The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Inline mode and dedicated interface

Prev Next

The simplest scenario is the one in which a SYN packet arrives on a port that is operating in inline mode and configured as a dedicated interface.

As a dedicated interface, there is a single VIDS ID associated with the entire interface, so it is straightforward to identify.

To determine direction, the Sensor considers the physical port on which the SYN packet arrives:

  • If the SYN packet arrives on the port connected to the inside network, the entire flow is considered outbound.

  • If the SYN packet arrives on the port connected to the outside network, the entire flow is considered inbound.

    Note

    A port is defined as inside versus outside from the Physical Ports page of the Manager.

For example, if a client connects to a server through the G0/1-G0/2 monitoring ports, and the client's SYN packet arrives on the outside port, all traffic in the flow is scanned using the signatures associated with the inbound attack set profile and VIDS ID for the G0/1-G0/2 interface; this includes return traffic from the server.