The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable the association of a Client Group at the domain level

Prev Next

Prerequisites:

You can enable the association of any Client group at the admin domain level or any child domain using the Devices → <Admin Domain Name> → Global → IPS Device Settings → NI Integration → Client Group Association tab. The task of Client Group association completes the Trellix IPS - Trellix NI integration process. Before you enable the association of Client Group for any domain in the Manager:

  • Make sure that you have configured the required Client Profile and Client Group on the NI appliance. For more information how to configure a Client Profile and Client Group using the NI CLI, refer to the topics Create a Client Profile on the NI CLI and Create a Client Group on the NI CLI.

  • Make sure that you have added the Client Group configured on the NI appliance to the Manager using the Devices → <Admin Domain Name> → Global → IPS Device Settings → NI Integration → Client Group Configuration tab. If you have not done it, you may add it by accessing the Client Group Association tab available at the domain level. Refer to the steps outlined below for more information.

  • Ensure that you have added an Inspection Options policy with Layer 7 Data Collection enabled at the required domain and have assigned it to the required interfaces and sub-interfaces. Refer to the chapter Working with Inspection options policies in Trellix Intrusion Prevention System 11.1 Product Guide for detailed information.

Steps:

Perform the following steps to enable association of a Client Group at the domain level:

  1. In the Manager, go to the Devices page and select the required domain from the Domain drop-down list.

  2. Now, select Global → IPS Device Settings → NI Integration.

    The NI integration page is displayed in the Manager.

  3. To enable association of a Client group at the domain level, select the Client Group Association tab. The configuration options within the Client Group Association tab are displayed.

    Configuration options in Client Group Association tab at the domain level
    Configuration options in Client Group Association tab at the domain level


  4. Specify the following configuration options in the appropriate fields:

    Field

    Description

    Inherit Settings?

    Selecting this checkbox means the entire domain and all Sensors attached to that domain will inherit global settings and no further options will appear in this page.

    The following options appear only when Inherit Settings? is deselected

    Enable Association with NI Appliance

    Select this checkbox to start the process of enabling Client Group association for the selected domain.

    The following options appear only when Enable Association with NI Appliance checkbox is selected

    Client Group

    This field enables you to select the specific Client Group to be enabled for a specific domain on the Manager via the following two options:

    • You can select the required Client Group from the drop-down list, if the Client Group has been added in the Manager using the Devices → <Admin Domain Name> → Global → IPS Device Settings → NI Integration → Client Group Configuration tab.

    • If you have not yet added the required Client Group in the Manager, click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon.

      Create New Client Group panel is displayed in which you can provide the Client Group name, the IPv4 address of the associated NI appliance, and authentication hash token attached to the specific Client Group, and click Save.

      GUID-AA7349A1-36F0-47D8-B8C3-DD2FE0DED078-low.jpg

      Once the Client group addition is successful, it gets automatically selected in the Client Group drop-down list.

    NI Appliance IP Address

    The IPv4 or IPv6 address of the NI appliance is automatically fetched in the field once you specify the Client Group from the drop-down or add it using the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon above.

    Once all fields have been configured, Click Save. After updating the NI integration configuration on the Client Group Association at the domain-level, you must deploy configuration changes to the required Sensor(s) for the updates to take effect.

    This marks the successful completion of the task of enabling NI integration at a domain-level in the Manager. In case you want to modify the Client Group association settings in the concerned domain at a later time, you may do so by performing either of the following two steps:

    • Selecting it in the required Client Group from the Client Group drop-down list and then saving the changes, provided that it has been already added in the Manager using the Client Group Configuration tab.

    • Adding the required Client Group using the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon present on the Client Group Association tab at the Global-level and then saving the changes

    If you wish to enable the association of separate Client Group(s) with different configurations for specific Sensor(s), you can do so from the Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → NI Integration → Client Group Association tab.