The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Details of how the integration works

Prev Next

Following is the procedure and process flow while integrating Trellix IPS with MVX.

Before you begin, make sure you configured the VX appliance and it is active. Make a note of the broker IP address and the user credentials of the appliance. Also, whether CA signed or Self-signed certificate is configured on the node. For more information, refer to the respective documentation.

  1. You configure MVX integration details at the admin domain level and/ or the device level.
  2. Verify that the:
    1. Manager to VX Authentication Status is Successful
    2. Sensor to VX Authentication Status is Successful
    3. Cluster Status is Ready
  3. You enable MVX as one of the malware engines in the corresponding Advanced Malware policy. For the sake of explanation, assume that you have enabled all the engines for all the file types.

    Note

    Trellix IPS follows down selection logic for file analysis. The file is submitted to the engines in order of their placement. Refer to Step no. 8 for the sequence. Based on the engine response, the IPS Sensor takes the response action. Consider that you have configured high-severity malware to be blocked by the Sensor. Trellix GTI File Reputation configured in reports a file as high-severity malware. Then, the Sensor blocks this file even before receiving the results from the MVX engine.

  4. You have applied this Advanced Malware policy to the required inline ports.

    Note

    The appliance can be used with SPAN and tap ports. However, similar to other malware engines, response actions, such as Block and Send TCP Reset, might not have the desired effect since the file might have reached the target host.

  5. If the Sensor detects a supported file type being transferred over HTTP, FTP or SMTP (encoded using Base64 only), it extracts the file and checks it against its allow list and then its block list.
  6. Assume that the file's hash value is not listed in the Sensor's allow or block list. The Sensor stores the file on the disk as the user downloads it. The Sensor holds the last packet from the user for 6 seconds, while it awaits the results from any of the configured malware engines.
  7. Based on VX appliance analysis, Trellix IPS determines the analysis method and the reports to be generated:
    • If the VX appliance responds with a malware score using cached result that meets the Action Thresholds for alerting in the Advanced Malware policy, the Sensor raises MALWARE: Malicious File Detected by MVX alert and takes the other configured response actions.
    • If the VX appliance does not respond with a malware score from cached result, the Sensor uploads the file to VX and raises an informational alert: MALWARE: File Submitted to MVX for Analysis . The Manager polls the VX appliance for the file analysis result and updates the alert as malicious/clean.

    Note

    The Sensor maintains a cache of the files that were submitted to it earlier. The VX appliance too maintains a cache of the files submitted earlier and the info can be referred by any Sensor device connected to the appliance. This way, any file that comes for analysis is directly compared with the files saved in the Sensor and VX cache. If there is a file match, the Sensor takes an action automatically without having to re-analyze it, thereby saving the analysis time.

    Recall that VX must respond within the file scan timeout for the Sensor to function as explained above.

    Note

    File submission timeouts might be seen for large files if:

    • The VX appliance is placed in a remote location
    • There is a latency in the network

    To avoid such time outs, it is recommended to deploy the VX appliance near the Sensor and maintain proper network connectivity.

  8. Trellix IPS performs malware analysis on files in the following sequence:
    • NS-series: Allow and Block Lists → TIE/GTI File Reputation/Trellix Cloud (for apk files) → Trellix IPS Analysis → Gateway Anti-Malware → MVX → Trellix Intelligent Sandbox
  9. The Manager polls the VX appliance for the submitted files as mentioned in Step no. 7. When the results are received, the Manager updates the record in the Malware Files page.
  10. If you had configured the Add to Block List action threshold in the Advanced Malware policy, the Manager can include the MD5 hash of this file in the block list of all its Sensors. Therefore, when the same file is detected by any of the Sensors, it is blocked by that Sensor itself. This reduces the chances of such malware entering your network again.

    Note

    Trellix recommends that you verify how the Advanced Malware feature works for a period of time, fine-tune it until it functions as expected, and only then enable the Add to Block List action threshold in the Advanced Malware policies.

What happens in case of MDR?

  • You configure MVX in the Active Manager. It takes 15 minutes for this configuration to be copied to the Standby Manager. Alternatively, you can use the Retrieve Configuration feature in the Standby Manager to immediately copy the MDR configuration.

    Note

    The VX appliance configuration cannot be manually configured on the Standby Manager. The Save button is hidden from the users and an Informational message is displayed on the MVX Integration page of the Standby Manager for the same.

  • When a Sensor submits a file to the VX appliance, it informs both the Managers. So, both the Managers query the appliance separately for the results of the file.
  • Every 10 minutes, both the Managers cross-check their malware report data from the VX appliance and ensure that the data is synchronized.

What happens in case of Sensors in failover?

  • When you configure the integration for the failover Sensors, both the Sensors establish separate communication channels with the VX appliance. So, VX considers them to be different users. It sends the update only to the Sensor that submitted the file.
  • The file is extracted only by the Sensor that detected it. If a Sensor goes down within the packet hold time interval, based on the port configuration, the file might be forwarded without malware analysis or dropped.
  • If the Sensor goes down after the packet hold time interval but before the file session time interval, the update from VX appliance is lost since it is sent only to the Sensor that submitted the file.