The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure 40 Gbps (QSFP+) monitoring ports

Prev Next

Configuration of monitoring ports enables you to set the operating mode of your ports, change port speeds or specify whether you are using Trellix certified modules, and/or choose the corresponding response port for device action.

  1. Go to Devices → <Admin Domain Name> → Devices → <Device_Name> → Setup → Physical Ports.

  2. Double-click on the row of numbered 40 Gbps (QSFP+) monitoring port. The Monitoring Port Details window is displayed.

    Configure Monitoring Port window
    Configure Monitoring Port window


    Note

    The speed is automatically set to 40 Gbps on the 40 Gigabit Ethernet ports. However, you can specify whether the modules are Trellix Certified.

  3. Select the State as either Enabled (on) or Disabled (off). The Link displays Up (on) or Down (off) accordingly.

    Note

    If your Link displays as Down and your State is Enabled, there may be a problem. Check the system faults in the Faults tab in Logs page for more information.

  4. Select a Mode from the following:

    Caution

    Your device connections must match the selected operating mode for correct system functionality. Improper deployment may result in system faults, including missed attacks and system failure.

    • Inline Fail Open – Active

    • Inline Fail Closed

      Note

      Inline fail-open and Inline fail-closed are determined by how the port cables are connected. Fail-open operation for GE ports requires use of the optional Bypass Switch provided in the Gigabit Optical Fail-Open Bypass Kit (sold separately). You should not select the Inline Fail Open option if the optional external Bypass Switch is not present.

    • SPAN or Hub

    • Tap

      GE ports can only be configured for External Tap mode.

      Note

      The Inline Fail Open – Passive mode is not supported with the NS9x00-series Sensors. Since the QSFP+ transceivers are supported only with the NS9x00-series Sensors, the Inline Fail Open – Passive mode is not supported as well.

    If a port is functioning as part of a Port Pair, the Peer Port is listed. For example, if port G2/1 is configured for Tap mode, port G2/2 is listed as the Peer Port. All ports are wire-matched internally with a single peer. For example, G2/1-G2/2 make up a port pair.

  5. Select Placement of your network where the current port is connected: Inside Network or Outside Network. This step applies to Tap or Inline modes only.

  6. Wherever applicable, select a Response Port. The following choices are available:

    • This Port: Respond out of the detection port to the segment. This is selected by default for Inline and SPAN operating modes.

    • R1: Sends responses through a R1 port

    • R2: Sends responses through a R2 port

    Tip

    You can assign a response port to more than one device monitoring port. However, knowing where your response ports are connected in the network will make for the best response system.

  7. Click Save to save changes.

    A confirmation page is displayed. A window is displayed to confirm the changes. Click OK to confirm changes.