The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How Trellix IPS-GTI integration for IP Reputation works

Prev Next

The Manager integrates with the GTI IP Reputation to obtain the reputation scores on hosts and geo-locations that are displayed in Attack Log.

The Sensor requests reputation for hosts from GTI. The reputation score acts as an important factor in determining whether to block the host. The scores are cached for one hour. After an hour, the information ages out and if the information is required again, the Sensor makes the GTI request again.

Note

Cache is not maintained on reboot.

Reputation scores:

  • Minimal Risk ( <=14)
  • Unverified ( 15 to 29)
  • Medium Risk (30 to 49)
  • High Risk (> 49)

After a High Risk External IP host is found, the traffic from that host can be blocked or the host itself can be quarantined.

Note

The terms reputation scores and risk assessment scores are interchangeably used for Sensor and Manager in Trellix IPS.

Note

DNS must be configured for the Sensor to reach the GTI server.

Note

HTTPS is used to obtain the reputation of the hosts.

The Sensor does not request reputation scores for hosts that have internal IP addresses. The following private IP address blocks are considered as internal IP addresses by the Sensor:

  • 0.0.0.0/8
  • 10.0.0.0/8
  • 100.64.0.0/10
  • 127.0.0.0/8
  • 169.254.0.0/16
  • 172.16.0.0/12
  • 192.0.2.0/24
  • 192.88.99.0/24
  • 192.168.0.0/16
  • 198.18.0.0/15
  • 198.51.100.0/24
  • 203.0.113.0/24
  • 224.0.0.0/3