The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS CLI enhancements

Prev Next

Following new Sensor CLI commands are available:

Normal Mode
CLI Command Description
exportsshpublickey Exports the Sensor public key public key to your remote machine for file transfers from the Sensor to the remote machine.
importsshpublickey Imports your public key to the Sensor so that the user can access the Sensor.
show datapath-memory-usage stats Displays the signature configuration memory usage details of the device.
show managercacertinfo Displays detailed information of the CA-signed leaf certificate of the Manager when the Sensor has established trust using CA-signed certificate.
show sensorcacertinfo Displays detailed information of the CA-signed leaf certificate of the Sensor.
show sshauth status Displays the SSH authentication status.
show ssl stats inbound proxy Displays the inbound SSL statistics while using the proxy method.
show urlrepstats Displays the statistics gathered when checking for the URL reputation such as the number of requests sent to the control plane, number of times an attack was triggered, number of times various header fields were processed, distribution of reputation scores, and any errors.
sshaccesscontrol resetlist Deletes the entire list of hosts or networks that are configured for SSH access.
Debug Mode
CLI Command Description
force_ssmode_trust Enables or disables the use of self-signed certificate for trust establishment or to check if the trust is established using self-signed or CA-signed certificate.
set auditlog-failure-respcfg Specifies the response action for audit logging failure.
set fe-switch-hardware-hashing-method Used to select the hashing method to distribute traffic through the Sensor.
show auditlog-failure-respcfg status Displays the response action configured for audit logging failure.
show fe-switch-hardware-hashing-method Displays the hashing method used to distribute traffic through the Sensor.
show msoffice-dfi stats Displays number of MS Office sub- files (files compressed within a file) and total compressed bytes sent for decompression as part of MS Office deep file inspection. Also, displays average size of decompressed files in bytes.
show nianticrecovery status Displays whether autorecovery is enabled on detection of stoppage of Niantic transmission.

Following Sensor CLI commands are updated:

Normal Mode
CLI Command Description
show gti config Displays the URL reputation configuration details for the GTI server.
show gti stats url Displays the GTI server statistics for URL reputation.
show ssl stats inbound known-key show ssl stats inbound command changed to show ssl stats inbound known-key.
show ssl stats outbound proxy show ssl stats outbound command changed to show ssl stats outbound proxy.
show ssl stats inbound known-key agents show ssl stats inbound agents command changed to show ssl stats inbound known-key agents.

Following Sensor CLI commands are removed:

Normal Mode
CLI Command
set l2f-unknown-udp
set outofcontext acllookup
show l2f-unknown-udp status
Debug Mode
CLI Command
set console mux
set http-rsp
show tempcounterstatus

For more information, see the CLI commands section in the Trellix Intrusion Prevention System Product Guide.