The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable IP address spoofing detection

Prev Next

Prerequisite: Make sure that for the port-pairs for which you need to enable Anti-spoofing feature, their Mode is set to inline and their Interface Type is set to CIDR.

  1. Click the Devices tab.

  2. Select the domain from the Domain drop-down list.

  3. On the left pane, click the Devices tab.

  4. Select the device from the Device drop-down list.

  5. Select Setup → Advanced → Anti-Spoofing.

    The Anti-Spoofing page displays. Note that the tabs relate to the interfaces on the Sensor.

  6. For the required port-pairs, enable Anti-Spoofing in the required directions - inbound, outbound, or both.

    You can only enable IP spoofing detection for port-pairs in inline mode with CIDR interface types. CIDR entries must be previously configured for IP spoofing detection to function properly. You can enable Anti-spoofing at the interface level; you cannot enable it for specific CIDR subinterfaces.

    Note

    You can click an interface name to view the CIDRs configured for that interface.

    Configuring Anti-spoofing
    Configuring Anti-spoofing


  7. Click Save to enable IP spoofing detection.

    Once you click Save, the configuration is sent through SNMP to the Sensor; thus, you do not have to update the configuration changes to the Sensor.

    Note

    When you enable Anti-spoofing, a Sensor drops any IP-spoofed packets but raises no alert. You can view a list of dropped packets by clicking on the Dropped Packets tab in Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Traffic Statistics. Once in the tab, select the port for which you want to see the list and count of dropped packets.

    Alternatively, you can use the show inlinepktdropstatSensor CLI command to view the number of IP-spoofed packets dropped by a Sensor. For information on using this CLI, refer to the CLI commands section.