The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

6. Deploy a Sensor in inline Active Fail-Open mode

Prev Next

Before you begin

  • The Sensor must be set up and have established trust with a Manager server.
  • The Sensor has a free port pair which can be deployed in inline Active Fail-Open mode.
  • It is assumed that you have inserted necessary transceiver modules into the Sensor if you have completed cabling the Sensor and Active Fail-Open module.

When you set up a Sensor for the first time, its ports are disabled by default. The Sensor ports must be manually configured for inline Active Fail-Open operation.

Task

  1. In the Manager, go to Devices → <Admin_Domain_Name> → Devices → <Device_Name> → Setup → Physical Ports.
  2. Double-click port one of the configurable ports, say G2/1.
    A configuration panel appears on the right side of the window.
  3. Under State, select Enabled from the drop-down list.
    You are asked whether you want to continue since this configuration also impacts port G2/2.
  4. Select Yes to continue.
    This enables port G2/1-G2/2.
  5. Under Mode, select Inline Active Fail-Open – Active from the drop-down list.
  6. Under Placement, select Inside Network or Outside Network from the drop-down list, depending on how you want to configure your ports.
    Trellix recommends choosing Gx/1 as Inside Network and Gx/2 as Outside Network.


  7. Click Save.

Results

The Sensor and Active Fail-Open module are set up. When traffic passes through the ports, the port link status changes to Up and turns green.