The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Primary vs. Active

Prev Next

You configure a HA pair using the Manager. You designate one Sensor as the template Sensor and the other as peer. This designation is used purely for configuration purposes and has no bearing on which Sensor considers itself active.

Once configured, the two Sensors exchange information to determine their respective roles; the Sensor that has been online the longest becomes the active Sensor. If they have been online for exactly the same amount of time, the Sensor with the higher serial number takes the active role. The Sensors communicate every second to determine if their peer is available. If the HA pair cannot communicate with each other, each Sensor will assume its peer Sensor is down, and both will issue alerts. If communication is re-established, the two Sensors communicate to determine their respective failover roles.

When one Sensor is brought up well after the other, the new Sensor synchronizes state with the old Sensor and builds on the synchronized state based on the packets received on its monitoring and interconnect ports.

This Active-Active configuration provides the added benefit of supporting asymmetric traffic flows (that is, when packets belonging to the same TCP/UDP flow are divided across Sensors). Thus, the Trellix IPSHA pair will detect attacks even when the traffic is asymmetric. This topic is discussed, in the section Interface groups.