The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Malware engine updates

Prev Next

Among the malware scanning engines present on the Sensor, the Gateway Anti-Malware Engine and the Block list can be updated through the intervention of the security administrator. Updates for these engines can be carried out independently irrespective of the Sensor software version.

However, for Gateway Anti-Malware, you must be aware of the versions of the malware engines that are compatible with specific Sensor and Manager versions. Refer to Gateway Anti-Malware Engine in the section How an Advanced Malware policy works in Trellix Intrusion Prevention System Product Guide.

Gateway Anti-Malware Engine for an airgap network

The Gateway Anti-Malware engine initialization in the Sensors requires an active connection to the GTI server. If your Sensors are in a network without an active GTI connection, the Gateway Anti-Malware engine initialization in the Sensor fails. In such a scenario, you must enable the airgap mode of Gateway Anti-Malware to initialize the Gateway Anti-Malware engine. You can achieve this by executing the set gam-airgap-network enable command in the Sensor CLI and reboot the Sensor for the changes to take effect.

For example, you can configure the Sensors to initialize the Gateway Anti-Malware engine in airgap mode when your network meets the following conditions:

  1. The Sensors are in a private network.

  2. You cannot use the Public GTI server.

You must enable the airgap mode of Gateway Anti-Malware before pushing the updates from the Manager to the Sensor. To view the status of the Gateway Anti-Malware updating for an airgap network, execute the show gam-airgap-network status command in the Sensor CLI.

Note

The Gateway Anti-Malware engine initialization for the Sensors in airgap network is supported on Gateway Anti-Malware 2019 version 0 and later.