The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Restricted SNMP write access for third-party NMS users

Prev Next

Sensors provide read-write access to a Host Quarantine Group portion of the MIB tree. To have read-write access to these MIBs, the following configurations are needed:

  • Configure third-party NMS users.

  • Configure a set of IPv4/IPv6 addresses from where third-party SNMP access would be allowed.

For managing the restricted read-write access, you need to enable/disable it from the Sensor CLI. For more information, see the CLI commands section.

After enabling/disabling the access, the Sensor is to be rebooted only if the SNMP users are already configured. If no SNMP user is configured on the Sensor, then the configuration is done without rebooting the Sensor.

The following write operations are permitted:

  • Add an IPv4/IPv6 entry to quarantine the host.

  • Extend the quarantine duration of an existing quarantined IPv4/IPv6 host entry.

  • Delete the IPv4/IPv6 filter entries one by one.

  • Delete all the IPv4/IPv6 filter entries at once.

  • Remediation for IPv4.

If the Sensor is in the failover mode, make sure that the entries are created on both the primary and secondary Sensors.

Restricted read-write access is permitted for the section of the MIB tree depicted in the following image.

GUID-C967D209-43FE-4B47-9EA7-8EF384453623-low.png

User scenarios

Scenario 1

To isolate a host in the Sensor from the third-party SNMP application:

Set the hostQUserDefFilterAction object of the hostIsolUserDefFilterTable to a value 1. For setting this object, the following indices are needed:

  • IP Address (To be provided in a dot separated format)

  • VidsId (should always be set to 0)

  • AttackId (should always be set to 0)

The above action is applicable to both IPv4 as well as IPv6 entries. Consider the following example:

For isolating a host with IPv4 address of 10.12.12.15, the following OID is to be set with a value 1.

OID - 1.3.6.1.4.1.8962.2.1.2.1.22.6.1.5.10.12.12.15.0.0

Scenario 2

To extend the isolation end time of an already isolated host in the Sensor from the third-party SNMP application:

Set the hostQUserDefFilterDuration object of the hostIsolUserDefFilterTable to a value <time in minutes>. For setting this object, the following indices are needed:

  • IP Address (To be provided in a dot separated format)

  • VidsId (should always be set to 0)

  • AttackId (should always be set to 0)

The above action is applicable to both IPv4 as well as IPv6 entries. Consider the following example:

For extending the isolation duration of an already isolated host with IPv4 address of 10.12.12.15, by 30 more minutes, the following OID is to be set with a value 30.

OID - 1.3.6.1.4.1.8962.2.1.2.1.22.6.1.4.10.12.12.15.0.0

Scenario 3

A list of already isolated hosts can be retrieved by performing an SNMP walk on the hostQBulkFilterTable.

To obtain the list of isolated hosts with IPv4 address, perform a walk on the hostQBulkFilterTableV4.

Similarly, to obtain the list of isolated hosts with IPv6 addresses, perform a walk on the hostQBulkFilterTableV6.

Scenario 4

To delete an already isolated host in the Sensor from the third-party SNMP application:

Set the hostQUserDefFilterAction object of the hostIsolUserDefFilterTable to a value 2. For setting this object, the following indices are needed:

  • IP Address (To be provided in a dot separated format)

  • VidsId (should always be set to 0)

  • AttackId (should always be set to 0)

The above action is applicable to both IPv4 as well as IPv6 entries. Consider the following example:

For isolating a host with IPv4 address of 10.12.12.15, the following OID is to be set with a value 2.

OID - 1.3.6.1.4.1.8962.2.1.2.1.22.6.1.5.10.12.12.15.0.0

Scenario 5

To delete all the isolated hosts in the Sensor from the third-party SNMP application:

Set the hostQDeleteAllFilters object of the hostQConfigGrp to a value 2.

OID - 1.3.6.1.4.1.8962.2.1.2.1.22.1.2.0

Scenario 6

To isolate and remediate an IPv4 host in the Sensor from the third-party SNMP application:

Set the hostQUserDefFilterRemediationV4 object of the hostIsolUserDefFilterTableV4 to a value 1. For setting this object, the following indices are needed:

  • IP Address (To be provided in a dot separated format)

  • VidsId (should always be set to 0)

  • AttackId (should always be set to 0)

The above action is applicable only to IPv4 entries. Consider the following example:

To isolate and remediate a host with IPv4 address of 10.12.12.15, the following OID is to be set with a value 1.

OID - 1.3.6.1.4.1.8962.2.1.2.1.22.6.1.6.10.12.12.15.0.0