The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Features supported by a Virtual Sensor

Prev Next

The following are the list of features supported by Virtual Sensors.

Supported features

Feature name

Inbound SSL decryption (Known-key and Agent based methods)

IPS policies for exploit attacks

IPS policies and DoS policies for detection of DoS attacks

DNS DoS protection

Reconnaissance policies

Quarantine (automatic through IPS policies and Attack Log, and from the Quarantine page within the Analysis tab)

MDR

Virtual Sensor monitoring ports based on CIDR and VLAN

Snort custom attack definitions

Trellix IPS custom attack definitions

Protection of web application servers

Advanced Traffic Inspection

Inspection of Q in Q traffic

Layer 2 passthru mode is supported but implemented differently when compared to physical Sensors

Layer 7 data collection

SYN cookie protection

ARP spoofing protection

IP spoofing protection

Virtualization of monitoring ports using VLANs and CIDRs (VIDS)

MPLS traffic inspection

IPv6 traffic inspection

IPv6 support for the management port

Inspection of tunneled traffic including GRE tunneled traffic

HTTP response scanning

Inspection of double VLAN tagged traffic

Monitoring Sensor performance (Device Throughput Usage, Memory Usage, and CPU Usage)

Synchronization of Sensor clock using an NTP server

Display Sensor CLI audit log events in the Manager

TACACS+ user in audit logs

Secure Transfer of Files from Sensor CLI

Application Identification and Visualization

Firewall policies

Advanced Traffic inspection

SmartBlocking of attacks including use of IP Reputation to augment SmartBlocking

Integration with GTI for IP reputation and file reputation. This includes protection from high-risk hosts.

Connection Limiting policies

Inspection of X-Forwarder-For Header Information. Reputation lookup and quarantine of client IP addresses in the XFF header.

Layer 7 Data Collection

Stateless Firewall access rules

Simulated Blocking

Latency monitor

Capture data packets (packet capture)

Granular access control for CLI commands (for TACACS users)

Advanced Malware policies including integration with IVX, Trellix Intelligent Sandbox and NTBA Appliances

Advanced callback activity including Bot Command and Control server activity detection

Network forensics

Passive device profiling

Web server protection against DoS attacks

Traffic prioritization

Netflow export to NTBA

Integration with McAfee Endpoint Intelligence Agent (McAfee EIA)

Sensor autorecovery — Since a Virtual IPS Sensor cannot depend on its software to go into layer 2 during recovery, the traffic is interrupted until all applications are restarted and the Sensor is back to good health.

Monitoring Sensor performance (Port Throughput Usage)



After you deploy a Virtual Sensor, the process of configuring and managing it is similar to that of a physical Sensor. Therefore, refer to the corresponding section for information on how to configure the supported features.