The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Device Manager in Trellix IPS Central Manager

Prev Next

The Devices → Manager Management → Device Manager page in Central Manager provides visibility to all devices configured with each of the associated Managers, such as NS-series Sensors, M-series Sensors, Virtual IPS Sensors, and NTBA Appliances. You can view the devices configured in an admin domain as well as those configured in the child admin domains of any Manager. The Device Manager grid view in the Central Manager loads and displays device details in real-time, which include general device information, system health, and faults status, thus offering a comprehensive view of all devices available on individual managers in a single page.

If any of the Managers managed by the Central Manager is in an MDR pair, the Central Manager fetches and displays device data from the active Manager. In case the Central Managers are in an MDR pair, the standby Central Manager displays same device details in the Device Manager page as visible in the active Central Manager.

Note

You cannot edit, modify, or save any device-related information in the Device Manager page in Central Manager. It only provides read-only view of the device details configured with the Managers.

Device Manager page in Central Manager


Callout Description
1 Top-right menu
2 Grid view
3 Bottom-left menu

The following options are available in the Device Manager page of the Central Manager:

Options Description
Top-right menu
Quick Search / Search Enter the keyword in the Quick Search / Search field and the results are automatically displayed.
Clear All Filters Click Clear All Filters to undo all filters applied.
Click this icon to refresh the page.
Bottom-left menu
Save as CSV Downloads the device details for all the devices as a .csv file.

Grid View

The following columns are available in the grid view of the Device Manager page in Central Manager:

Option Definition
Manager Displays the name(s) of the Manager(s).

A header column is available for each Manager. You can expand or collapse the header column of any Manager to view or hide device information specific to them as per your requirement. The Manager name provides a hyperlink which redirects you to the login page of the respective Manager.

Device Name Displays the name of the device(s) configured with the Manager.

Note

For vIPS Clusters, it displays the name of the member Sensors.

Connection Status Displays the status between the Sensor and the Manager.
  • Fully Connected: Indicates that all channels are up. The Sensor is able to communicate with the Manager.
  • Partially Connected: Indicates that one or more channels are down.
  • Disconnected: Indicates that the command channel is down. This occurs when the Sensor fails to communicate with the Manager.
  • Trust Pending: Indicates that the Sensor is defined on the Manager but not on the Sensor.
Channel Status Displays the name of the following channels and its status whether "Up" or "Down" :
  • Command
  • Alert
  • Packet

If the trust is not established between the Manager and Sensor, the Channel Status is displayed as ---.

Protections

Displays if the versions for the following protection parameters are latest not:

  • Signature Set
  • Callback Detectors
  • GAM (Gateway Anti-Malware engine)
  • Anti-Malware Version

The icons displayed for the parameters are as follows:

  • : Displayed when the parameter has the latest version available.
  • : Displayed when the version available in the Manager differs with the version available in the Sensor.
  • : Displayed when there is no latest version available on the Manager.
  • : Displayed when the latest version cannot be determined. This is displayed only for GAM and Anti-Malware Version.
Device Details
Type Displays if the device is a Sensor or an NTBA appliance.
Model Displays the Sensor model.
Serial Number Displays the Sensor serial number.
Software Displays the software version running on the Sensor.
Hardware Displays the current hardware version running on the Sensor.
Reboot Status Displays if the Sensor requires a reboot. This is required to deploy configuration changes to the Sensor without any failure.
  • Reboot Required: Indicates that the Sensor requires a reboot. The reason for the reboot is also provided for better understanding. For example, Reboot Required (Sensor software change).
  • No Reboot Required: Indicates that the Sensor does not require a reboot.

Note

This is not applicable to NTBA appliances. It is displayed as ---.

Upgrade Status Displays if the latest software version is being installed on the Sensor or being downloaded to the Manager before installing it on the Sensor.
  • Successful : Displayed when the Sensor upgrade is successful.
  • In-progress: Displayed when the Sensor is upgrading to the latest Sensor software version.
  • Failed : Displayed when the Sensor upgrade fails.
  • ---: Displayed when no upgrade is performed.
vIPS Cluster Displays the name of the vIPS Cluster. For non-vIPS Clusters, "---" is displayed.

Note

This column is applicable only to Sensors that are members of a vIPS Cluster.

vIPS Probe Displays the vIPS Probe version running on the member Sensor. For non-vIPS Probe, "---" is displayed.

Note

This column is applicable only to Sensors that are members of a vIPS Cluster.

Cloud Cluster Id Displays the Cluster ID for the vIPS Clusters. For non-vIPS Clusters, "---" is displayed.

Note

This column is applicable only to Sensors that are members of a vIPS Cluster.

Last Upgrade Displays the date, time, and year of the last software upgrade.
System Running Capacity: Displays the throughput of the Sensor.

Note

The information is displayed only for NS9500, NS7500, and NS3500 Sensors.

License: Displays one of the following:
  • Required: The reason can be one of the following:
    • License has not been assigned to the device.
    • The license is assigned, but its capacity is less than the device's configured capacity.
  • Present: The license is present and valid.
  • Expired: The license is assigned, but has expired.
  • Grace Period: The license has expired and is running on grace period.

    Note

    A grace period of 30 days is provided to subscription-based System licenses after they expire.

Stack Name: Displays the name of the stack of NS9500 Sensors.
Capacity: Displays the throughput for the stack.
License: Displays one of the following:
  • Required: The reason can be one of the following:
    • License has not been assigned to the stack.
    • The license is assigned, but its capacity is less than the stack's configured capacity.
  • Present: The license is present and valid.
  • Expired: The license is assigned, but has expired.
  • Grace Period: The license has expired and running on grace period.

    Note

    A grace period of 30 days is provided to subscription based system licenses after they expire.

HA Pair If the device is a part of a HA pair, it displays the name of the HA pair the device belongs to.
Management IP Address Displays the IP address of the management interface in the device and the subnet mask IP address.
Default Gateway Displays the IP address of the default gateway configured on the Sensor.
FIPS Mode Displays if FIPS mode is enabled or disabled.

Note

This is not applicable to NTBA appliances. It is displayed as ---.

Last Reboot Displays the date and time of the previous reboot of the Sensor.
Owner Domain Displays the admin domain name or the child admin domain name to which the device belongs.
Comment Displays the location and contact information.
System Health
Overall Health Displays the overall health of the system.
  • Normal: All the health indicators are normal.
  • Abnormal: One or more health indicators are abnormal.
  • ---: Disconnected or trust pending.
Internal Health Displays the Sensor health.
  • Normal: All the health indicators are normal.
  • Abnormal: One or more health indicators are abnormal.
  • ---: Disconnected or trust pending.
Physical Ports Displays if the ports are operating normally or abnormally.
  • Normal: Physical ports are operating normally.
  • Abnormal: One or more ports are down or the failover kit is in bypass mode.
  • ---: Disconnected or trust pending.
Inspection

Displays if the device is in layer 2 bypass mode.

  • Normal – Traffic inspection is enabled
  • Abnormal – Traffic inspection is disabled. This means that the device is in layer 2 bypass mode.
Performance

Displays if there are any performance related faults for the device.

  • Normal – Indicates that the device has no unacknowledged performance faults.
  • Abnormal – Indicates that the device has one or more unacknowledged faults.

Note

This is not applicable to NTBA appliances and vIPS Clusters. It is displayed as ---.

Hardware

Displays if the hardware has any temperature or power related issues.

  • Normal – Indicates that the device has no unacknowledged faults
  • Abnormal – Indicates that the device has one or more unacknowledged faults
Power Supplies

Displays the power supply status. The following are the status of the power supply:

  • Operational - Indicates that the power supply is detected and operational.
  • Non Operational - Indicates that the power supply is detected but not operational.
  • Absent - Indicates that the power supply is absent.
  • Error - Indicates Error when the system fails to fetch the real power status.
  • --- - Indicates that the trust is not yet established or power supply status is not applicable for it.

For NS-series Sensors, two units of power modules and power supply status are displayed:

  • A: Displays the Primary power module and power supply status
  • B: Displays the Secondary power module and power supply status

Note

Only for NS9300 Sensor, four units of power modules and power supply status are displayed:

  • For Primary, A and B displays the two units of power module and power supply status.
  • For Secondary, A and B displays the two units of power module and power supply status.

Note

For all untrusted devices and NTBA, it is displayed as ---.

Note

The NS3x00 Sensors do not support Secondary power supply module. So, the status of only Primary power supply module is displayed.

Faults
Total

Displays the number of unacknowledged faults generated for the device.

Click the tooltip icon to navigate to the Faults window.

Critical Displays the number of critical faults generated for the device.
Error Displays the number of error faults generated for the device.
Warning Displays the number of warning faults generated for the device.
Info Displays the number of info faults generated for the device.
Sync
Status Displays the synchronization state of the Sensor.
  • Synchronized: Displayed there are no pending changes.
  • Sync required: Displayed when there are pending changes on the Sensor.
  • Sync in progress: Displayed when the deployment is in progress.
  • ---: Indicates that there is no trust established between the Sensor and the Manager.
Pending Changes Displays the configuration changes updated to the device including signature set or callback detectors.
Last Sync Displays the date and time of the last configuration change.
Deployment Mode Displays if the configuration update was online or offline. This is displayed as Direct for online update and Indirect for offline update.

You can also view these device details in the Details panel to the right of the page by double-clicking anywhere on the selected device.

Details panel


Note

You cannot edit, modify, save any device-related information in the Details panel of the Device Manager page in Central Manager. It only provides read-only view of the details of the selected device.

Faults

A Faults window is displayed on selecting the tooltip icon for a particular fault in the Device Manager page of the Central Manager. On selecting Clear All Filters, the Faults window displays all the faults generated for the selected device.

Faults window


This window is similar to the Faults tab in the Manager → Troubleshooting → Logs page, except that this window displays the faults for the selected device only based on the severity. All the actions that can be performed in the Faults tab in the Logs page can also be performed through this window.

For more information, refer to the Faults section.

Click or to go back to the Device Manager grid view.