The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Scenario 2: High-level steps for Virtual Sensor deployment

Prev Next

This section assumes the following for deploying the Virtual Sensor for scenario 2.

  • The ESX server meets the requirements as discussed in Requirements for deploying the Virtual Sensor.

  • You have the privileges on the ESX server to add and modify vSwitches and port groups.

  • You have installed the Virtual Sensor and established trust with the Manager successfully. As an example in this scenario, the management port is connected to vSwitch2.

  • As an example, this section uses the IPS-VM5000 Virtual Sensor to explain the deployment.

  • This scenario involves only a Sensor monitoring port pair deployed in inline fail-closed mode.

  • This section uses only the vSphere Client for configurations on the ESX.

Steps:

  1. Create vSwitch1 for connecting Sensor monitoring port 2 and the 10.10.10.16 server.

    Refer to Create a standard vSwitch for a monitoring port.

  2. Modify vSwitch0 to connect monitoring port 1.

    Refer to Modify an existing standard vSwitch for a monitoring port.

  3. Assign the corresponding switch port group (promiscuous mode) that you created in step 1 to monitoring port 2.

    See Specify the switch port groups for monitoring ports.

  4. Change the switch port group for the 10.10.10.16 server such that it is now connected to vSwitch1.

  5. Assign the corresponding switch port group (promiscuous mode) that you created in step 2 to monitoring port 1.

    See Specify the switch port groups for monitoring ports.

  6. Verify if you have deployed the Virtual Sensor correctly and whether it is inspecting traffic.

    Refer to Verify the deployment.