The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Release information

Prev Next

This release of Trellix IPS is to provide new features and enhancements on the Manager and NS-series Sensor software.

Release parameters

Version

IPS Manager software

11.1.7.3

Signature Set

11.9.0.21

NS-series Sensor software (NS9500, NS9300, NS9200, NS9100, NS7500, NS7350, NS7300, NS7250, NS7200, NS7150, NS7100, NS5200, NS5100, NS3500, NS3200, NS3100)

11.1.5.2

Trellix SSL Agent (For inbound SSL decryption using DHE/ECDHE ciphers)

1.0.4

Suricata Snort Engine

3.2.3

Note

The Manager version 11.1.7.3 has been retracted from Trellix Download Server. It has been replaced by Hotfix version 11.1.7.3.5. For more information, see KB96458.

Note

The Signature Set version 11.9.0.21 bundled with this release of Manager contains only Digital Envoy database for IP address to Geolocation Mapping. This signature set version will not be a part of the publicly available signature sets.

Note

When you upgrade the Sensor software version to 11.1.5.2, you must also upgrade the corresponding Manager software version to 11.1.7.3.

For more information, see Manager and its compatible Sensor software versions in Trellix Intrusion Prevention System 11.1.x Product Guide.

Note

The Manager software 11.1 is not supported on Windows-based Appliance. The end-of-life for Windows-based Appliance has been declared and the end-of-life is on 01-Apr-2023. Trellix recommends you to migrate from Windows-based Appliance to Linux-based Appliance.

Note

If you have a 9.x Manager managing 9.x NTBA, you should consider upgrading 9.x Manager to 10.1 or 11.1. If you plan to upgrade the Manager to 11.1, you need to first upgrade it to 10.1.7.65 and then to 11.1.

Upgrade support

Trellix regularly releases updated versions of the signature set. You can choose to automatically download and deploy the signature set in the Manager.

Upgrade paths for Manager software versions

Note

Before you start upgrading to the latest 11.1 Manager version, ensure that you do not change the timestamp and timezone values of the Manager.

Caution

The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.

Caution

If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 10.1.7.65 or above, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 10.1.7.65 or above. Post this, you may upgrade the Sensor to 10.1.5.190 or above.

For example, if you have a NS9500 Sensor running on software version 9.2.5.52 (TLS 1.0) and Manager software version 10.1.7.44, and you plan to upgrade the Sensor to 10.1.5.190 and Manager to 10.1.7.65, you must follow the upgrade path as listed below:

  1. Upgrade your NS9500 Sensor from 9.2.5.52 (Supports TLS 1.0) to 10.1.5.107 (Supports TLS 1.2).

  2. Upgrade the Manager from 10.1.7.44 to 10.1.7.65.

  3. Upgrade the Sensor from 10.1.5.107 to 10.1.5.190.

Similarly, if you have a NS9300 Sensor running on software version 9.2.5.72 (TLS 1.0) and Manager software version 10.1.7.44, you must follow the upgrade path as listed below:

  1. Upgrade your NS9300 Sensor from 9.2.5.72 (Supports TLS 1.0) to 10.1.5.106 (Supports TLS 1.2).

  2. Upgrade the Manager from 10.1.7.44 to 10.1.7.65.

  3. Upgrade the Sensor from 10.1.5.106 to 10.1.5.190.

Note

If you have Sensor software version that supports TLS 1.0, please refer to KB96194 and contact Trellix Support for assistance.

Windows based Manager:

Version

Upgrade path to 11.1

10.1.7.4, 10.1.7.7, 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66.3

11.1.7.3

Note

The Manager version 11.1.7.3 has been retracted from Trellix Download Server. It has been replaced by Hotfix version 11.1.7.3.5. For more information, see KB96458.

Linux based Manager:

Caution

After upgrade, the Linux-based Manager reboots automatically. If it fails to reboot, check the installation logs for errors and reboot the Manager manually.

Version

Upgrade path to 11.1

10.1.7.4, 10.1.7.7, 10.1.7.25 (Cloud), 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66 (Cloud), 10.1.7.66.3

11.1.7.3

Note

The Manager version 11.1.7.3 has been retracted from Trellix Download Server. It has been replaced by Hotfix version 11.1.7.3.5. For more information, see KB96458.

Note

For all direct upgrades to 11.1.7.3.5, use the IPSM_111735_setup.bin Version 11.1.7.3.5 upgrade file.

Upgrade paths for Sensor software versions

Caution

The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.

Caution

If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 10.1.7.65 or above, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 10.1.7.65 or above. Post this, you may upgrade the Sensor to 10.1.5.190 or above.

For example, if you have a NS9500 Sensor running on software version 9.2.5.52 (TLS 1.0) and Manager software version 10.1.7.44, and you plan to upgrade the Sensor to 10.1.5.190 and Manager to 10.1.7.65, you must follow the upgrade path as listed below:

  1. Upgrade your NS9500 Sensor from 9.2.5.52 (Supports TLS 1.0) to 10.1.5.107 (Supports TLS 1.2).

  2. Upgrade the Manager from 10.1.7.44 to 10.1.7.65.

  3. Upgrade the Sensor from 10.1.5.107 to 10.1.5.190.

Similarly, if you have a NS9300 Sensor running on software version 9.2.5.72 (TLS 1.0) and Manager software version 10.1.7.44, you must follow the upgrade path as listed below:

  1. Upgrade your NS9300 Sensor from 9.2.5.72 (Supports TLS 1.0) to 10.1.5.106 (Supports TLS 1.2).

  2. Upgrade the Manager from 10.1.7.44 to 10.1.7.65.

  3. Upgrade the Sensor from 10.1.5.106 to 10.1.5.190.

Note

If you have Sensor software version that supports TLS 1.0, please refer to KB96194 and contact Trellix Support for assistance.

Sensor models

Version

Upgrade path to 11.1

NS9500 (Standalone)

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190

11.1.5.2

NS9500 (Stack)

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190

11.1.5.2

NS-series (NS9300, NS9200, NS9100, NS7300, NS7200, NS7100, NS5200, NS5100, NS3200, NS3100)

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190

11.1.5.2

NS7500

10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190

11.1.5.2

NS7x50

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190

11.1.5.2

NS3500

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190

11.1.5.2

Note

If the Sensor is running on 10.1.5.153 or a later version of 10.1 and you plan to downgrade it to 10.1.5.106 (for NS9300, NS9200, NS9100, NS7500, NS7300, NS7200, NS7100, NS5200, NS5100, NS3500, NS3200, NS3100) or 10.1.5.107 (for NS9500, NS7350, NS7250, NS7150) or any older version, you need to first downgrade the Sensor to 10.1.5.116 and then downgrade it to the targeted version. Please refer to KB96194 and contact Trellix Support for further assistance.

Heterogeneous support

This version of 11.1 Manager software can be used to configure and manage the following devices:

Device

Version

NS-series Sensors (NS3100, NS3200, NS3500, NS5100, NS5200, NS7100, NS7200, NS7300, NS7150, NS7250, NS7350, NS7500, NS9100, NS9200, NS9300, NS9500 standalone and stack)

10.1, 11.1

Virtual IPS for ESXi server, AWS, and Azure (IPS-VM600)

10.1, 11.1

NTBA Appliances (T-600, T-1200)

9.1

Virtual NTBA Appliances (T-VM, T-100VM, T-200VM)

9.1

Integration support

Trellix IPS version 11.1 supports integration with the following product versions:

Product

Version supported

Trellix ePolicy Orchestrator - On-prem

5.10.0 Update 15

Trellix Endpoint Security

10.7.0

Trellix Global Threat Intelligence

Compatible with all versions

McAfee Endpoint Intelligence Agent

3.2.4

McAfee Logon Collector

3.0.10

Trellix Threat Intelligence Exchange

4.0.0, 3.0.3, 3.0.1

Trellix Data Exchange Layer

6.0.3

Trellix Intelligent Sandbox

5.2, 5.0, 4.14.2

Virtual Trellix Intelligent Sandbox

5.2, 5.0, 4.14.2

Trellix Virtual Execution

9.1.2 and above