The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Inline monitoring

Prev Next

The Network Security appliance can be configured for transparent inline operation to proactively protect the enterprise from infection by blocking suspicious network traffic while allowing all legitimate traffic to continue to its destination unhindered.

Note

SmartVision Mode sensors and appliances are not supported in inline deployments. These appliances must be deployed out-of-band using a TAP device. For more information, see “SmartVision Appliance Placement and Operational Mode” in the Network Security SmartVision Feature Guide.

The Network Security appliance can be deployed inline (block or monitor mode) or out-of-band (TCP reset or monitor mode). When deployed in monitor mode, network traffic can be passed through the interfaces without blocking any traffic. You can specify the inline policy on the following monitoring interfaces. These monitoring interfaces are configured and deployed in pairs that consist of two ports.

  • A—Monitoring interfaces named pether3 and pether4.

  • B—Monitoring interfaces named pether5 and pether6 (on appliances with two port pairs).

When deployed in out-of-band prevention mode, the appliance can be configured to issue TCP resets for out-of-band blocking of TCP, UDP, or HTTP connections.

Task list for managing Inline monitoring

Complete the tasks for managing inline monitoring in the following order:

  1. Log in to the Web UI or CLI.

  2. Set the operational mode by configuring and customizing inline operations on the appliance.

    For details, see Configuring inline operational modes.

  3. Enable the drop filter configuration settings.

    For details, see Enabling or disabling the drop filter settings.

  4. (Optional) If your Network Security appliance monitors traffic filtered by a Web proxy, you can configure the appliance to identify blocking actions taken by the Web proxy. This enables the appliance to distinguish traffic blocked by the Web proxy from traffic blocked by the appliance.

    For details, see Blocked-by-proxy detection.