The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix IPS policies

Prev Next

In Trellix IPS, all the major features, including IPS, are policy based. For example, for IDS/IPS, you use IPS policies and recon policies. Similarly, for the Firewall feature, you use the Firewall policies. This chapter introduces the security policies in Trellix IPS and provides the conceptual details for IPS policies. Other security policies such as the Firewall policies and Advanced Malware policies are discussed in their respective sections.

Generally, a security policy in Trellix IPS is a set of rules defining the activity you want the Sensors to detect and how you want to respond if that activity is detected. The activity that a rule is to detect need not be a malicious one always. For example, you can define a Firewall rule to always allow all types of traffic from your CEO's laptop. Creating a policy enables you to define a set of rules that define the different services, protocols, and/or product implementations in your network.

The following are the type of security policies in Trellix IPS:

  • IPS policies
  • Reconnaissance policies
  • Advanced Malware policies
  • Inspection Options policies
  • Firewall policies
  • QoS policies
  • Connection Limiting policies

The best practice for protecting against misuse is not to apply a one-size-fits-all policy to the entire network, but to create multiple specific policies which focus on the specific needs of unique segments of your network. Except for some policies, Trellix IPS enables rule-based policies for your network resources, right down to individual sub-flows of network traffic. For certain policy types, several pre-configured policies are supplied for immediate application.

Imagine a network that has Windows and Linux hosts interspersed across it. The best approach for IPS here is to apply a policy that includes attacks for both Windows and Linux on all ports through which their traffic flows. If this network happens to be controlled in such a way that the traffic from all Windows hosts is flowing through one segment of the network and the traffic from all Linux hosts is flowing through a different segment, you could connect these different segments to different monitoring ports. You could then apply Windows-specific and Linux-specific policies to the respective ports. In doing so, you would minimize the chance of false positives and reduce the quantity of scanning required on each port.