The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Resolved issues

Prev Next

The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release.

For a list of current known issues, see: Trellix IPS 11.1 Known Issues (KB96274).

Resolved Manager software issues

The following table lists the high-severity Manager software issues:

Reference #

Resolution

NSPMGR-30119

Fixes an issue where the system remained in a persistent loading state when attempting to create Correlation-Based Custom Reconnaissance Attack.

NSPMGR-30010

Updated the compilation failure message to specify the missing rule object ID when a signature deployment fails.

The following table lists the medium-severity Manager software issues:

Reference #

Resolution

NSPMGR-30213

Changes to the Syslog Facility option in the Manager → Setup → Notification → IPS quarantine access events page would not save and reverted to the default value.

NSPMGR-30208

Enhances the scheduler logic to automatically download the Public Global Threat Intelligence (GTI) certificate file (tsgtipubcerts.bin) if it is missing from the Manager.

NSPMGR-30098

The CustomJSSEcaCerts file (/opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts) is set to read-only permissions after a fresh installation or migration to TREFOS. This prevents write access and causes LDAP authentication failures.

NSPMGR-30097

The show ipsmanager logs command fails to list the logs in the CLI and displays the error: % No folder/directory present: /var/opt/ipsm/logs/.

Workaround: Log in to root mode to access the log files.

NSPMGR-30018

Ensures the option to copy the Graphical User Interface (GUI) certificate is respected during MDR pair creation.

NSPMGR-29918

The automatic Callback Detectors successfully deploys to Sensors on the Azure platform.

NSPMGR-29870

The Post-Attack notation appears correctly in the Capture Packets field of the attack definitions grid when viewed in the policy screen.

NSPMGR-29865

Snort rule validation correctly shows failed status for invalid rules, and rule syntax remains visible after adding a rule.

NSPMGR-29753

Changing the Application Identification setting for member Sensors in a stack correctly triggers the Deploy Pending Changes flag.

NSPMGR-29484

The CSV files containing Chinese characters in the filename import correctly into the blocked file hash list.

NSPMGR-29467

The Manager is correctly excluded as a fault source in the Fault Report when only the Sensor is selected in Manager → Reporting → Configuration Reports → Faults.

NSPMGR-29251

Windows-based Managers successfully access APIs related to cloud clusters without internal errors.

NSPMGR-28850

Azure cloud discovery works correctly when using a proxy server by properly handling HTTPS proxy requests.

NSPMGR-27897

NTP and Restrict SSH Access settings persist on Failover (FO) Sensors after changing the Sensor's Internet Protocol (IP) address.

Resolved Sensor software issues

The following table lists the high-severity Sensor software issues:

Reference #

Resolution

NSPSNSR-17183

The backend processor incorrectly handled memory segments during the decode process. This caused buffer corruption resulting in a backend process crash.

NSPSNSR-17103

Global Threat Intelligence (GTI) credentials remain persistent across sensor reboots. This ensures that authentication checks pass successfully using existing data, preventing "Invalid GTI Private Cloud Server username" errors.

The following table lists the medium-severity Sensor software issues:

Reference #

Resolution

NSPSNSR-17187

The NS3600 sensor model supports up to 100,000 customized attacks. This increase from the previous 40,000 limit allows successful configuration pushes when attack counts are high.

NSPSNSR-17091

Enhanced alert throttling (specifically the 24-hour alert suppression window) is unavailable on NS7600 Sensors running with a 20 Gbps license.

NSPSNSR-17079

The Alert Channel connection to the Standby Manager intermittently disconnects and reconnects (flaps) on Virtual IPS Sensor configured with a CA-signed 2048-bit trust certificate in an MDR environment.

NSPSNSR-17030

SSL proxy exceptions were not working correctly in scenarios where the traffic bypass decision was delayed.

NSPSNSR-17019

Allow list/Block list bulk update fails when there are hash entries with file size 0.

NSPSNSR-16940

[NS3600] "Keep Monitoring ports enabled on Link Failures" does not work when NS3600 sensors are configured for failover.

NSPSNSR-16939

Corrects misleading malware statistics for the IVX engine by ensuring files are marked as "Ignored" instead of "Processed" when no broker is configured.

NSPSNSR-16774

Malware FFP Bulk Update failure was seen due to list corruption.

NSPSNSR-16411

Resolves a delay in Secure Shell (SSH) connection establishment and CLI command execution observed after upgrading Sensors to version 11.1.