The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Quarantine options for NTBA alerts

Prev Next

You can choose to quarantine policy violation, callback attacks, recon and threshold-based attacks, endpoint-based anomaly attacks, and behavioral NTBA alerts.

The quarantine response action needs to be enabled at the policy level per zone.

If the attack was detected by Cisco router, the NTBA Appliance quarantines that endpoint by setting an ACL at the router for 5 minutes by default.

If the attack was detected at a Sensor, the NTBA Appliance sends the quarantine details as part of the alert to the Manager. In response to this, the Manager sends the corresponding source endpoint as part of endpoint quarantine to the Sensor.

The quarantine details sent in the alert are exporter id, response action, and source interface.

The period for which quarantine is effective is 5 minutes by default. If you want to change this value, contact Trellix Technical Support.