The following are some points that you can consider to troubleshoot issues related to user-based access rules:
Make sure that above your user-based access rules, there are rules that allow DNS, DHCP, and AD traffic to the corresponding servers.
If a user-based rule is not working as expected, change the Source User to any and see if the rule is working fine.
If you are unable to view the users or user groups in the Firewall page, check the communication between the Manager and the Trellix Logon Collector.
CLI commands related to user-based access rules:
show userInfo stats: Displays the number of full (bulk) updates and incremental updates to the Sensor. Also, displays the number of users, user groups, and host IP addresses currently present in the Sensor.
The Manager raises a fault message for the following conditions :
The Manager is unable to contact Trellix Logon Collector.
The number of IPs to users mapping has exceeded 100,000.
The number of users has exceeded 75,000.
The bulk update from the Manager to the Sensor is more than 25 MB in size. In this case, the fault is raised and the Manager aborts the update.
When the user groups limit exceed the specified values, the following faults are raised:
AD user groups size exceeded
TLC IP-User mapping/ User count exceeds limit
TLC Group Size fault
For more information on these faults, refer to Manager faults in the Troubleshooting section of this guide.