, or the TCP/UDP port numbers, use the Service rule object. You can create Service rule objects or use the default ones. The well-known services on standard TCP and UDP ports, as well as ICMP codes are pre-defined. For example, telnet is predefined as TCP on port 23. Similarly, ICMP codes such as ICMP echo reply and ICMP request are pre-defined. When you create a Service rule object, the options are to specify the protocol number, TCP port, or UDP port. For custom ICMP codes, you need to specify the IP protocol number and the ICMP code in the port field. You can define only one IP protocol specification per rule object.

Notes:

  • A Sensor processes the access rules of a quarantine zone in a top-down fashion. So, if you want to drop traffic based on Services, then define those access rules high up in the policy.

  • For access rules that use Service rule objects, the Sensor factors in any non-standard ports that you have configured for IPS. For example, if you have specified port 2023 as the non-standard port for FTP, and if you have used the FTP Service rule object in a rule, then the Sensor considers FTP on both ports 21 and 2023.

  • It is not advisable to set permit rules for protocols such as FTP, TFTP, and RPC services that negotiate ports dynamically. For RPC services, you can configure explicit allow and deny rules for RPC as a whole, but not its constituents, such as statd and mountd.

  • Multimedia protocols such as H.323 and services such as instant messaging and peer-to-peer communication either negotiate the data channel separate from the control channel or negotiate ports that do not follow a standard. However, you can configure access rules to deny these dynamic protocol instances by denying the fixed control port.

  • An option for denying protocols that use dynamic negotiation is to configure quarantine zone to drop the attacks that are detected in such transmissions. Trellix IPS detects use of and attacks in such programs as Yahoo Messenger, KaZaA, IRC, and so forth.

Yes

No