The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Best Practices

Prev Next

It is recommended to follow these practices while deploying Trellix vIPS in the public cloud environment.

  • Deploying Virtual IPS Sensors in the same region as the virtual machines to be protected minimizes latency.

  • It is recommended not to share a vIPS Controller across different regions.

  • The Trellix IPS Manager should be deployed with a static IP address.

  • The vIPS Controller should be assigned a static IP address. Ensure that the security group allows intended communication only to the assigned static IP address.

  • The Restrict SSH Access to the CLI checkbox must be selected to configure IP addresses or CIDR blocks to restrict SSH access from external invalid IPs.

    To enable this option, navigate to Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings, and under CLI select Restrict SSH Access to the CLI.