The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Interfaces

Prev Next

Networking professionals often interchange the terms port and interface. In the Trellix IPS context, however, there is an important distinction to be made; a port actually represents the physical component, whereas an interface represents the logical abstraction of one or more physical monitoring ports on a Sensor and all traffic flowing through the port(s). All Sensor interfaces are represented by FE or GE monitoring ports connected directly or through an external tap, hub, or SPAN port to network segments.

A simple, yet effective example of the difference between port and interface is with regard to a "port pair." When you configure a Sensor to run inline, you combine and manage the two physical ports as a single logical interface.

To use an example, assume that you have a Finance parent domain, and it has two child domains—Payroll and Accounts Payable. The Payroll department network is comprised entirely of Windows machines, and Accounts Payable is predominantly Solaris. You have a single Sensor that is running in internal tap mode with two peer ports, port pair G1/1 and G1/2, monitoring traffic in the Payroll department and port pair G1/3 and G1/4 monitoring Accounts Payable. You can use a Windows Server IPS policy and apply it to the Payroll interface and a Solaris Server IPS policy to apply to the Accounts Payable interface.

Deploying security policies
Deploying security policies