The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Types of Firewall policies

Prev Next

You can use two types of Firewall policies in Trellix IPS — advanced and classic. Functionally, these two types are similar. However, as the names might suggest, advanced Firewall policies provide you more options to filter traffic when compared to classic.

Notes:

  • All Sensor models support Classic and Advanced Firewall policies.

Differences between advanced and classic Firewall policies

Advanced

Classic

Options on source or destination of the traffic

Source or destination are based on:

  • Country

  • A host's DNS name

  • A host's IPv4 or IPv6 address

  • An IPv4 or IPv6 address range to which a host belongs.

  • IPv4 or IPv6 networks or a group of IPv4 or IPv6 networks.

  • Windows Active Directory user names and user groups

Source or destination are based on:

  • A host's IPV4 address

  • IPv4 Network

Options on the traffic

Traffic is based on:

  • A specific or a group of Layer 7 applications. For example, you can filter out Yahoo! Games while allowing Yahoo! Mail. These applications can be on the standard or custom communication ports.

  • IP protocol or the TCP/UDP port numbers.

Traffic is only based on the IP protocol or the TCP/UDP port numbers.

Option to enforce the Firewall policy based on time.

Yes. For example, the Sensor can enforce a policy on all weekends only.

No.

Option to define a rule that mandates AD authentication

Yes.

No.