The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Scenario 1: Inspection of traffic between virtual machines in SPAN mode

Prev Next

This scenario involves using a SPAN monitoring port to inspect traffic between virtual machines on the same ESX. Similar to the SPAN mode deployment of a physical Sensor, the SPAN mode deployment of a Virtual IPS Sensor is also simple and non-intrusive.

Scenario description before Virtual IPS Sensor deployment

  • The servers are installed on guest VMs on the ESX.
  • These servers are connected to a standard vSwitch — vSwitch0.
  • vSwitch0 has a physical adapter, which is connected to networks outside the ESX.
Scenario before Virtual IPS Sensor deployment


Scenario description after Virtual IPS Sensor deployment

  • Create a new switch port group set in promiscuous mode In vSwitch0.
  • The Virtual IPS Sensor is deployed on the ESX.
  • Consider that the Manager is installed on a VM connected to vSwitch1.
  • In this scenario, the Manager is connected to the management port of the Virtual IPS Sensor through vSwitch1. This vSwitch1 has a physical adapter vminc1. So, you can access the Manager and the Sensor from outside the ESX.
  • Monitoring port 1 of the Virtual IPS Sensor is in SPAN mode. This is connected to the promiscuous switch port group in vSwitch0. Therefore, a copy of all the packets of vSwitch0 are sent to port 1 for intrusion detection.
Scenario after Virtual IPS Sensor deployment