The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Scenario 4: High-level steps for Virtual Sensor deployment

Prev Next

This section assumes the following for deploying the Virtual Sensor for scenario 4.

  • The ESX server meets the requirements as discussed in Requirements for deploying the Virtual Sensor.

  • You have the privileges on the ESX server to add and modify vSwitches and port groups.

  • You have installed the Virtual Sensor and established trust with the Manager successfully. As an example in this scenario, the management port is connected to vSwitch2.

  • As an example, this section uses the IPS-VM5000 Virtual Sensor to explain the deployment.

  • This scenario involves only a Sensor monitoring port pair deployed in inline fail-closed mode.

  • This section uses only the vSphere Client for configurations on the ESX.

Steps:

  1. Connect the trunk port of Physical switch 1 and Physical switch 2 to two different physical NICs on the ESX.

  2. Create two standard vSwitches for connecting Sensor monitoring ports 1 and 2.

    Refer to the section Create a standard vSwitch for a monitoring port. Both these switches need physical adapters. For this scenario, vSwitch0 must be assigned a physical adapter that is connected to Physical switch 1. Similarly, vSwitch1 must be assigned to a physical adapter that is connected to Physical switch 2.

  3. Create a switch port group in vSwitch0, which corresponds to the trunk port on Physical switch 1.

    1. Log on to the ESX as the root user in VMware vSphere Web Client. GUID-ED003931-0EA0-43A9-889D-8C1D10FE78FE-low.png

    2. Select the required ESX server and select Configure → Networking → Virtual switches → vSwitch0.GUID-EFF4167D-2437-4338-AD0F-88BB19DB084F-low.png

    3. Click ADD NETWORKING tab for vSwitch0.

    4. In the Select connection type section, select Virtual Machine Port Group for a Standard Switch. GUID-732DC670-B254-4029-8112-78F8CF43F4D8-low.png

    5. In the Select target device section, select Select an existing standard switch and make sure vSwitch0 is selected. GUID-9B1CCC58-B150-49E1-9A03-76946B3BF73E-low.png

    6. In the Connection settings section, enter a name in the Network Label field.

      For example, enter Physical Client Port.

    7. In the VLAN ID (Optional) field, select All (4095) because this switch port group corresponds to the trunk port of a physical switch. GUID-353CE53E-47B8-47A6-B6AB-98FC0D95C321-low.png

    8. Click NEXT and then, click FINISH.

    9. Under Standard switch: vSwitch0 (VM Network), click the ellipsis icon next to the switch port group that you created and click Edit Settings.

      In this example, it is Physical Client Port.

      GUID-0F410B03-C1B4-42D8-AC1F-68C19E8A3B5C-low.png
    10. In the Edit Settings wizard, go to the Security section, make sure the fields are set with the following values and click OK.

      • Promiscuous mode — Accept. This is set to accept because traffic related to all the hosts connected to Physical switch 1 is involved.

      • MAC address changes — Accept

      • Forged transmits — Accept

        Note

        Select the Override check-box to be able to change the state of an option.

      GUID-A527EE98-A07D-46F1-81CE-0401DB527D0F-low.png
  4. Use the previous step to create a similar switch port group in vSwitch1.

    This corresponds to the trunk port on Physical switch 2.

  5. Assign the switch port group that you created in step 3 to monitoring port 1.

    See the section Specify the switch port groups for monitoring ports.

  6. Assign the switch port group that you created in step 4 to monitoring port 2.

    See the section Specify the switch port groups for monitoring ports.

    Make sure the monitoring port 1 is connected to the corresponding port group (VIPS5000-PG-Port1) on vSwitch0 and the monitoring port 2 is connected to the corresponding port group (VIPS5000-PG-Port2) on vSwitch1. Both these port groups must have their VLAN ID as All (4095). This is required since the monitoring ports are connected to trunk ports of the physical switches.

  7. Verify if you have deployed the Virtual Sensor correctly and whether it is inspecting traffic.

    Refer to the section Verify the deployment.