The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Benefits of running inline mode

Prev Next

The benefits to using Sensors in inline mode are:

  • Protection/Prevention — Prevention is a feature unique to inline mode. When running inline, a Sensor can drop malicious packets and not pass them through the network. This acts sort of like an "adaptive firewall," with your detection policy dictating what is dropped. Furthermore, when dropping packets, Trellix IPS is very precise and granular. The Sensor can drop only those packets it identifies as malicious or all of the packets related to that flow (a choice that is user configurable).

  • Packet "scrubbing" — In addition to dropping malicious traffic, Trellix IPS can scrub—or normalize—traffic to take out any ambiguities in protocols that the attacker may be using to try to evade detection. Current IDS products are susceptible to these techniques, and an example of this attempt is IP fragment and TCP segment overlaps. The Sensor can reassemble the IP fragments and TCP segments and enforce a reassembly mode of the user's choice to accept either the old or the new data.

  • Processing at wire-speed — Sensors are able to process packets at wire rates.

    In inline mode, the Sensor logically acts as a transparent repeater with minimal latency for packet processing. Unlike bridges, routers, or switches, the Sensor does not need to learn MAC addresses or keep an ARP cache or a routing table.

  • Traffic prioritization – When you deploy a port in inline mode and enable the inline traffic prioritization feature, the Sensor prioritizes packets emerging from the port in inline mode, during heavy network load conditions, over packets emerging from a port in SPAN mode.

    The Sensor periodically checks for latency in inline packets. If latency is higher than a stipulated limit and, at the same time, there are several inline packets and SPAN packets in queue to be analyzed by the Sensor, some of the SPAN packets are dropped to prioritize inline packets.

    When traffic density returns to normal operating levels, the Sensor stops prioritizing inline packets and traffic is analyzed in the order that it arrives.

    Note

    Prioritization of inline traffic is disabled by default. You can view or change its status only through the Sensor CLI Debug mode using the following commands:

    • show inline traffic prioritization status – Displays whether it is enabled or disabled.

    • set inline traffic prioritization <enable | disable> – Enables or disables the feature.