The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Advantages

Prev Next

The following are the advantages of integrating Trellix IPS with IVX.

  • When a supported file is being downloaded into your network, it can be analyzed in depth using the IVX engine. This fortifies your already strong anti-malware defense with Trellix IPS.

  • IVX appliance and IVX Cloud are not inline devices. They can receive files from IPS Sensors for malware analysis. So, it is possible to deploy them in such a way that you obtain the advantages of an inline anti-malware solution but without the associated drawbacks.

  • IVX appliance and IVX Cloud do not sniff or tap into your network traffic. They analyze the files submitted to them for malware. This means that you can place the IVX appliance or IVX Cloud anywhere in your network as long as they are reachable to the Manager and the Sensor.

  • IPS deployments on 11.1 Update 4 and later releases provide capability to configure up to 5 broker nodes within IVX cluster. The Sensor submits files to the broker nodes in round robin manner for analysis and result polling, meaning better file submission rate and high availability are achieved.

  • Files are concurrently analyzed by various engines. So, it is possible for known malware to be blocked in almost real time.

  • Consider a host downloaded a zero-day malware, but a Sensor that detected this file submitted it to the IVX appliance or IVX Cloud. Based on how you have configured the Advanced Malware policy, it is possible for the Manager to add this malware to the block list of all the Sensors in your organization's network. Thus, the chances of the same file re-entering your network is reduced.

  • Even the first time when a zero-day malware is downloaded, you can contain it by quarantining the affected hosts until they are cleaned and remediated.