The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

1/10 Gigabit Modular Passive Fail-Open Kit Quick Start Guide

Prev Next

Trellix Intrusion Prevention System Sensors, when deployed in-line, route all incoming traffic through a designated port pair. However, at times, a Sensor might need to be turned off for maintenance or its ports can go down because of an outage. In such a scenario, you might want to continue allowing traffic to pass through without interruption. For such requirements, you can consider an external device called a fail-open switch. The fail-open switch can either be an active fail-open switch or a passive fail-open switch.

Note

In this guide, unless explicitly stated, Trellix Intrusion Prevention System Manager is commonly referred to as "Manager" and Trellix Intrusion Prevention System Sensor is commonly referred to as "Sensor".

A passive fail-open switch relies on the Sensor to supply a power signal to the switch through a Control cable. The Control port on the Sensor is connected to a Control port on the fail-open switch by a Control cable. While the Sensor is operating, the switch is “on and routes all traffic directly through the Sensor. When the Sensor fails, the switch automatically shifts to a bypass state; in-line traffic continues to flow through the network link but is no longer routed through the Sensor. After the Sensor resumes normal operation, the switch returns to the "on" state, enabling in-line monitoring again. Certain Trellix IPS Sensors have Control ports. These ports are internally wired to the corresponding monitoring port pair.

The table below shows you the various models of passive fail-open switches.

Fail-open switch

SKU

NS9600

NS9500

NS9x00

NS7600

NS7500

NS7x00/NS7x50

Passive-Fiber (850 nm)

10G (50 µm)

IAC-PF85050-

KT1

No

No

No

No

Yes

(supported

on G0 only)

Yes

(supported

on G0 only)

Passive-Fiber (850 nm)

10/1G (62.5 µm)

IAC-PF85062-

KT1

No

No

No

No

Yes

(supported

on G0 only)

Yes

(supported

on G0 only)

Passive-Fiber (1310 nm)

10/1G (8.5 µm)

IAC-PF131010-

KT1

No

No

No

No

Yes

(supported

on G0 only)

Yes

(supported

on G0 only)

Passive-Copper

10/100/1000

IAC-PFOCG-

KT2

No

No

No

No

Yes

(1000Mbps supported on G0 only)

Yes

(1000Mbps supported on G0 only)

Fail-open switch

SKU

NS5x00

NS3600

NS3500

NS3x00

Passive-Fiber (850 nm)

10G (50 µm)

IAC-PF85050-

KT1

Yes

(supported

on G0 only)

No

No

No

Passive-Fiber (850 nm)

10/1G (62.5 µm)

IAC-PF85062-

KT1

Yes

(10/1G supported on G0, but

only 1G supported on G1)

No

No

No

Passive-Fiber (1310 nm)

10/1G (8.5 µm)

IAC-PF131010-

KT1

Yes

(10/1G supported on G0, but

only 1G supported on G1)

No

No

No

Passive-Copper

10/100/1000

IAC-PFOCG-

KT2

Yes

(1000Mbps supported on

G0 and G1 only)

No

No

No

Fiber fail-open switches consist of two types: single mode and multi-mode fibers. The table gives you some details about both types of fiber optic fail-open switches. Such information is important because you must determine the type of fiber optics used in your organization network before you decide which type of fail-open switch to use. It is also important to understand these types because all product documentation for fiber fail-open kits and decals on the fail-open switches display these parameters. The table below shows you the differences between single-mode and multi-mode fiber specifications.

Type

Fiber thickness

Wavelength range

Single mode (Long reach)

8.5 µm

1300 nm to 1550 nm

Multi-mode (Short reach)

50 µm or 62.5 µm

850 nm to 1300 nm

Note

For more details on fail-open kits and Sensor compatibility with various fail-open kit models, refer to the chapter Fail-Open operation in Sensors in the Trellix Intrusion Prevention System Product Guide. Since this Quick Start Guide makes references to information associated with that chapter, keeping an easily accessible copy of it before you begin installing and configuring your fail-open switch will be helpful.