The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Features supported by a Virtual Sensor

Prev Next

The following are the list of features supported by Virtual Sensors.

Supported features
Feature name
Inbound SSL decryption (Known-key and Agent based methods)
IPS policies for exploit attacks
IPS policies and DoS policies for detection of DoS attacks
DNS DoS protection
Reconnaissance policies
Quarantine (automatic through IPS policies and Attack Log, and from the Quarantine page within the Analysis tab)
MDR
Virtual Sensor monitoring ports based on CIDR and VLAN
Snort custom attack definitions
Trellix IPS custom attack definitions
Protection of web application servers
Advanced Traffic Inspection
Inspection of Q in Q traffic
Layer 2 passthru mode is supported but implemented differently when compared to physical Sensors
Layer 7 data collection
SYN cookie protection
ARP spoofing protection
IP spoofing protection
Virtualization of monitoring ports using VLANs and CIDRs (VIDS)
MPLS traffic inspection
IPv6 traffic inspection
IPv6 support for the management port
Inspection of tunneled traffic including GRE tunneled traffic
HTTP response scanning
Inspection of double VLAN tagged traffic
Monitoring Sensor performance (Device Throughput Usage, Memory Usage, and CPU Usage)
Synchronization of Sensor clock using an NTP server
Display Sensor CLI audit log events in the Manager
TACACS+ user in audit logs
Secure Transfer of Files from Sensor CLI
Application Identification and Visualization
Firewall policies
Advanced Traffic inspection
SmartBlocking of attacks including use of IP Reputation to augment SmartBlocking
Integration with GTI for IP reputation and file reputation. This includes protection from high-risk hosts.
Connection Limiting policies
Inspection of X-Forwarder-For Header Information. Reputation lookup and quarantine of client IP addresses in the XFF header.
Layer 7 Data Collection
Stateless Firewall access rules
Simulated Blocking
Latency monitor
Capture data packets (packet capture)
Granular access control for CLI commands (for TACACS users)
Advanced Malware policies including integration with MVX, Trellix Intelligent Sandbox and NTBA Appliances
Advanced callback activity including Bot Command and Control server activity detection
Network forensics
Passive device profiling
Web server protection against DoS attacks
Traffic prioritization
Netflow export to NTBA
Integration with McAfee® Endpoint Intelligence Agent (McAfee EIA)
Sensor autorecovery — Since a Virtual IPS Sensor cannot depend on its software to go into layer 2 during recovery, the traffic is interrupted until all applications are restarted and the Sensor is back to good health.

After you deploy a Virtual Sensor, the process of configuring and managing it is similar to that of a physical Sensor. Therefore, refer to the corresponding section for information on how to configure the supported features.