The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Working with firewall policies

Prev Next

Review the following points while working with Firewall policies:

  • You cannot set explicit access rules for protocols that negotiate ports dynamically, with the exception of FTP, TFTP, and RPC services. Protocols, such as H.323 and Netmeeting, which negotiate the data channel separately from the control channel, or negotiate ports that do not follow a standard, are not supported. However, you can configure access rules to explicitly deny these protocol instances by denying the fixed control port.

  • For RPC services, you can configure explicit permit and deny rules for RPC as a whole, but not its constituents, such as statd and mountd.

  • Protocols or services, such as instant messaging and peer-to-peer communication that use dynamic ports, are not supported.

  • An alternative option for denying protocols that use dynamic ports is to configure IDS policies to drop the attacks that are detected in such transmissions. Trellix IPS detects use of and attacks in multiple such programs as Yahoo Messenger, KaZaA, IRC, and so on.

  • There is a limit on the number of access rules that can be supported by various Sensor models.

For more information, see Firewall policies.