The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Release information

Prev Next

This release of Trellix vIPS is to provide new features and enhancements on the Manager and Virtual IPS Sensor software.

Release parameters

Version

IPS Manager software

11.1.7.154

Signature Set

11.10.35.5

Virtual IPS Sensor software

11.1.7.152

Virtual Controller/Probe

2.7.2

Trellix SSL Agent (For inbound SSL decryption using DHE/ECDHE ciphers)

1.0.5

Caution

The IPS Manager no longer supports HTTP-based connection and can be accessed via HTTPS connection only. You need to manually enter the following on the supported browsers to access the Manager UI.

  • For Hostname or IPv4: https://hostname or host-IP

    Example: https://localhost or https://10.x.x.x

  • For IPv6: https://[IPv6 address]

    Example: https://[2607:8xxx:4xx:2xxx::5100]

Note

If you have a 9.x Manager managing 9.x NTBA, you should consider upgrading 9.x Manager to 10.1 or 11.1. If you plan to upgrade the Manager to 11.1, you need to first upgrade it to 10.1.7.65 and then to 11.1. From this release onwards, this only applies to Windows-based Manager upgrades.

Upgrade support

Upgrade paths for Manager software versions

Note

Before you start upgrading to the latest 11.1 Manager version, ensure that you do not change the timestamp and timezone values of the Manager.

Caution

  • The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.

  • If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.154, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.154. Post this, you may upgrade the Sensor to 11.1.7.152.

Windows-based Manager:

Version

Upgrade path to 11.1

10.1.7.4, 10.1.7.7, 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66.3, 10.1.7.66.11

11.1.7.154

11.1.7.3, 11.1.7.3.5, 11.1.7.26, 11.1.7.41, 11.1.7.41.2, 11.1.7.56, 11.1.7.71, 11.1.7.84, 11.1.7.97, 11.1.7.111, 11.1.7.121, 11.1.7.136, 11.1.7.136.2

11.1.7.154

Note

For all direct upgrades to 11.1.7.154 for Windows-based Manager, use the IPSM_1117154_setup.exe file.

Linux-based Manager:

Important

  • Physical appliances: To install the 11.1 Update 10 (Trellix OS) on your Manager appliance, you must migrate from 11.1 Update 9 (MLOS). For more information, see Migrating from 11.1 Update 9 MLOS Manager Appliance to 11.1 Update 10 Trellix OS Manager Appliance.

  • VM instances: You cannot perform a direct upgrade or migrate from 11.1 Update 9 to 11.1 Update 10. To install the 11.1 Update 10 version of the Trellix OS Manager on a VM, you must perform a fresh deployment and restore All Table Backup. For more information, see Prepare for 11.1 Update 10 Trellix OS Manager fresh virtual machine instance deployment.

  • A direct upgrade from 11.1.7.153 or 11.1.7.153.9 to 11.1.7.154 is not supported on Trellix OS IPS Manager. These builds require a specific upgrade procedure. If you plan to upgrade from these builds, contact support for assistance.

  • A direct upgrade from 11.1 Update 9 to 11.1 Update 10 is not supported. To migrate your existing data, take an All Table Backup of the 11.1 Update 9 Manager, deploy a new 11.1 Update 10 Manager, and restore the 11.1 Update 9 database. Then, deploy the Sensors using the user data from the cluster.

    When you deploy a new Manager for Trellix OS in an MDR environment, and a database restore is done, the configuration displays the previous Manager's details. To resolve this, set the Manager to standalone mode and then set up MDR using the new peer Manager details.

Upgrade paths for Sensor software versions

Virtual IPS Sensor software (IPS-VM600, IPS-VM5000, IPS-VM600-SSL, IPS-VM600-VSS-SSL, and IPS-VM5000-SSL):

Caution

  • The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.

  • If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.154, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.154. Post this, you may upgrade the Sensor to 11.1.7.152.

Sensor models

Version

Upgrade path to 11.1

IPS-VM600

10.1.7.1, 10.1.7.42, 10.1.7.51, 10.1.7.65, 10.1.7.86, 10.1.7.96 , 10.1.7.123, 10.1.7.135, 10.1.7.155, 10.1.7.156 (Cloud)

11.1.7.152

11.1.7.1, 11.1.7.22, 11.1.7.44, 11.1.7.56, 11.1.7.72, 11.1.7.81, 11.1.7.98, 11.1.7.111, 11.1.7.121, 11.1.7.136

11.1.7.152

IPS-VM600-SSL, IPS-VM600-VSS-SSL, and IPS-VM5000-SSL

11.1.7.121, 11.1.7.136

11.1.7.152

IPS-VM5000

11.1.7.44, 11.1.7.56, 11.1.7.72, 11.1.7.81, 11.1.7.98, 11.1.7.111, 11.1.7.121, 11.1.7.136

11.1.7.152

Important

Starting with the 11.1 Update 2 release, the minimum memory requirement for IPS-VM600 deployment on ESXi and KVM is 8 GB. Contact Trellix support for more information and assistance.

Note

If the Sensor is running on 10.1.7.123 or a later version of 10.1 and you plan to downgrade it to 10.1.7.86 or an older version, you need to first downgrade the Sensor to 10.1.7.96 and then downgrade it to an older version.

Heterogeneous support

These versions of 11.1 Manager software can be used to configure and manage the following devices:

Device

Version

NS-series Sensors (NS3100, NS3200, NS3500, NS5100, NS5200, NS7150, NS7250, NS7350, NS7100, NS7200, NS7300, NS7500, NS9100, NS9200, NS9300, NS9500 standalone and stack)

10.1, 11.1

NS-series Sensors (NS3600, NS7600, and NS9600 - standalone and stack)

Note

NS7600 and NS3600 Sensors have been introduced with the 11.1 Update 5 release, and NS9600 Sensor with the 11.1 Update 7 release.

11.1

Virtual IPS for AWS and Azure (IPS-VM600 and IPS-VM600-VSS-SSL)

10.1, 11.1

Virtual IPS for KVM and ESXi server (IPS-VM600, IPS-VM5000, IPS-VM600-SSL, and IPS-VM5000-SSL)

Note

  • IPS-VM5000 and support for KVM have been introduced with 11.1 Update 2 release.

  • IPS-VM600-SSL, IPS-VM5000-SSL, IPS-VM600-VSS-SSL and have been introduced with 11.1 Update 8 release.

10.1, 11.1

Integration support

Trellix IPS version 11.1 supports integration with the following product versions:

Product

Version supported

Trellix Data Exchange Layer

6.0.3

Trellix Endpoint Security

10.7.0

Trellix ePolicy Orchestrator - On-prem

5.10 SP1

Trellix Global Threat Intelligence

Compatible with all versions

Trellix Intelligent Sandbox

5.4.0 and above

Virtual Trellix Intelligent Sandbox

5.4.0 and above

Trellix Intelligent Virtual Execution - Server

10.0.0, 11.0.1

Trellix Intelligent Virtual Execution Cloud

Version 25R4

Trellix Logon Collector

3.0.11

Trellix Network Investigator (Appliance and Virtual)

3.2.0 and 4.0.0

Trellix Threat Intelligence Exchange

4.0.0

Note

Integration with any point product is not supported on public cloud deployments.