The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Quarantining hosts

Prev Next

Trellix IPS enables you to quarantine your network hosts when required. For example, some hosts on your network might be compromised and used to attack other hosts in your network and outside. You might have identified hosts that are non-compliant with the security policies of your organization. In such cases, you can use the Quarantine feature of Trellix IPS to isolate the required hosts from the network and force them to remediate before you let them back on your network.

There are two ways to quarantine hosts:

  • Configure the Sensor to quarantine hosts automatically when they generate specific attacks.

  • Manually quarantine specific hosts that are listed in the Attack Log.

When a Sensor identifies the host that needs to be quarantined, a quarantine rule is created for the source IP address of the host. The host is now in quarantine, meaning it has a restricted access on your network. The compromised hosts are isolated from the network temporarily, thus preventing them from harming other network systems.

Note

Quarantine works only when the Sensor monitoring ports are in inline mode.

The Quarantine feature is very flexible and easy to implement. You can implement Quarantine with the default settings by just enabling it on the required Sensor monitoring ports or customize it to suit your requirements. Based on how you want to customize Quarantine, you require additional configurations. For example, to enable quarantined hosts to remediate, you must install a remediation portal and provide those details in the Manager. These requirements are discussed in the corresponding sections which contain the steps for customization.

The following are some of the options to customize Quarantine:

  • You can restrict the network access of a quarantined host based on the following:

    • The destination IP address that a host wants to access

    • The IP network that a hosts wants to access

    • The network service such as DHCP, FTP, HTTP, SSL and so on.

  • If a quarantined host attempts to access a network resource, you can redirect the HTTP traffic from the host to a web page displaying why the host is being quarantined and subsequently redirect it to the remediation portal. In the remediation portal, you can provide the links to the security software to make the host compliant with the security policies of your organization.

  • While adding an endpoint to quarantine, you can also configure to redirect the quarantined endpoint to the configured remediation portal. These configurations can be made in the following pages on the Analysis tab:

    • Threat Explorer

    • Callback Activity

    • High-Risk Endpoints

    • Quarantine

    • Attack Log

  • You can configure a list of hosts that you want to be excluded from being quarantined. For example, you might want to exclude servers, such as vulnerability scanners from being quarantined.

The state of the host, that is, whether the host is in Quarantine/ Remediation, can be viewed from the Quarantine page.