The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Inline deployment walkthrough

Prev Next

In-line mode enables you to run the Sensor in a protection/prevention mode, where packet inspection is performed in real time, and intrusive packets can be dealt with immediately; you can actively drop malicious packets because the Sensor is physically in the path of all network traffic. This enables you to actually prevent an attack from reaching its target.

  1. Determine the optimal high availability strategy for the Sensor.

    This indicates how you would like the Sensor to behave when it fails (that is, fail-open, fail-closed, or support a failover/high-availability configuration).

  2. Physically install the Sensor on your network, and connect the Sensor cables for the deployment mode of your choice.

    For example, connect one Sensor standalone (to fail-open, if applicable, or configure two Sensors as part of a HA pair).

  3. Configure the Sensor monitoring ports.

  4. Configure one or more policies for the inline ports.

  5. Understand how blocking works, and configure blocking.

    Note

    You must use Manager to configure most aspects of your Sensor(s), including port configuration, pairing two Sensors for failover operation, and configuring and applying policies to detect and drop malicious traffic.