The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Licensing for proxy based SSL decryption

Prev Next

With this release of 10.1, the proxy based SSL licenses must be assigned to specific Sensors. The SSL decryption feature can be enabled now even before importing the license to the Manager. Upon license expiration, the SSL decryption feature is not disabled automatically. But configuration updates to the Sensor will not be possible until a new license is assigned to the Sensor. Configuration updates like signature set update and policy update are disabled when an invalid license is assigned to the Sensor.

Points for consideration:

  • After upgrading the Sensor to 10.1, the SSL license has to be reassigned to the Sensor.
  • To procure the demo licenses, contact MB Licensing.
  • To procure production licenses, refer the following SKUs:
    Sensor Model SKU's
    NS9500 with 30 Gbps SSL9530ECE-AT
    NS9500 with 20 Gbps SSL9520ECE-AT
    NS9500 with 10 Gbps SSL9510ECE-AT
    NS9200 OSLNS92ECE-AT
    NS9100 OSLNS91ECE-AT
    NS7300 OSLNS73ECE-AT
    NS7200 OSLNS72ECE-AT
  • The SSL proxy based licenses have a validity of one year from the day it is ordered.
  • Warning is generated in the Manager 30 days before the license expiry.

    To view the faults, go to, Manager → <Admin Domain Name> → Troubleshooting → Logs and select Faults tab to view the system faults.

  • For NS9500 (Standalone), the system license and the proxy SSL license assigned to the Sensor must have the same capacity to perform configuration update.
  • For a HA pair, proxy based SSL decryption license must be assigned to both the primary and the secondary Sensors.