The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable Intelligent Virtual Execution (IVX) engine integration for an admin domain

Prev Next

You can configure the details for the integration at an admin domain so that the corresponding Sensors and child domains can inherit these settings. However, you must enable the integration at the Sensor level for the Sensor and the Manager to be able to communicate with Intelligent Virtual Execution (IVX) engine.

  1. In the Manager, select the Devices tab.

  2. Select the required domain from the Domain drop-down list and then select Global.

  3. Select IPS Device Settings → IVX Integration.

  4. Select Enable IVX Integration checkbox.

  5. Choose Enable IVX or Enable IVX Cloud configure them.

    Enabling IVX Integration for an admin domain
    Enabling IVX Integration for an admin domain


    Option definitions

    Option

    Definition

    Enable IVX Integration

    Select this option to integrate the Manager and Sensor with the IVX appliance or IVX Cloud.

    Enable IVX: Enables IVX appliance integration

    Enable IVX Cloud: Enables IVX Cloud integration

    After you select, you will be able to view and configure the details for the integration.

    Note

    At any instance, you can choose to integrate either IVX or IVX Cloud with Trellix IPS, but not both of them together.

    Save

    Click Save when you enable or disable IVX Integration.



Enable and Configure integration with IVX Appliance

  1. To enable and configure an IVX appliance integration, select the Enable IVX option.

    Enabling IVX Appliance Integration for an admin domain
    Enabling IVX Appliance Integration for an admin domain


    Option definitions

    Option

    Definition

    IVX Appliance Configuration

    Cluster Status

    Displays the status of the cluster that an IVX broker node belongs to.

    • GUID-E9D50264-CAFF-4207-8FAC-77D0B81FDCF3-low.pngReady: Cluster is ready and all the broker nodes are active.

    • GUID-28FE5921-ACF1-491C-B376-930A589BF74C-low.png: Any state other than Ready when one or more brokers are affected.

    • ---: Not available.

    Note

    The file submission to the cluster happens if the status is either GUID-E9D50264-CAFF-4207-8FAC-77D0B81FDCF3-low.png or GUID-28FE5921-ACF1-491C-B376-930A589BF74C-low.png. However, in the GUID-28FE5921-ACF1-491C-B376-930A589BF74C-low.png state, a few broker nodes might be down/not reachable but the file submission continues to happen to the active broker nodes.

    Broker Nodes Configured

    Lists the IP address of the broker nodes configured for communication.

    Listening Port

    Displays the port that IVX appliance will listen for connections from Sensor and Manager. The default port is 443 and users cannot change it.

    Enable Certificate Validation

    Displays the status of the certificate validation as Enabled or Disabled.

    Enable Proxy for IVX Communication

    Displays the status of the proxy communication as Enabled or Disabled.

    Add IVX Cluster

    Allows you to add a cluster consisting of IVX broker nodes.

    Remove IVX Cluster

    Use this option if you plan to remove an existing cluster.

    Save

    Saves the integration details in the Manager database and applies it to the inherited child domain(s)/device(s).



    Note

    The Add IVX Cluster, Remove IVX Cluster, and Save options will be hidden if:

    • You are viewing this page as a user with read-only access (or)

    • Manager is in Standby mode

  2. The Add IVX Cluster option allows you to add a cluster and its associated broker nodes. Click Add IVX Clusterdisplayed in the image Enabling IVX Integration for an admin domain.

  3. A new page opens where you can configure the cluster and its associated broker nodes.

    Adding broker nodes to a cluster
    Adding broker nodes to a cluster


    Option definitions

    Option

    Definition

    Cluster Details

    Note

    Configuration made in this section will be applicable to all the broker nodes that you add.

    Enable Certificate Validation

    Select this option if you have configured CA signed certificate on the IVX appliance.

    If the certificate is configured on the appliance, it is recommended to enable this option to ensure secure communication.

    Enable Proxy for IVX communication

    Select this option if you deployed proxy server between the IPS (Sensor and Manager) and the IVX appliance.

    You need to configure proxy server at device level page and enable proxy option under the IVX Appliance Configuration section.

    Listening Port (TCP)

    This is the port that IVX appliance will listen for connections from Sensor and Manager. The default port is 443 and users cannot change it.

    Cluster Status

    Displays the status of the cluster that an IVX broker node belongs to.

    • GUID-E9D50264-CAFF-4207-8FAC-77D0B81FDCF3-low.pngReady: Cluster is ready and all the broker nodes are active.

    • GUID-28FE5921-ACF1-491C-B376-930A589BF74C-low.png: Any state other than Ready when one or more brokers are affected.

    • ---: Not available.

    Broker Nodes

    Server Address

    Enter the IP address (IPv4/IPv6) or Host Name of the IVX broker for communicating with the Manager and Sensor.

    Username

    Username of the IVX broker node.

    Manager to IVX Authentication Status

    Displays the authentication status of the Manager with the IVX appliance.

    • GUID-E9D50264-CAFF-4207-8FAC-77D0B81FDCF3-low.pngSuccessful: Manager to IVX authentication is successful.

    • GUID-33513EA0-E7A4-45A2-BEFE-EBAD9042CC8D-low.jpgUnsuccessful: Manager to IVX authentication failed. User needs to recheck the credentials entered.

    • ---: Yet to be configured.

    Manager to IVX Authentication Failure Reason

    In case of Manager to IVX authentication failure, this column displays the reason for failure which helps users to take corrective actions and attain successful authentication.

    In case of a successful connection, the column displays the status as ---.

    Test connection

    Click to verify if the Manager is able to communicate with the broker node(s) using the details you configured.

    A Result pop-up appears displaying the status of the connection for all the configured broker nodes.

    Note

    When you click Test connection, the action is performed over all the newly added and existing broker nodes and the result is displayed.

    GUID-8D2203E5-2C86-4970-8BBE-0E051DDA1A11-low.jpg

    Click this button to add a broker node.

    Note

    You can add a maximum of 5 broker nodes within a cluster.

    Note

    Users should ensure that the broker nodes added in this section belong to the same IVX cluster.

    GUID-C5DB3A60-0A1C-4C8F-83A6-37EAFFF00433-low.jpg

    Click this button to remove newly added or existing broker nodes.

    You can delete only one node at a time.

    Next

    Click this option upon modifying the broker node(s).

    Cancel

    Click this option to cancel the add/delete operation performed on the broker nodes.



    Note

    Cluster Status, Manager to IVX Authentication Status, and Manager to IVX Authentication Failure Reason are updated only when you save the configuration changes.

  4. Upon clicking GUID-8D2203E5-2C86-4970-8BBE-0E051DDA1A11-low.jpg, Add Broker Node panel appears in the right pane.

    Adding broker node details
    Adding broker node details


    Option definitions

    Option

    Definition

    Server Address

    Enter the IP address (IPv4/IPv6) or Host Name of the IVX broker for communicating with the Manager and Sensor.

    Username

    Enter the username of the IVX broker node.

    Password

    Enter the password of the IVX broker node.

    Add

    Click Add upon entering the broker node details.

    Note

    The Add button remains grayed out if you enter invalid IP address.

    Update

    Double-click an existing broker node if you plan to make any modifications in it. Upon updating the fields with valid inputs, click Update.



Upon configuring the cluster and the broker nodes, click Next. You will be redirected to the IVX Integration home page., click Save.

Once the changes are saved, the IVX Appliance Configuration section appears as shown below:

IVX Appliance Configured
IVX Appliance Configured


Note

If you plan to modify an existing cluster, double-click the cluster to go to the next page where you can update the Cluster Details and the Broker Nodes. Follow the above steps to make the modifications.

Enable and Configure integration with IVX Cloud

  1. To enable and configure IVX cloud integration, select the Enable IVX Cloud option.

    Enabling IVX Integration for an admin domain
    Enabling IVX Integration for an admin domain


    Option definitions

    Option

    Definition

    IVX Cloud Integration

    Host Name

    Enter the host name for the IVX Cloud service (that is, the domain name on which IVX Cloud service is hosted).

    Note

    You need to add a firewall exception to the domain (that you enter as Host Name) to ensure uninterrupted communication. For more information, see Set the desktop firewall.

    API Key

    Enter the API key created in the IVX Cloud portal. This key is used for authentication and it retrieves the IVX Cloud service status.

    Note

    The maximum character length supported is 6000.

    Service Status

    Displays the status of IVX Cloud service.

    • GUID-E9D50264-CAFF-4207-8FAC-77D0B81FDCF3-low.pngRUNNING: The IVX Cloud service is running and is available for malware file polling and retrieving the analysis reports. The details of subscription and the files daily quota are also displayed underneath the RUNNING status.

    • GUID-33513EA0-E7A4-45A2-BEFE-EBAD9042CC8D-low.jpgFailed: User needs to recheck the configuration settings and the status of the IVX Cloud service. The failure reason is displayed which can be useful in troubleshooting the issue.

    • ---: Not applicable.

    Listening Port

    This is the port that IVX will listen for connections from Sensor and Manager. The default port is 443 and users cannot change it.

    Enable Proxy for IVX Cloud Communication

    Select this option if you deployed proxy server between the Sensor and IVX Cloud.

    You need to configure proxy server at device level page and enable proxy option under the IVX Cloud Integration section.

    Test connection

    Click to verify if the Manager is able to communicate with IVX Cloud using the details you configured. If the details entered are correct and the IVX Cloud service is running, a Successful dialog-box appears. This ensures that the Sensors submit suspicious files for analysis, and the Manager retrieves the analysis result and display it in the user interface.

    Click OK to close the dialog-box.

    If there is an issue, an Error dialog-box appears displaying the failure reason which can be useful in troubleshooting.

    Note

    When you click Test connection, the action is performed over the currently selected configuration.

    Save

    Saves the integration details in the Manager database and applies it to the inherited child domain(s)/device(s).



    Note

    The Service Status is updated only when you save the configuration changes.

Upon saving the integration details, the IVX Cloud Integration section appears as shown below:

IVX Cloud integrated at domain level
IVX Cloud integrated at domain level