The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Note about upgrading the Sensor from 10.1 or 11.1 to 11.1.5.122

Prev Next

Enhanced security measures for proxy-based SSL/TLS decryption

Starting with this release of 11.1, enhanced security measures have been implemented to bolster both inbound and outbound proxy-based SSL/TLS decryption. The new features include the following:

  • Proxy-based SSL decryption is supported on NS9600 (standalone and stack), NS9500 (standalone), NS7600, NS7500, and NS3600 Sensors.

  • IPS-VM5000-SSL, IPS-VM600-SSL, and IPS-VM600-VSS-SSL Sensors are introduced for virtual and cloud deployments.

  • Support for jumbo frame parsing.

  • SSL decryption exclusions apply to both inbound and outbound SSL decryption.

  • Support for 4096-bit RSA and up to 521-bit ECDSA certificates.

  • HTTP2 traffic inspection with TLS is supported.

Note

  • The re-signing CA certificate must be created for server authentication and added to the browser as a trusted authority without purpose limitations.

  • The "Outbound" Block Flow configuration will apply to "Inbound" and may block inbound flow if an internal web server uses expired/untrusted CA certificates. Thus, an exception rule with the specific internal web server IP should be added to allow inbound flow without decryption when block flow is configured.

  • Once Inbound proxy is enabled, all Inbound traffic will be decrypted; However, it is recommended to create a proxy rule for Inbound SSL decryption.

License requirements for proxy-based SSL decryption

Model

System license

SSL license

Virtual license

NS9600 (standalone and stack), NS7600, and NS3600 Sensors

Requires a separate system license for each throughput per device.

Requires one SSL license per device, regardless of throughput.

NA

NS9500 (standalone) and NS7500 Sensors

Requires a separate system license for each throughput per device.

Requires an SSL license based on the device system license.

NA

IPS-VM5000-SSL, IPS-VM600-SSL, and IPS-VM600-VSS-SSL Sensors

NA

NA

Requires one or more SSL-enabled virtual Sensor licenses (IPS-VM1000-SSL-CLD-SUB) depending on the Sensor or cluster capacity.

Example:

  • IPS-VM600-SSL - 1 unit of license

  • IPS-VM5000-SSL - 5 units of license

Supported models and platforms

The following table lists the supported models and platforms for the proxy-based inbound and outbound SSL decryption:

Models

Platform

NS9600, NS9600_Stack, NS9500_Standalone, NS7600, NS7500, and NS3600

All

IPS-VM5000-SSL and IPS-VM600-SSL

ESXi and KVM

IPS-VM600-VSS-SSL

AWS and Azure

Important

IPS-VM5000-SSL, IPS-VM600-SSL, and IPS-VM600-VSS-SSL Sensors are compatible with signature set version 11.10.28.4 and above.

A new command show ssl proxy is included to support the SSL enhancements.

Support for SMB and DCERPC layer 7 data collection and SmartVision attack related L7 metadata and alerts export to Trellix Network Investigator

Starting with this release of 11.1, Trellix IPS supports collecting layer 7 data for SMB (SMBv1 and SMBv2) and DCERPC protocols (over TCP). It also exports the SmartVision attack related L7 metadata related to these protocols from IPS Sensors and alerts from IPS Manager, when the integration between Trellix IPS and Trellix NI is enabled. The SmartVision alerts and L7 metadata collected for SMB and DCERPC protocol traffic and exported to NI further enhances its SmartVision capabilities for detecting malicious activities, such as malware lateral movement, data exfiltration, and beaconing.

Consider the following if you want to enable the detection and export of SmartVision attacks related L7 metadata and alerts related to SMB and DCERPC protocols to NI:

  • You need to use Manager and Sensor(s) running on 11.1 Update 8 and later, along with a compatible signature set (11.10.28.4 and above) that includes SMB and DCERPC related attack signatures.

  • Manager running on 11.1 Update 8 and later includes additional L7 data fields for SMB (under the netbios-ss section) and DCERPC protocols in the Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection page. These L7 fields related to SMB and DCERPC protocols are applicable only for Sensors running on 11.1 Update 8 version or later and can be customized accordingly.

    Note

    DCERPC L7 data collection is supported over TCP only.

  • When Trellix IPS and Trellix NI is integrated, Manager sends all relevant alert data (including SmartVision attacks) to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later send only SmartVision attack-related L7 metadata to NI.

Support for script files for advanced malware detection

Starting with this release of 11.1, Trellix IPS supports script files to be scanned while configuring an advanced malware policy. It is available for configuration under the File Scanning Options section in the Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware page. To know the list of advanced malware file extensions supported by signature sets, refer to KB96988.

After configuring the advanced malware policy, you need to assign it to the required Sensor monitoring resources such as ports, interfaces, and sub-interfaces. You must do a configuration and signature set update for any changes in the policy to take effect.

Support for 4-port 100/40 Gigabit with internal fail open interface modules in NS9600 Sensor

Starting with this release, the NS9600 Sensor supports the following network interface modules in G1 and G2 slots (any combination of the interface modules can be used):

  • 4-port 100/40 Gigabit SR MTP/MPO interface module with built-in fail open

  • 4-port 40 Gigabit LR4 interface module with built-in fail open

  • 4-port 100 Gigabit LR4 interface module with built-in fail open

  • 4-port 100/40 Gigabit BiDi interface module with built-in fail open

Note

These interface modules are supported only in NS9600 Sensors running on 11.1 Update 8 version or later.

Important

If you have configured 100/40 Gigabit SR MTP/MPO or BiDi with internal fail-open network interface modules with the 100 Gbps speed and you want to reconfigure the speed to 40 Gbps, you may have to click Disable and then Enable the ports once or twice and refresh the Monitoring Ports tab to bring up the ports. This also applies to 100/40 Gigabit SR MTP/MPO interface module.

Enhancements in the NS3600 Sensor

Starting with this release of 11.1, the NS3600 Sensor includes enhancements to display the temperature status of the power supply unit.

Sample output for NS3600 Sensor with chassis version 0.1:

intruShell@NS3600> show powersupply

==== PSU Status ====
PSU Model: FSP300-50RFB
PSU Firmware: 001
Vin: 230.00 V
Vout: 12.14 V
Iout: 5.64 A
Pin: 92.00 W
Pout: 83.00 W
Ambient Temp: 30.00 C
PSU1 Temp: 33.00 C
PSU2 Temp: 25.00 C
Fan Speed: 3148 rpm
Status: OK
Vout Status: OK
Iout Status: OK
Temp Status: OK

Power Supply PRESENT health = OK

Enhanced support for latency troubleshooting

With this release of 11.1, Trellix IPS introduces a significant improvement to latency troubleshooting, providing a streamlined solution for diagnosing performance-related issues. It addresses common latency-related problems such as slow application response, packet drops, network slowdowns, and delayed file transfers/database operations.

You can use the latency-troubleshooting command to add, delete, list the configured commands, modify the frequency of execution, and collect logs from the trace in debug mode.

The following commands are available:

Parameter

Syntax

Description

start

latency-troubleshooting start

Starts latency troubleshooting

status

latency-troubleshooting status

Check the current status of latency troubleshooting

stop

latency-troubleshooting stop

Stops latency troubleshooting

command

add

latency-troubleshooting command add <"idscli+COMMAND">

Add a command to the list

delete

latency-troubleshooting command delete <"idscli+INDEX">

Delete a command from the list

list

latency-troubleshooting command list

Lists all added commands

run

latency-troubleshooting run

Run latency troubleshooting once

set

frequency

latency-troubleshooting set frequency <number>

Modify the frequency of run

rollover_limit

latency-troubleshooting set rollover_limit <number>

Sets the number of logs to retain