The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How Trellix IPS - IVX integration works

Prev Next

When you integrate Trellix IPS with IVX, the Manager and Sensor initiate communication channel with the sandbox (Trellix VX or Trellix IVX Cloud). This channel is open unless the Sensor is down, the sandbox is down, or you disable the integration. By default, this communication channel is over HTTPS protocol and the sandbox listens on port 443 which cannot be changed.

Note

In this section, unless explicitly mentioned, sandbox would refer to Trellix VX or Trellix IVX Cloud whichever the user plans to integrate with Trellix IPS.

The Manager accesses the RESTful APIs of IVX for its communication. When a connection is required, the Manager establishes an HTTPS connection.

When you integrate Trellix IPS with IVX and the authentication is successful, IVX serves as an additional malware engine for all the supported file types in the Advanced Malware Policies. You can select this engine along with any of the other malware engines.