The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

6. Deploy a Sensor in inline Active Fail-Open mode

Prev Next

Prerequisites:

  • The Sensor must be set up and have established trust with a Manager server.

  • The Sensor has a free port pair which can be deployed in inline Active Fail-Open mode.

  • It is assumed that you have inserted necessary transceiver modules into the Sensor if you have completed cabling the Sensor and Active Fail-Open module.

To configure a fail-open switch you must configure the port pair to operate as an inline fail-open port.

  1. After cabling the Sensor and the fail-open switch, log on to your Manager.

  2. Go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Physical Ports.

  3. Double-click port one of the configurable ports, say 1/1 (Gx/1).

    A configuration panel appears on the right side of the window.

  4. Click the State drop-down and select Enabled.

    This will impact the port 1/2 (Gx/2) as well. So, ports 1/1-1/2 (Gx/1-Gx/2) are enabled.

  5. Click the Certification drop-down and select an option depending on your requirement.

    Note

    Based on the I/O module and port selected, you may be required to select the Auto Negotiate checkbox and set the speed under Maximum Negotiable Speed (Duplex). For certain ports, the speed is automatically selected and you will not be able to edit it.

  6. Click the Media Type drop-down and select Copper or Fiber depending on the cable type you are using.

  7. Click the Mode drop-down and select Inline Fail Open – Active.

    This means port pair 1/1-1/2 is now configured for inline fail-open.

  8. Under Placement, select Inside Network or Outside Network from the drop-down list, depending on how you want to configure your ports.

    Placement refers to the area of the network which that individual port is connected.

    Configuration of a port pair for inline fail-open active operation
    Configuration of a port pair for inline fail-open active operation


  9. Click Save.

    Note

    An Alert! pop-up displays stating the changes made on port x/1 impacts x/2 as well. Click OK.

If traffic is passing through the ports, you will notice the port link status changes to Up and goes green.