The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deploying virtual Network Security appliances using Hyper-V Manager in inline mode

Prev Next

In a typical Network Security inline deployment, port pair A is the inline port pair. The pether3 monitoring interface is connected to the subnet that hosts the on-premises enterprise clients (the client subnet) and the pether4 monitoring interface is connected to a subnet that hosts the Network Security appliance (the server subnet).

Example addresses for the subnets and interfaces are shown below.Example addresses for the subnets and interfaces are shown below.

  • Client subnet—10.100.1.64/27

  • Network Security pether3 interface—10.100.1.69

  • Server subnet—10.100.1.96/27

  • Network Security pether4 interface—10.100.1.100

Note

This procedure assumes that the interface pair

The following task is required to configure a virtual Network Security appliance in inline mode. No additional tasks are required in Hyper-V Manager.

  • Use the policymgr layer3-mode enable command in the Network Security CLI to enable Layer 3 forwarding. For detailed information and additional commands, see the "Layer 3 Forwarding Using VRF Instances" information in the Network Security System Administration Guide.