The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes for upgrading the Sensor from 10.1 or 11.1 to 11.1.5.84

Prev Next

If you are upgrading the Sensor from version 10.1 or 11.1 to version 11.1.5.84, read the following sections carefully.

Introducing Trellix Intrusion Prevention System Sensor - NS7600

This release of 11.1 introduces Trellix's next-generation IPS NS7600 Sensor model. The NS7600 Sensor operates at 5 Gbps, 10 Gbps, and 15 Gbps throughput depending on the license purchased.

The NS7600 Sensors are 1RU units equipped with the following components:

  • 4 SFP/SFP+ 1/10 Gigabit Ethernet ports in built-in G0 module

  • Three slots (G1, G2 and G3) for pluggable and hot swappable I/O modules:

    • 6-port RJ45 10/1 Gigabit with internal fail-open interface module

    • 8-port 10/1 Gigabit SM (8.5 micron) with internal fail-open interface module

    • 8-port 10/1 Gigabit MM (50 or 62.5 micron) with internal fail-open interface module

      Caution

      Apart from the network interface modules mentioned above, no other interface modules are compatible with the NS7600 Sensor.

  • SFP+ (SM and MM), SFP Fiber (SM and MM), and SFP Copper transceiver modules are supported in NS7600 Sensor models.

    Note

    Transceiver modules are supported in the built-in G0 module only.

  • One console port

  • Two external USB ports for Storage/Rescue applications

  • One RJ-45 10 Gbps/1 Gbps Management port

  • One RJ-45 10 Gbps/1 Gbps Response port

  • The front and rear panel LEDs provide status information for the health of the Sensor and the activity on its ports

To know information on NS7600 Sensor capacity, refer to the section NS7600 Sensor capacity. Note that the following features are not supported in NS7600 Sensors:

  • Suricata Snort engine

  • Proxy-based SSL decryption (both inbound and outbound)

Introducing Trellix Intrusion Prevention System Sensor - NS3600

This release of 11.1 introduces Trellix's next-generation IPS NS3600 Sensor model. The NS3600 Sensor model provides 1 Gbps, 3 Gbps, and 5 Gbps throughput.

The NS3600 Sensors are equipped with the following components:

  • Console port

  • USB port

  • RJ-45 10/100/1000 Mbps Ethernet Monitoring ports

  • RJ-45 10/100/1000 Management port (MGMT)

  • RJ-45 10/100/1000 Response port (R1)

  • 2-port 10/1 Gbps Ethernet Monitoring ports (This requires SFP/SFP+ transceivers and they are sold separately.)

The Sensor LEDs provide status information for the health, link, speed, and activity on its management/response/monitoring ports.

The NS3600 Sensors support the 4-port copper and fiber interface modules. These interface modules can be installed in only one slot that includes ports 11-14 on the Sensor. Note that the interface modules are not hot-swappable. The NS3600 Sensors support the following interface modules:

  • 4-port RJ-45 1 Gbps/100 Mbps/10 Mbps with internal fail-open Network Interface Module

  • 4-port 10/1 GigE MM 50/62.5 μm with internal fail-open Network Interface Module

In NS3600 Sensors, transceiver modules are supported only in ports 5 and 6. It includes SFP+ (SM and MM) and SFP Fiber (SM and MM).

The following features are not supported in NS3600 Sensors:

  • Suricata Snort engine

  • Proxy-based SSL decryption (both inbound and outbound)

IPS CLI enhancements

The following Sensor CLI command is added:

Normal Mode

Command

Description

show gam-behavioral-scan status

This command displays the status of the behavioral scan on the Gateway Anti-Malware engine as enabled or disabled.



Debug Mode

Command

Description

set gam-behavioral-scan config

This command allows users to enable or disable behavioral scans on the Gateway Anti-Malware engine.

getnimdprotostats

This command displays counter specifics related to successful metadata export per protocol to Trellix Network Investigator when the integration with Trellix NI is enabled.



The following Sensor CLI command is updated:

Normal Mode

Command

Description

show inlinepktdropstats <all>

(Applicable to NS7600 Sensors only) The show inlinepktdropstats all command now shows the count for the following two categories:

  • Count of packets dropped due to oversubscription. This count is triggered when the throughput exceeds the subscription limit. This is a subset of Total Other Layer-2 Packets Dropped.

  • Count of packets not dropped though oversubscribed. This count is triggered when the subscribed license capacity is reached but packets are not dropped.



Debug Mode

Command

Description

getnistats

This command now shows additional counter specifics related to netflow and metadata export to Trellix NI. Some of these counters include the following:

  • NI netflow metadata export failure count

  • NI metadata request timeout error count

  • NI netflow export timeout and NI netflow metadata export timeout count

  • NI netflow template creates success and failure count

  • NI netflow metadata template creates success and failure count

  • NI netflow queue drop and netflow metadata queue drop count



This release provides the following enhancements related to platforms, environments, or operating systems:

OpenSSL upgrade

Starting with this release of 11.1, the OpenSSL version is upgraded to 1.0.2zh-fips. This new version includes additional security against new vulnerabilities.