The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

arp spoof

Prev Next

This command enables or disables the ARP spoofing detection. It is used in conjunction with the Trellix IPS ARP spoofing detection feature.

Syntax:

arp spoof <enable><disable>

Parameter

Description

enable

Enables ARP spoofing detection

disable

Disables ARP spoofing detection

Default Value:

It is disabled by default.

Applicable to:

NS-series and Virtual IPS Sensors. For Virtual Security System instances, this command is available in debug mode.