The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure your deployment using the Manager

Prev Next

After you are up and running and reviewing the data generated by the system, you can further configure and maintain your system. For example, you can do the following:

  • Apply IPS policies to each interface of your multi-port Sensor (instead of applying one policy to all interfaces, as when you chose the default policy to establish Sensor-to-Manager communication) — You can ensure that all of your interfaces use IPS policies specifically for the areas of your network they are monitoring. For example, you can apply a Web Server policy to one interface, Mail Server policy to another, Internal Segment policy to another, and so on. More information on the provided policies is available in the subsequent sections.

  • Configure responses to alerts — Developing a system of actions, alerts, and logs based on impact severity is recommended for effective network security. For example, you can configure Trellix IPS to send a page or an email notification, execute a script, disconnect a TCP connection, send an ICMP Host Not Reachable message to the attack source for ICMP transmissions, or send address-blocking for a host.

  • Filter alerts — An ignore rule limits the number of alerts generated by the system by excluding certain source and Destination IP address parameters. If these address parameters are detected in a packet, the packet is not analyzed further (and is automatically forwarded when in Inline mode).

  • View the system's health — The Faults tab in the Logs page details the functional status for all of your installed Trellix IPSsystem components. Messages are generated to detail system faults experienced by your Manager, Sensors, or database. For more information, see the Troubleshooting section.

  • View a port's performance — The Traffic Statistics action enables you to view performance data for a port on a Sensor. You can view the statistics of the total number of packets received (Rx) and transmitted (Tx) for a given device per port. You can also view the reason and the packet drop rate on a port for a device. The data collected is a reflection of the traffic that has passed through the port.

  • View datapath statistics for ports — Datapath statistics include data on the traffic such as number of frames, bytes, and count of the traffic that are received and sent by the Sensor ports. It also contains the count of error packets for TCP, IP, and UDP traffic. These statistics can be viewed by using the datapath intfportcommand. For more information, see the CLI commands section.

  • Back up all or part of your Manager configuration information to your server or other location. Trellix IPS provides the following backup options:

    • All Tables — All Trellix IPS data (configuration, audit, and alert)

    • Config Tables — All information related to system configuration, such as port configuration, users, admin domains, policies for all Trellix IPS resources in all domains

    • Audit Tables — All information related to user activity and alerts

    • Event Tables — All information related to alerts, packet log host and Sensor performance

    • Trend Tables — All information related to trend patterns of alerts and Sensor performance events

    Note

    The All Tables and Audit Tables options can be rather large in size, depending upon the amount of alert data in your database. Trellix recommends saving these types of backups to an alternate location.

    For more information on how to back up your data, see the Manager Administration section.