The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure advanced device settings

Prev Next

Use the Advanced Device Settings page to configure settings for packet captures, tunneled traffic, and CLI activity.

  1. At an Admin domain level, select Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings.

    The Advanced Device Settings page appears.

    Note

    Alternatively, you can configure these settings for a Sensor from Devices → <Admin Domain Name> → Devices → <Sensor_name> → Setup → Advanced → Advanced Device Settings.

  2. The bytes to be captured when pre-attack capturing is enabled is set in the IPS Policy and is displayed on this page. Valid values are 128 and 256 bytes.

  3. Select the Inspect Tunneled traffic checkbox to parse IPv4 and IPv6 traffic for all supported tunneling protocols like GRE, GTP for malware detection. By default, this checkbox is deselected.

  4. Select a Snort Rule Engine. You can select either the Trellix IPS Snort engine or the Suricata Snort engine. By default, the Snort Rule Engine is set to Trellix IPS Snort.

    Note

    The Suricata Snort engine is not available on NS9600, NS7600 and NS3600 Sensors.

  5. From CLI Activity Logging options, select Log to Device Only, Log to Manager Only, or Log to Device and Manager to track executed CLI commands. By default, this is set to Disabled.

    GUID-E8614595-8789-4388-B2DB-FCB79D03F808-low.png
  6. Select Show CPU usage in the CLI to determine the Sensor load. By default, this checkbox is deselected.

  7. Select Log SSH Access to the CLI to log all attempts to access CLI on the device. By default, this checkbox is deselected.

  8. Use the Restrict SSH Access to CLI checkbox to configure IP addresses or CIDR blocks to restrict SSH access. You can set IPv4 and IPv6 blocks and click Add. By default, this checkbox is deselected.

    Note

    For Virtual IPS Sensors in the AWS environment, this checkbox must be selected and the IPv4/IPv6 CIDR blocks must be added to restrict SSH access from external invalid IPs.

    GUID-635ECBE1-7943-4227-AFE7-E591E821AE63-low.png
  9. Click Save.