The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IP spoofing detection

Prev Next

The Anti-Spoofing feature enables the detection of packets that either originate from sources external to your network (inbound) which use your internal addresses as the source IP addresses, or originate from your internal network (outbound) which use IP addresses not defined in your customized list of good addresses.

Note

In these sections, the term IP spoofing detection refers to the detection of IP-spoofed attacks, whereas the term Anti -Spoofing refers to the feature in Trellix IPS that detects these attacks.

You can apply IP address spoofing detection to any inline interface that has been previously segmented by CIDR-based addressing. A Sensor maintains a table of CIDR-based addresses it protects. Then, for example, if it detects a packet that originated from outside your network but contains an identified internal address, it just drops the packet.

Any port pair in inline mode that has been segmented by CIDR addressing is eligible for IP spoofing detection. This includes any CIDR-segmented subinterfaces of an eligible port pair. For example, port pair G0/1-G0/2 protects the 192.16.1.0/24 and 192.16.2.0/24 networks in inline mode. You create the subinterface Payroll-Server to protect host 192.16.1.1/32. When you enable IP spoofing detection for G0/1-G0/2, all three addresses are checked for IP spoofing attacks.