The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure response ports

Prev Next

Utilizing device response ports enables your device to send preset responses (enabled in policy configuration), such as a TCP reset, as well as post-detection responses, such as firewall blocking of traffic, upon detection of malicious traffic. The device response ports are most commonly used with an external tap operating configuration. The other operating modes allow responses to be injected back through the interface ports. Since responses cannot be injected into a segment through an external tap, response port configuration is necessary.

  1. Go to Devices → <Admin Domain Name> → Devices → <Device_Name> → Setup → Physical Ports.

  2. Click on the Response Ports tab.

  3. Double-click on the row of the response port to be configured. The Response Port Details window is displayed.

    Configure Response Port window
    Configure Response Port window


  4. Select a Speed (Duplex). The following are the supported options for NS-series Sensor models.

    • NS-series:

      • Auto-Negotiate

      • 1 Gbps

      • 10 Gbps

  5. Select the State as either Enabled (On) or Disabled (Off). For example, you need to disable the port if you connect a new wire, then enable it after re-connection.

  6. Select the network component the response port connects to (Connected To): either a Switch or a Router.

    • If you select Router, in the Virtual MAC Address type the MAC address of the router to which you are connecting. The MAC address cannot be the broadcast address "ff:ff:ff:ff:ff:ff."

  7. Click Save to save your port changes.