The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure device profiling per device

Prev Next

To access device profiling settings in the Manager, perform the following steps:

  1. The Manager allows you to define settings for the device as follows:

    To modify device profile settings at the device level, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced.

  2. Click Passive Device Profiling.

    The Passive Device Profiling page appears.

    Passive Device Profiling Page
    Passive Device Profiling Page


  3. Select the State.

    If you select Profiling enabled for the entire device or Enable profiling per interface, proceed with the configuration. If you select Profiling disabled for the entire device, click Save to complete the configuration.

  4. You must now decide whether you want to inherit settings from the IPS admin domain by selecting the Inherit Settings checkbox.

    Note

    Selecting this checkbox means either the entire device or the interfaces will inherit global settings and no further options will appear in this page. If you have not chosen to inherit settings from the admin domain, proceed to Step 5.

  5. Select the techniques that you want to use for device profiling.

    You will find three checkboxes:

    • DHCP indicates the use of DHCP DISCOVER and REQUESTS packets for device profiling.

    • TCP indicates the use of TCP SYN and SYN + ACK packets for device profiling.

    • HTTP indicates the use of HTTP User Agent field for device profiling.

  6. Specify the Profile Expiration duration.

    This timer ensures periodic re-profiling of a device to detect any changes in that period. Trellix recommends this duration be set at 5 minutes. However, you can increase it up to 12 hours.

  7. Specify the Endpoint Inactivity Timer duration.

    This value specifies the duration after which information for a device is considered invalid. It occurs when the host has remained idle for the said duration. This timer ensures that the Sensor will renew its detection of the IP address if it is noticed again. Trellix recommends this duration be set at 1 hour. However, you can increase it up to 24 hours.

  8. If you selected DHCP as your preference, you will need make sure that DHCP traffic actually passes through the Sensor monitoring port. If not, you have the provision to configure the monitoring port of a Sensor with an IP address to receive DHCP traffic through a relay agent. Provide these settings by selecting Bind an IP Address For Copied DHCP Traffic?.

    Using the DHCP Relay Agent

    A DHCP relay agent is any host that facilitates transfer of DHCP packets between clients and servers. Relay agents are used to forward requests and replies between clients and servers when they are not on the same physical subnet. In the illustration provided below, Sensor A exists in a specific physical subnet and the clients for which the Sensor needs to monitor DHCP traffic exist in another physical subnet. In such a network, you can use a DHCP Relay Agent to make sure that DHCP traffic from the clients in the other subnet reaches Sensor A. To accomplish this, you will need use a device, such as a router (we will consider a CISCO router that runs CISCO IOS software). The DHCP client broadcasts a request for an IP address and additional configuration parameters on its local LAN. Router 1, which plays the role of a DHCP relay agent, picks up the broadcast and generates a new DHCP message to send out on another interface. As part of this DHCP message, the relay agent inserts the IP address of the interface containing the ip helper‑address command into the gateway IP address (giaddr) field of the DHCP packet, which will be the Sensor monitoring port IP address, 10.32.221.2. The DHCP relay agent sends the local broadcast, via IP unicast, to the Sensor monitoring port address, 10.32.221.2, specified by the ip helper‑address interface configuration command. This enables Sensor A to monitor DHCP traffic in another physical subnet.

    DHCP Relay Agent
    DHCP Relay Agent


    1. Select the Designated Port which will function as the monitoring port.

    2. Enter the Port IP Address, Network Mask, Default Gateway, and VLAN ID of the Sensor monitoring port.

      This is the same IP address that you will provide in the relay agent configuration settings.

  9. Click Save.