Trellix Intrusion Prevention System combines Trellix Intrusion Prevention System Sensor and Trellix Intrusion Prevention System Manager for the accurate detection and prevention of attacks using signature detection, zero-day attacks using anomaly detection, denial of service (DoS) attacks, and distributed denial of service (DDoS) attacks.
Sensors can be deployed in a variety of topologies such as SPAN or Hub, Tap, In‑line fail‑closed, and In‑line fail‑open. Additionally, Sensors support features like interface groups or port clustering where multiple ports on a single Sensor can be grouped together for effective traffic monitoring, particularly useful for asymmetrically routed networks. Trellix IPS also provides high‑availability; if one Sensor fails, the standby Sensor automatically takes over and continues to monitor the traffic with no loss of session state or degradation of protection level.
The following are the currently available NS‑series Sensor models for IPS/IDS: NS9600, NS9500(1.10), NS9500(1.00), NS9300(P & S), NS9200, NS9100, NS7600, NS7500, NS7350, NS7250, NS7150, NS5200, NS5100, NS3600, NS3200, and NS3100.