The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Optimal Sensor location determination

Prev Next

The previous section is mostly intended as a point of reference. The good news is that Trellix IPS fail-over process is often identical, whether the network fail-over configuration is active-active, with or without asymmetric routing, active-passive, or even made up of a single path.

The details are as follows:

  • Both the Sensors in a fail-over pair are always in an active state. In this way, they are sure to protect a network on which the redundant path is active.

  • However, such an approach does not preclude the Sensors from protecting a network on which the Secondary path is passive; the Sensor on the passive path will not have much or any flow information to pass to its counterpart.

  • Sensors in a fail-over Pair scan independently, but use the information they share with each other during the scanning process. In this way, if a flow happens to be asymmetrically routed across both Sensors, each Sensor will end up with the full flow.

Redundant Sensors on redundant paths

Determining the optimal physical location for the Sensors on a redundant network is usually quite obvious. If you ignore the idea of Trellix IPS fail-over for a moment, the rule of thumb for Sensor placement is to install the Sensor along the same boundaries of trust that often guide firewall placement. In fact, most Sensor installations are either directly inside or directly outside the company firewall. Of course, like a firewall, a Sensor can be used deep inside an enterprise to isolate one segment of the network from the next.

The same basic rule applies to Trellix IPS fail-over. If the network currently has parallel firewalls connected to parallel switches, for example, it follows that you can introduce parallel Sensors between them. The following set of diagrams is a very simple "before and after," to help clarify the logic. (The dotted line represents a heartbeat link.):

Determination of optimal Sensor location — Before
Determination of optimal Sensor location — Before


Determination of optimal Sensor location — After
Determination of optimal Sensor location — After


The key is to ensure the redundant Sensors will be scanning the same traffic at the same point in the network. If you were to instead place one Sensor outside the firewall on one path and the other Sensor inside the firewall on the other path, the outcome is what developers like to refer to as "undefined." That is, there is no telling what false positives and false negatives, and even instability, such a setup might produce.