The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Failover — Configuration of two Sensors in inline mode

Prev Next

In a failover configuration, the two Sensors are placed inline, connected to each other via cables, and configured to act as a failover pair. All traffic is copied and shared between them in order to maintain state. Sensor A copies the packets received on its monitoring ports to Sensor B using the interconnection ports and vice versa. Since both Sensors see all traffic and build state based on it, their state information is synchronized at all times.

All packets are seen by both Sensors (when both are operational); however, only one Sensor in the pair raises an alert whenever an attack is detected.

When deploying the two Sensors in failover mode, you must ensure the following:

  • The Sensor interconnection ports must be connected appropriately so that both the Sensors can communicate.

  • Both Sensors must be of the identical model type, and have the same signature set and software loaded. (One of the two Sensors may be a "Failover (FO)" Sensor model, which is a fully functional Sensor limited to operation as part of a failover pair; it cannot operate standalone.)

  • Additionally, all ports on both the Sensors must be configured to run in inline mode.