The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to understand failover in Trellix IPS

Prev Next

In typical failover configurations, one device is the template device while the other is the peer. As its name implies, when you create the HA pair, the configurations applied on the template device is applied on the peer. The template device is the active device and performs normal network functions while the peer is the standby, which monitors, ready to take control should the template/active device fail. When you delete the HA pair, the template device's configuration is what remains on the peer device. So, it is recommended that you export the configuration of the peer device before you create a HA pair.

In Trellix IPS, because both failover Sensors must be ready to process packets on their monitoring ports at all times, both Sensors are actually active at all times; neither Sensor is inoperative, or 'standing by' unless the unit has failed. Instead, both Sensors operate normally.

In the following figure, two Sensors are placed in-line, connected to each other via cables, and configured to act as a HA pair. All traffic is copied and shared between them in order to maintain state. One Sensor copies the packets received on its monitoring ports to the other Sensor using the interconnection ports and vice versa. Since both Sensors see all traffic and build state based on it, their state information is synchronized at all times.

All packets are seen by both Sensors (when both are operational); however, only one Sensor in the pair raises an alert whenever an attack is detected.

Two NS9500s in a high availability configuration
Two NS9500s in a high availability configuration