The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to define the Trellix Intrusion Prevention System fail-over pair

Prev Next

After the Sensors are known to be working independently, we are ready to define a fail-over pair. It is through the fail-over pair configuration that we ensure the Sensors share flow information under normal conditions and also fail over as required.

The one important consideration is that the current configuration of "primary" Sensor will be copied over that of the "secondary" Sensor during the pair creation process.

Note

The creation of a fail-over pair happens in real time. There is no need to explicitly update the configuration.

When it comes to scanning roles, however, you can safely ignore the terms Primary Sensor and Secondary Sensor here. Remember that both Sensors are always scanning actively.

After completion, the display of the user interface will change to reflect the existence of the new fail-over pair:

A new fail-over pair node now exists under IPS Interfaces. That node contains icons for each interface taking part in the fail-over process. A list of its member Sensors is also found within the fail-over pair node.

Most configuration options are hereafter done at the fail-over pair node level. For example, you can now apply a policy or update the configuration at the fail-over pair node level and it will automatically propagate to each of the member Sensors. On the other hand, you still configure the port settings, view interface statistics, and upgrade the Sensor software at the Sensor node level. So, the easiest way to get a feel for the fail-over pair configuration process is to examine the user interface once the pair has been created.

Note

The Sensors must be running the same software version to run in a fail-over configuration. However, you upgrade software at a Sensor level, even those that are part of a fail-over pair. The recommended upgrade procedure is to, therefore, upgrade the software version on both Sensors, and then restart them sequentially. In other words, once the upgrade process is complete on both, restart the first, confirm that it has restarted without error, and restart the second.

You can view the additional details on the current fail-over status for a given interface from the Physical Ports page.

Sensor status and operational details
Sensor status and operational details