The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Hardware for monitoring ports

Prev Next

Before you configure the monitoring and response ports of a physical Sensor, make sure you have correctly cabled the ports as per your network design and requirements. Based on the Sensor model and the port that you plan to use, you might be required to connect some hardware to the monitoring ports. This section introduces the various hardware that might be required to configure monitoring ports.

  • Transceivers — Based on the Sensor model, monitoring ports use different types of transceivers to connect to peer devices. The transceiver types that are supported are as follows:

    • Small Form-factor Pluggable (SFP) (fiber or copper)

    • SFP+

    • QSFP+

    • QSFP28

    Note

    • NS9600 Sensor supports QSFP+ (fiber) 40Gbps and QSFP28 (fiber) 100Gbps transceiver modules.

    • NS9500 Sensor supports SFP (fiber or copper) 1 Gbps, SFP+ (fiber) 10 Gbps, QSFP+ (fiber) 40Gbps, and QSFP28 (fiber) 100Gbps transceiver modules.

    • NS9x00 Sensors support SFP (fiber or copper) 1 Gbps, SFP+ (fiber) 10 Gbps, and QSFP+ (fiber) 40Gbps transceiver modules.

    • NS7600 Sensor supports SFP (fiber or copper) 1 Gbps and SFP+ (fiber) 10 Gbps transceiver modules.

    • NS7500, NS7x50, and NS7x00 Sensors support only SFP (fiber or copper) 1 Gbps and SFP+ (fiber) 10 Gbps transceiver modules.

    • NS5x00 Sensors support only SFP (fiber or copper) 1 Gbps transceiver modules.

    • NS3600 Sensor supports SFP (fiber) 1 Gbps and SFP+ (fiber) 10 Gbps transceiver modules.

    • NS3x00 Sensors do not need transceiver modules.

    Refer to the corresponding Sensor product guide to know the transceivers type used by the monitoring ports and how to cable them.

  • Fail-open kits — Fiber monitoring ports are fail-closed by default. Thus, if these ports are deployed in-line, a Sensor hardware failure, for example, results in network downtime. Fail-open operation for fiber ports requires the use of the an external bypass switch. Fail-open bypass kits minimize the potential risks of in-line Sensor failure on critical network links. There are two types of fail-open kits available - active and passive. To know the difference between the two and the active and passive fail-open kits available, see the section Using active fail-open kit in Trellix Intrusion Prevention System Product Guide. For information on how to deploy a particular fail-open kit, refer to the corresponding guide. For example, for information on how to deploy gigabit optical Active fail-open switch, see the Trellix Intrusion Prevention System Fail-Open Kit Product Guide.

  • External tap device, if you plan to deploy monitoring ports in the tap mode. Refer to Deployment of Sensors in tap mode.