The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

10G/40G Active Fail-Open Bypass Kit Guide

Prev Next

Trellix Intrusion Prevention System Sensors, when deployed in-line, route all incoming traffic through a designated port pair. However, at times, a Sensor might need to be turned off for maintenance or its ports can go down because of an outage. In such a scenario, you might want to continue allowing traffic to pass through without interruption. For such requirements, you can consider an external device called a Fail-Open module. The Fail-Open module can either be an active Fail-Open module or a passive Fail-Open module.

Note

In this guide, unless explicitly stated, Trellix Intrusion Prevention System Manager is commonly referred to as "Manager" and Trellix Intrusion Prevention System Sensor is commonly referred to as "Sensor".

An active Fail-Open module constantly monitors the Sensor state. It does this by sending a heartbeat packet through its ports. The heartbeat packet is sent through one of the Monitoring ports and received through the other, indicating that the Sensor is functioning normally.

This document describes the contents and how to install and use the Trellix 10/40 Gigabit Active Fail-Open Bypass Kit (the Kit) for Trellix IPS Sensors. The 10/40 Gigabit monitoring ports on the IPS Sensor are, by default, fail-closed; thus, if the Sensor is deployed in-line, a hardware failure results in network downtime. Fail-open operation for the monitoring ports requires the use of an optional external Active Fail-Open module provided in the Kit.

During normal Sensor in-line fail-open operation, the Active Fail-Open Kit sends a heartbeat packet for every 50 milliseconds by default (user configurable), to the monitoring port pair. If the Active Fail-Open Kit does not receive 6 heartbeat signals within its programmed interval (300 milliseconds by default; user configurable), the Active Fail-Open kit goes into bypass mode, which removes the Sensor from the traffic path, providing continuous end-to-end data flow but without Inspection.

The Active Fail-Open module, by default, is configured to work in the Active/in-line Switching Mode, where the traffic between the public and private networks is routed through the Sensor. Typically, traffic flows from the Public Network to Port NET0 (network in) and then will be actively transferred by the Active Fail-Open module to Port MON0 (appliance in) and routed through the in-line appliance to Port MON1 (appliance out). Active switching will then route the data through Port NET1 and out to the Private Network. This Mode can operate in reverse as well, with traffic routing from a Private to a Public Network.

In split TAP mode, the ingress traffic into NET0 is mirrored to MON0 while being passed to NET1. At the same time, ingress traffic to NET1 is mirrored to MON1 and passed to NET0. The bidirectional traffic passing from the public network to the private network can be monitored by an appliance with a dual NIC.

When the Sensor fails, the switch automatically shifts to a bypass state; in-line traffic continues to flow through the network link but is no longer routed through the Sensor. In the Bypass Mode, the traffic is routed through a closed loop from port NET0 (network in) to port NET1 (network out) and bypasses the Sensor so that it goes directly from the public network to the private network. This mode can operate in reverse as well, with traffic routing from a private to a public Network.

Once the Sensor resumes normal operation, the switch returns to the "On" state, enabling in-line monitoring again.

The external active bypass enables plug and play connectivity, includes an auto heartbeat, and does not require additional drivers to be installed on any connected appliance. The Active Fail-Open module has one I/O channel, supports one appliance, and provides the following features:

  • Secure Web Management Interface (using HTTPS)

  • CLI access via Serial Console or SSH

  • Support for SNMP version 1, 2c, 3 (SHA, AES)

The table below shows various models of 10/40 Gigabit active fail-open switches and the Sensor models that are compatible with these switches.

Fail-open switch

SKU

NS9600

NS9500

NS9x00

NS7600

NS7500

NS7x00/NS7x50

Active Fiber

10G - SR

(LC 62.5μm)

IAC-4P10FOSR-KIT

Yes

Yes

Yes

Yes

Yes

Yes

Active Fiber

10G - LR

(LC 8.5μm)

IAC-4P10FOLR-KIT

Yes

Yes

Yes

Yes

Yes

Yes

Active Fiber

40G - SR4

(50μm MTP/MPO)

IAC-2P40FOSR4-KIT

Yes

Yes

Yes

No

No

No

Active Fiber

40G -LR4

(LC 8.5μm)

IAC-2P40FOLR4-KIT

Yes

Yes

Yes

No

No

No

Active Fiber

40G - BiDi

(LC 50μm/62.5μm)

IAC-2P40FOBD-KIT

Yes

Yes

Yes

No

No

No

Active Fail-Open Chassis: Module based for 40G

IAC-AFOCH40-KT2

Yes

Yes

Yes

Yes

Yes

Yes

Fail-open switch

SKU

NS5x00

NS3600

NS3500

NS3x00

Active Fiber

10G - SR

(LC 62.5μm)

IAC-4P10FOSR-KIT

Yes

Yes

(supported on ports 5 and 6

and

ocp fiber is supported on ports 11-14)

No

No

Active Fiber

10G - LR

(LC 8.5μm)

IAC-4P10FOLR-KIT

Yes

Yes

(supported on ports 5 and 6)

No

No

Active Fiber

40G - SR4

(50μm MTP/MPO)

IAC-2P40FOSR4-KIT

No

No

No

No

Active Fiber

40G -LR4

(LC 8.5μm)

IAC-2P40FOLR4-KIT

No

No

No

No

Active Fiber

40G - BiDi

(LC 50μm/62.5μm)

IAC-2P40FOBD-KIT

No

No

No

No

Active Fail-Open Chassis: Module based for 40G

IAC-AFOCH40-KT2

Yes

Yes

No

No

You must also make sure you have the requisite SFP+, or QSFP+ when making this choice.

Fiber fail-open switches consist of two types: single mode and multi-mode fibers. The table below gives you some relevant details about both types of fiber optic fail-open switches. This is especially relevant because you must determine the type of fiber that is used in your organization's network before you decide which type of fail-open switch to use. Also, all product documentation for fail-open kits and decals on the fail-open switches will repeatedly refer to these parameters. The table below shows you the differences between single-mode and multi-mode fiber specifications.

Type

Fiber thickness

Wavelength range

Single mode (Long reach)

8.5 µm

1300 nm to 1550 nm

Multi-mode (Short reach)

50 µm or 62.5 µm

850 nm to 1300 nm

Note

For more details about fail-open kits, refer to the section Fail-Open operation in Sensors in the Trellix Intrusion Prevention System Product Guide. Since this Quick Start Guide will make references to information associated with that chapter, keeping an easily accessible copy of it before you begin installing and configuring your fail-open switch will be helpful.

Hardware description

The Active Fail-Open chassis supports both 10G and 40G modules. You can install a maximum of three modules in any combination of 10G and 40G modules. For example, you can install two 10G modules and one 40G module, all three 10G modules, all three 40G modules, and so on.

Front panel

GUID-DD616482-2975-429E-B155-7E9975ABE2DC-low.png
  1. Ethernet management port (1)

  2. RS232(RJ45) Console Port (1)

  3. USB Port (1)

  4. 10G-SR module

  5. 40G-BiDi (Multi Mode)

  6. 10G-LR module

Chassis LEDs

GUID-F00333F9-BB63-4B1D-9FED-EA44D7D0B1F9-low.jpg
  1. Power LEDs (PS1 and PS2)

  2. System Status LEDs (Sys Ok, Sys Up, and ALM)

  3. Management Port Activity

  4. Management Port Link

  5. Console Port (RS232) Activity

  6. Console Port (RS232) Link

  7. Module Power LEDs (M1, M2, and M3)

10G Fail-Open module LEDs

GUID-5EE22494-0737-48A8-A5E4-77BD810C2074-low.png
  1. Heartbeat (HB). It blinks green when heartbeats are sent out.

  2. Bypass / Inline mode. Green color indicates inline mode and amber color indicates bypass mode.

Note

This is an image of a 10G Long Range (LR) Fail-Open module. Similar LEDs are present in the 10G Short Range (SR) Fail-Open module.

40G Fail-Open module LEDs

GUID-E8B1C20F-5589-45DA-B7F2-ED3081D32BE2-low.png
  1. Inline Mode

  2. Non Inline Mode (Bypass/Tap/Disconnect)

  3. Heartbeat (HB)

  4. Heartbeat Expiration (HB Exp)

Note

This is an image of a 40G Long Range (LR4) Fail-Open module. Similar LEDs are present in the 40G Short Range (SR4) and 40G BiDi Fail-Open modules.

Rear panel

GUID-BE4FBE71-CE68-4418-9EDB-FA1535D24169-low.png
  1. Fan units (4)

  2. Power supply 1/2

  3. LED on the Power Supply Unit

    • Power switched on - Solid Green

    • Standby - Blinking Green

    • Power Fail - Solid Red

    • Internal Fan Fail (any of the 4 Fans) - Blinking Red