The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Methods for blocking attacks

Prev Next

The Trellix Intrusion Prevention System IPS offers a variety of ways to block malicious traffic. These options include the following:

  • Block exploit traffic (based on IPS policy configuration)

  • Block DoS traffic (behavior-based detection)

  • Block malware download (based on Malware policies)

  • Block using Firewall policies (based on ACLs in the Firewall policies)

  • Use Trellix IPS's traffic normalization feature—block based on configured TCP flow violation (out-of-order packets, deny…)

  • Block IP-spoofed packets (configured)

    Tip

    Ignore rules can be configured to override the blocking criteria—to permit particular source IPs, for example.

The Malware, Firewall, and DoS are detailed in their respective chapters of this Guide.