The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Establishing Sensor-to-Manager communication

Prev Next

The process of setting up a Sensor is described below at a high level.

Steps:

  1. Set up the Manager software on the server machine.

    • Install the Manager software on the server machine. This process is described in detail in the Trellix Intrusion Prevention System Installation Guide.

    • Start the Manager as described in the Trellix Intrusion Prevention System Installation Guide. You can establish communication with a Sensor from the Manager server or from a remote client machine connected to the Manager server via any web browser.

    • You can choose a specific policy to apply by default to the root admin domain (and thus to all monitoring interfaces on the Sensor).

    Whatever policy you have specified will apply until you make specific changes; this policy gets you up and running quickly. Most users tune their policies over time to best suit their environments and reduce the number of irrelevant alerts.

    Note

    By default, the Default Preventionpolicy is applied to all of your Sensor ports. Note that this policy's behavior is to automatically block certain attacks upon detection. For more information on other provided policies, see Trellix IPS policies in the IPS Administration section.

    Open the Sensors tab in Device Manager page and add a Sensor, providing the Sensor with a name and a shared secret key value. For instructions on how to open the Sensors tab in Device Managerpage, see the IPS Administration section. For instructions on how to add a Sensor to the Manager, see Trellix Intrusion Prevention System Installation Guide.

  2. Configure the Sensor.

    From a console connected physically or logically to the Sensor, configure the Sensor with network identification information (that is, an IP address, the IP address of the Manager server, and so on), and configure it with the same name and shared secret key value you provided in the Manager. For more information on Configuring the Sensor using the Sensor CLI, see the CLI commands section.

  3. Verify communication between the Sensor and the Manager.

    There are three ways to check that the Sensor is configured and available:

    • In the Manager Dashboard, check the System Faults. (See if the Sensor is active. If the link is yellow, click on the cell to see the System Faults on the Sensor. For more information, see the Manager Administration section.

    • In the Manager, click Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Physical Ports → Monitoring Ports. Look at the color of the button(s) representing the ports on the Sensor, and check the color legend on the screen to see the status of the Sensor's ports. For more information on this process, see the Manager Administration section.

    • Type status in the Sensor command line interface (CLI). Check the following line:

      trust established between sensor and manager = yes

      If the answer is no, recheck that your Sensor name and shared secret are the same on both the Sensor and the Manager.

  4. Troubleshoot any problems you run into.

    If you run into any problems, check your configuration settings and ensure that they are correct. For troubleshooting tips, see the Troubleshooting section.

  5. Verify the monitoring mode of the ports on your Sensor.

    Your IPS Sensor ports are configured by default for monitoring in Default Prevention mode; that is, connected in-line on a network segment (for example, between a switch and a router or two switches). If you've cabled the Sensor to monitor in another monitoring mode, check your settings to make sure everything is correct. Some users choose instead to monitor in SPAN mode at first, and move to tap and/or in-line mode later.

    For more information on verifying port configuration, see Trellix Intrusion Prevention System Installation Guide.