The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Establish Sensor-to-Manager communication

Prev Next

The process of setting up a Sensor is described at a high level.

  1. Set up the Manager software on the server machine.

    1. Install the Manager software on the server machine. For more information on this process, see Trellix Intrusion Prevention System Installation Guide.

    2. Start the Manager software as described in Trellix Intrusion Prevention System Installation Guide. You can establish communication with a Sensor through the Manager server or from a browser on a client machine that can connect to the Manager server.

      Trellix recommends you connect to the Manager server through a browser session from a separate client machine to perform your configuration tasks.

    3. You can choose a specific policy to apply by default to the root admin domain (and thus all monitoring interfaces on the Sensor). By default, the pre-defined Default Prevention policy is applied to all of your Sensor ports upon Sensor addition.

      Whatever policy you've specified will apply until you make specific changes; the default policy gets you up and running quickly. Most users tune their policies over time, in conjunction with VIPS, to best suit their environments and reduce the number of irrelevant alerts.

  2. Use the Sensors tab in Device Manager page of the Manager and add the Sensor to required domain.

    1. On the Devices tab of the Manager, select the domain where you want to add the Sensor and go to Global → Device Manager. The Device Manager page is displayed. Select the Sensors tab and click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png.

    2. Specify the required information in the Add Device - Step 1 of 2 window.

      • Enter the Name of device. This must be the same name (case-sensitive) that you assigned to the Sensor through Sensor CLI.

      • Enter and confirm the Shared Secret. You must enter the same shared secret (case-sensitive) in the Sensor CLI when you establish Sensor-to-Manager communication.

      • Select IPS Sensor or NTBA Appliance as the Device Type.

      • Specify the deployment mode as either Direct or Indirect.

      • If required, provide the information for the optional fields.

      • Click Save.

  3. Configure the Sensor.

    • From a serial console connected physically or logically to the Sensor, configure the Sensor with network identification information (that is, IP address, IP address of the Manager server, and so on), and configure it with the same case-sensitive name and shared secret key value you provided in the Manager.

      For more information on configuring the Sensor using the Sensor CLI, see CLI commands section.

  4. Verify communication between the Sensor and the Manager.

    • Verify the health of the Sensor on the Sensor CLI and that the Sensor has established communication with the Manager. Use the status command.

    • Verify in the Manager interface that the Sensor's name is listed. On the Devices tab of the Manager, select the corresponding domain and check if the Sensor is listed in the Device drop-down.

  5. Troubleshoot any problems you run into.

    • If you run into any problems, check your configuration settings and ensure that they are correct. For more troubleshooting tips, see Troubleshooting section.

  6. Verify the operating mode of the ports on your Sensor.

    • Your Sensor ports are configured by default for monitoring in in-line mode; that is, connected via a port pair on the Sensor to a segment of your network. If you've set up the Sensor to monitor in in-line mode, check your settings to make sure everything is correct.