The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage HA pairs

Prev Next

Go to Devices → <Admin Domain Name> → Global → Device Manager page. You can add new HA pairs by selecting the HA pair tab. A HA pair will be managed just as any other device is managed, by going to Devices → <Admin Domain Name> → <Device Name> → Devices.

Using the HA Pairs tab, you can enable failover configuration for two identical Sensor models. The term "HA pair" refers to the pair of devices that constitute the Primary-Secondary arrangement required for failover functionality. The Primary/Secondary designation is used purely for configuration purposes and has no bearing on which device considers itself active. Primary device designation determines which device's configuration is preserved and copied to the Secondary device by Manager. Both devices receive configuration and update changes from Manager; however, the Secondary accepts the changes as if they are coming directly from the Primary device. In the event of primary failure, the Secondary device will see all changes as coming directly from Manager.

Two devices in a HA pair can have different fail-open/fail-closed settings. It is possible to configure, for example, one device to fail open, and the second device to fail closed. The intended use of this option is in an Active-Standby configuration with the Active link configured to fail closed (to force traffic to the standby link in case of failure), and the Standby link configured to fail open (to provide uninterrupted traffic flow should both devices fail).

Note

For more information on high availability using HA pairing, see the Trellix Intrusion Prevention System Product Guide.

NS-series Sensor model Port(s) used for failover
NS9500 G0/1 (QSFP28 100 or 40G QSFP+)
NS9300 G1/1 and G1/2 (40G QSFP+)
NS9200 G0/1
NS9100 G0/1
NS7500 G0/1
NS7350 G0/1 (10G SFP+)
NS7250 G0/1 (10G SFP+)
NS7150 G0/1 (10G SFP+)
NS7300 G0/1 (10G SFP+)
NS7200 G0/1 (10G SFP+)
NS7100 G0/1 (10G SFP+)
NS5200 G1/1 and G1/2
NS5100 G1/1 and G1/2
NS3500 Not Supported
NS3200/NS3100 1

Note

High availability is not supported in NS3500 Sensor.

M-series Sensor model Port(s) used for failover
M-8000 3A and 3B
M-6050 4A. Note that 4B remains unused.
M-4050 2A
M-3050 2A
M-2950 6A
M-2850 6A
M-1450 4A
M-1250 4A

To configure two devices for failover, do the following:

Task

  1. Go to Devices → <Admin Domain Name> → Global → Device Manager page and select HA Pairs tab.

    The HA Pairs tab is displayed.
  2. Click . The New HA Pair dialog box is displayed.
    New HA pair window


  3. Enter the HA pair name that will uniquely identify the grouping in HA Pair Name.
  4. Select the Model from the drop-down option. Both devices in a HA pair must be using same model and same version.
  5. Select the Template Sensor from the drop-down option.
  6. Select the Peer Sensor from the drop-down option.
  7. Enable or disable Disable Monitoring Ports on Link Failure for the HA pair as per your requirement. By default, it is disabled.
  8. Click Save. A Confirmation dialog box is displayed. Click OK. The new HA pair will appear in the display list.

    Note

    In the Manager, if at least two Sensors are not using same model and software version, an Error dialog box is displayed.

    Note

    An option to edit the existing HA pair is not provided. If you double-click a row in the grid, an Error dialog box is displayed. You change the configuration by deleting and re-creating a HA pair.

    Note

    If you have created a HA pair while maintaining an open Attack Log window, the Attack Log will continue to report alerts from both the Primary and Secondary devices, respectively, identifying each device by the given device name and not by the name of the HA pair. This may cause confusion in the event that both devices detect identical alerts. (In true failover operation, if both devices detect the same alert, only one alert instance is reported with the name of the HA pair as the identifying device.) Restart the Attack Log for proper alert reporting. The same is true in reverse if a HA pair is deleted. You must restart the Attack Log to view alerts separately from each device.