The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Scenario 3: High-level steps for Virtual Sensor deployment

Prev Next

This section assumes the following for deploying the Virtual Sensor for scenario 3.

  • The ESX server meets the requirements as discussed in Requirements for deploying the Virtual Sensor.

  • You have the privileges on the ESX server to add and modify vSwitches and port groups.

  • You have installed the Virtual Sensor and established trust with the Manager successfully. As an example in this scenario, the management port is connected to vSwitch2.

  • As an example, this section uses the IPS-VM5000 Virtual Sensor to explain the deployment.

  • This scenario involves only a Sensor monitoring port pair deployed in inline fail-closed mode.

  • This section uses only the vSphere Client for configurations on the ESX.

Steps:

  1. Create a standard vSwitch for connecting Sensor monitoring port 2 with the external network through vmnic0. For this scenario, consider it is vSwitch1.

    Refer to the section Create a standard vSwitch for a monitoring port.

    Make sure this vSwitch has a physical adapter and that this is connected to the corresponding external switch.

  2. Modify vSwitch0 to connect monitoring port 1 and the virtual servers.

    For this scenario, you need not change the switch port group for the virtual servers. Create a new switch port group for monitoring port 1. Refer to the section Modify an existing standard vSwitch for a monitoring port.

  3. Assign the corresponding switch port group (promiscuous mode) to the monitoring ports.

    See the section Specify the switch port groups for monitoring ports.

    • The switch port group that you created in step 1 (vSwitch1) must be assigned to monitoring port 2.

    • The switch port group that you created in step 2 (vSwitch0) must be assigned to monitoring port 1.

  4. Verify if you have deployed the Virtual Sensor correctly and whether it is inspecting traffic.

    Refer to the section Verify the deployment.