The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deployment of Sensors in inline mode

Prev Next

Inline monitoring mode provides prevention of attacks by enabling Security Administrators to select the types of attacks/traffic to drop, thus preventing the negative end-system impact common with today's network attacks. Inline mode is achieved when the Sensor is placed directly in the path of a network segment, becoming, essentially, a "bump in the wire," with packets flowing through Sensor. In this mode, the Sensor inspects all traffic at wire-speed and can prevent network attacks by dropping malicious traffic in real time—the Sensor actually ends the attacking transmission before it can reach and impact the target. Preventative actions can operate at a highly granular level, including the automated dropping of DoS traffic intended for a specific host.

When operating in inline mode, network segments are connected to two wire-matched Sensor ports (For example, peer ports G0/1 and G0/2), and packets are examined in real time as they pass through the Sensor. In this mode, a packet comes in through the first interface of the pair of the Sensor and out the second interface of the pair. The packet is sent to the second interface of the pair unless that packet is being denied or modified by a signature.

The Sensor ports are configured by default for monitoring in inline mode; that is, connected inline on a network segment (For example, between a switch and a router or two switches).

Note

This change will not override user-configured settings.