The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Network scenario without virtualization

Prev Next

Imagine a network on which Windows and Linux hosts are interspersed. The best approach here is to apply a policy that includes attacks for both Windows and Linux hosts on all the ports through which their traffic will flow.

If this network happens to be controlled in such a way that the traffic from all the Windows hosts is flowing through one segment of the network and the traffic from all Linux hosts is flowing through a different segment, you could connect these different segments to different Sensor monitoring ports. You could then apply Windows-specific and Linux-specific policies to the respective ports. In doing so, you would minimize the chance of false positives and reduce the quantity of scanning required on each port.

When you consider that many IDS and IPS offerings only allow for a single policy per Sensor, the option to apply a unique policy to each port is much more impressive. But what happens if a Sensor doesn't have enough physical ports to cover the different ways in which traffic may be controlled on a given network? Or more realistically, what happens if the Sensor is placed at an aggregation point on the network, such as on a trunked uplink, or an administrator wants a unique policy applied to a single host or two? This is when virtualization becomes relevant.