The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes on IPv4 and IPv6 rule objects

Prev Next

The following table classifies IPv4 and IPv6 rule objects for firewall:

Type

Rule objects

IPv4

IPv4 Endpoint, Host DNS Name, IPv4 Address Range, IPv4 Network, User, User Group, Country

IPv6

IPv6 Endpoint, IPv6 Address Range, IPv6 Network, Country

Note

The default Service rule object for ICMPv6 is also available.

  • You use the above-listed, IPv6-based rule objects to create a Network Group rule object. However, you cannot use a combination of IPv4 and IPv6 based rule objects in one Network Group rule object.

  • In a Firewall access rule, you cannot specify an IPv4-based rule object for one field and IPv6-based rule objects for other applicable fields. For example, if you select an IPv6-based rule object in the Source Address field, then you cannot specify IPv4-based rule objects for Destination Address or Source User fields. For this example, you can specify only an IPv6-based rule object or other as the value for Destination Address and any for Source User. Recall that User and User Group rule objects are considered as IPv4 based rule objects because Trellix Logon Collector does not collect user information from IPv6 hosts. Similarly, Country and Host DNS Name are also IPv4-based rule objects.

  • Starting from 11.1 Update 10, you can configure IPv6 geolocation-based firewall rules. However, while configuring IPv6 geolocation-based firewall rules, you cannot set both the Source Address and Destination Address as Country. Doing so causes the system to identify the traffic as IPv4, preventing IPv6 alerts from triggering.

    To ensure IPv6 geolocation-based traffic detection, you must configure one field (Source Address or Destination Address) as a country, and the other as a country along with any other rule object, such as IPv6 Endpoint or IPv6 Network.

    Important

    The Manager prevents you from pushing Firewall policies that combine IPv6 rule objects (such as IPv6 address ranges or IPv6 networks) and Geolocation to sensors running versions earlier than 11.1 M10. If you attempt to push this configuration, the Manager blocks the action and displays an error message.

You configure user-based Firewall access rules using the user and user group rule objects. It is important to note the following regarding these rule objects:

  • You cannot create, modify, or delete the User or User Group rule objects. The Manager manages these rule objects according to the updates from Trellix Logon Collector.

  • You can view these rule objects only on the Access Rules tab of the Firewall page. You cannot view these rule objects in the Rule Objects page.

  • The user names verified through Kerberos snooping or the Sensor's Guest Portal are not displayed in the Manager.