The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

1/10 Gigabit Modular Active Fail-Open Kit Quick Start Guide

Prev Next

Trellix Intrusion Prevention System Sensors, when deployed in-line, route all incoming traffic through a designated port pair. However, at times, a Sensor might need to be turned off for maintenance or its ports can go down because of an outage. In such a scenario, you might want to continue allowing traffic to pass through without interruption. For such requirements, you can consider an external device called a fail-open switch. The fail-open switch can either be an active fail-open switch or a passive fail-open switch.

Note

In this guide, unless explicitly stated, Trellix Intrusion Prevention System Manager is commonly referred to as "Manager" and Trellix Intrusion Prevention System Sensor is commonly referred to as "Sensor".

An active fail-open switch constantly monitors the Sensor state. It does this by sending a heartbeat signal through its ports. The heartbeat signal is sent through one of the Monitor ports and received through the other, indicating that the Sensor is functioning normally.

The table below shows you the various models of active fail-open switches.

Fail-open switch

SKU

NS9600

NS9500

NS9x00

NS7600

NS7x00/NS7x50

Active-Fiber (850 nm)

10G (62.5 µm)

IAC-AF85010-

KT1

Yes

Yes

Yes

Yes

Yes

Active-Fiber (1310 nm)

10G (8.5 µm)

IAC-AF131010-

KT1

Yes

Yes

Yes

Yes

Yes

Active-Fiber (850 nm)

1G (62.5 µm)

IAC-AF85062-

KT1

Yes

Yes

Yes

Yes

Yes

Active-Fiber (1310 nm)

1G (8.5 µm)

IAC-AF131085-

KT1

Yes

Yes

Yes

Yes

Yes

Active-Copper

10/100/1000 module

IAC-AFOCG-

KT2

Yes

Yes

Yes

Yes

Yes

Active Fail-Open

Chassis

IAC-AFOCH-

KT2

Yes

Yes

Yes

Yes

Yes

Fail-open switch

SKU

NS5x00

NS3600

NS3500

NS3x00

Active-Fiber (850 nm)

10G (62.5 µm)

IAC-AF85010-

KT1

Yes (supported on G0 only)

Yes

(supported on ports 5 and 6

and

ocp fiber is supported on ports 11-14)

No

No

Active-Fiber (1310 nm)

10G (8.5 µm)

IAC-AF131010-

KT1

Yes (supported on G0 only)

Yes

(supported on ports 5 and 6)

No

No

Active-Fiber (850 nm)

1G (62.5 µm)

IAC-AF85062-

KT1

Yes

Yes

(supported on ports 5 and 6

and

ocp fiber is supported on ports 11-14)

No

No

Active-Fiber (1310 nm)

1G (8.5 µm)

IAC-AF131085-

KT1

Yes

Yes

(supported on ports 5 and 6)

No

No

Active-Copper

10/100/1000 module

IAC-AFOCG-

KT2

Yes

Yes

(supported on ports 1-4 and 7-10

and

ocp copper is supported on ports 11-14)

No

Yes

Active Fail-Open

Chassis

IAC-AFOCH-

KT2

Yes

Yes

(supported on ports 5 and 6

and

ocp fiber is supported on ports 11-14)

No

Yes

You must also make sure you have the requisite SFP/SFP+'s, QSFP+, or QSFP28 when making this choice.

Fiber fail-open switches consist of two types: single mode and multi-mode fibers. The table below gives you some relevant details about both types of fiber optic fail-open switches. This is especially relevant because you must determine the type of fiber that is used in your organization's network before you decide which type of fail-open switch to use. Also, all product documentation for fail-open kits and decals on the fail-open switches will repeatedly refer to these parameters. The table below shows you the differences between single-mode and multi-mode fiber specifications.

Type

Fiber thickness

Wavelength range

Single mode (Long reach)

8.5 µm

1300 nm to 1550 nm

Multi-mode (Short reach)

50 µm or 62.5 µm

850 nm to 1300 nm

Note

For more details about fail-open kits, refer the chapter Fail-Open operation in Sensors in the Trellix Intrusion Prevention System Product Guide. Since this Quick Start Guide will make references to information associated with that chapter, keeping an easily accessible copy of it before you begin installing and configuring your fail-open switch will be helpful.

Working

To begin with, the Trellix IPS Sensor Sensor and fail-open switch need to be appropriately cabled with each other. The IPS Sensor ports are then configured for fail-open operation. For more details about configuring Sensor monitoring ports, refer to the section Configure Sensor Monitoring Ports.

After connecting and configuring the Sensor and fail-open switch, the switch begins to send a heartbeat signal to the Sensor. Each heartbeat signal, once sent returns from the Sensor to the fail-open switch. When the fail-open switch does not receive this response from the Sensor for a specified period, the switch removes the Sensor from the data path and begins to route traffic to the network through its ports.

A 1G fiber or a Copper fail-open switch sends a heartbeat signal every second. When the fail-open switch does not receive a response for 3 seconds, it changes its working mode to "unknown" and begins to route traffic through itself.

A 10G fiber fail-open switch sends a heartbeat signal every 10 milliseconds (ms). If the fail-open switch does not receive a response from the Sensor for 100 ms, it removes the Sensor from the data path and begins to route traffic through its own ports.