To function as a HA pair, the two Trellix IPS Sensors must be the same model and have the same Sensor image (Sensor software version).
You can create Sensor fail-over pairs even if the monitoring ports are in different operating modes, that is some ports in Inline, some in SPAN, and some in Tap mode. For example, you can create an NS7100 fail-over pair with monitoring ports G0/1-G0/2, G3/1-G3/2, G3/3-G3/4 and G3/5-G3/6 deployed in Inline mode and port G3/7 deployed in SPAN mode.
In some Sensor models, a monitoring port is configured for the primary-secondary heartbeat. In such cases, the peer monitoring port is disabled. For example, in NS7200, monitoring port G0/1 is used for the heartbeat and when you create the HA pair, port G0/2 is disabled.
Note that the port deployment modes of both the primary and secondary Sensors must be the same. For example, if port G3/1 is deployed in SPAN mode in the primary then G3/1 of the secondary must be deployed in SPAN mode as well.
By design, there will always be a certain amount of independence among the Sensors. For example, the solution must be flexible enough to handle a network on which a primary path runs at 100 Mbps full duplex, but the secondary path runs at only 10 Mbps half duplex.
This is the proper time to configure each port pair to fail open or closed. In previous Trellix IPS versions, you could only configure each Sensor in a HA pair to fail closed. Now, you can configure one Sensor to fail closed and the second to fail open.
Note
There is no special requirement for a minimum Sensor software version to be able to configure one Sensor to fail closed and the other to fail open.
Before creating a HA pair, you have to change the Media Type to Copper in the Physical Ports page when using copper SFP's. A port mismatch error may be generated on the Faults tab in the Logs page as the default media type configuration is Fiber. If such an error is generated, you may have to delete and recreate the HA pair.
You can configure the port speed and operating mode from the Physical Ports page in the Manager:
.png)