The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a port cluster

Prev Next

The Port Clusters action enables multiple Sensor ports to be grouped together for the effective monitoring of asymmetric environments. Asymmetric networks are common in load balancing and active/passive configurations. Port clusters normalize the impact of traffic flows split across multiple interfaces, thus maintaining state to avoid information loss.

Once configured, an interface group appears in the IPS interfaces as a single interface node (icon) under the <Device Name> where it is located. All of the ports that make up the interface are configured as one logical entity, keeping the configuration consistent.

Caution

If you decide to change your settings after the initial interface group configuration, all of the previous configurations performed for the interface group are erased in favor of the new port configuration. This can affect sub-interfaces and policy settings.

  1. Select Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → Port Clusters.

    Port cluster list area
    Port cluster list area


  2. Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png.

  3. Type a Name.

  4. Select a Template Port from the drop-down list.

    • For standalone Sensors, the template port will display the port pair (G3/3-G3/4)

    • For a stack of Sensors, the template port will display the member Sensor along with the port pair (<Stackname_node-Id>/G3/3-G3/4).

      Note

      G0/1 and G0/2 ports will be excluded from the drop-down list because they are used to create the stack.

    • For HA pair of Sensor stacks, the template member port will display both peer member sensors along with the port pair (<Stackname_node-Id>:<Stackname_node-Id>/G3/3-G3/4).

      Note

      G1/1 and G1/2 ports will be excluded from the drop-down list because they are the interconnect ports used to create HA pairs.

    The template member port determines the policy that is enforced by the group.

    Note

    An interface changed from Dedicated to VLAN or CIDR traffic types is not eligible for interface group combination until VLAN or CIDR IDs are added.

  5. Click Next.

    Create Cluster dialog
    Create Cluster dialog


  6. Select interfaces to add to the group.

    For Sensors in a stack, the list of available ports displays interfaces of each member Sensor in the stack.

  7. Click Save to complete the creation of a port cluster, or click Cancel to exit the window.

    If interfaces are functioning as a port pair, they cannot be separated within an interface group.

    Add/Delete Interfaces To Port Cluster Member dialog
    Add/Delete Interfaces To Port Cluster Member dialog


  8. Download the changes to your Sensor by clicking Deploy Pending Changes.