The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Evaluation of fail-open modes

Prev Next

It all begins with estimating the requirements of your organization’s network. If it is paramount to allow uninterrupted traffic flow to the network, a fail-open deployment will work best. However, if security cannot be compromised at any instant, you must choose a fail-closed configuration. Both deployments come with inherent advantages and disadvantages. While a fail-closed setup ensures that all traffic entering the network is monitored, it results in network outages which may not be favorable if you host business-critical servers in the network. On the other hand, a fail-open setup ensures that traffic is never interrupted but can result in malicious traffic entering the network during a Sensor outage. So, this is the first choice that you, as a security analyst, need to make.

Broadly, these are the benefits of choosing a fail-open network architecture.

  • It reduces network downtime to seconds during any Sensor reboot or Sensor failure.

  • It protects your network during link failure on the Sensor.

  • It bypasses the Sensor when troubleshooting network issues. This will help you identify or eliminate the Sensor as the cause of network issues.

Fail-closed configuration

To configure your network for fail-closed operation, you will simply need to make sure that a port pair on the Sensor is set to inline fail-closed configuration.

Fail-open configuration

Should you decide to go the fail-open route, you have two options:

  • Internal fail-open: Fail-Open is built into some of the Sensor ports

    Note

    When a port pair is configured for internal fail-open, the downtime between link failure on the Sensor and bypass can be a maximum of 3 seconds.

  • External fail-open: Fail-Open is carried out using external hardware

If you use a Sensor that supports internal fail-open, you simply need to configure the appropriate port pair for inline fail-open.

If you use a Sensor that supports external fail-open, you will need to make sure you have the additional hardware necessary for an inline fail-open deployment. Trellix IPS provides a range of fail-open kits to accommodate diverse requirements. You must purchase a fail-open kit that best suits your requirements and one that is compatible with your existing network infrastructure. The primary component in a fail-open kit is the fail-open switch, which can be active or passive.

An active fail-open switch sends a signal to the Sensor at regular intervals and awaits a response. A response indicates that the Sensor is operating normally. This signal is called a “heartbeat” signal. If the switch does not receive a response for a set number of signals, it removes the Sensor from the path of traffic and routes all traffic through its own ports, thereby ensuring continuous traffic flow.

A passive fail-open switch relies on the Sensor to send an electrical signal to determine if the Sensor is operating normally. If the switch does not receive a signal in a specified period, it removes the Sensor from the path of network traffic and bypasses the Sensor, routing traffic through its own ports.

Note

A heartbeat signal is a data packet that is sent by the Sensor or by the fail-open switch (depending on whether it is passive or active). Regardless of whether it is passive or active, a signal is sent at regular intervals and is used by the fail-open switch to determine the operational state of the Sensor. The interval between each signal varies with the type of fail-open switch you are using.