The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor critical faults

Prev Next

These are the critical faults for a Sensor device.

Fault Severity Description/Cause Action
Temperature Error Critical Device temperature is outside its normal range. Check the cooling of your server room. Ensure there are no fan failures. Ensure the air used to cool the system is within the thermal specifications for the system (typically below 35°C).
Link Error on {0} Critical The link on {0} is {1} Confirm that the device to which this port is connected is online and the cable connecting them is secure. If this port is not actually being used, disable it on the Physical Ports page.
Generic Memory Error Critical A generic, memory-related error has been detected. A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.
Packet Buffer Overflow Critical A packet buffer overflow has been detected. A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.
Generic Error Critical A generic error has been detected A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.
Firewall Connectivity Failure Critical The connectivity between the device and the firewall is down. This fault can occur in situations where, for example, the firewall machine is down or the network is experiencing problems. Ping the firewall to see if the firewall is available. Contact your IT department to troubleshoot connectivity issues.
Late Collision of {0} Critical The link on {0} detects {1}. Check both, the device and the one to which it is connected for compatible ethernet settings.
Port Pair {0} in Bypass Mode Critical Device {0} is configured in in-line, fail-open mode, but it is in bypass mode. The port pair is not inspecting traffic. Confirm that the port is connected properly and operational. Additionaly disable and re-enable the port. Check if the traffic rate is above the supported port throughput (this forces the device into bypass mode).
Port Pair {0} in In-Line, Fail-Open Mode Critical {0} has returned from bypass mode to in-line, fail-open mode. Confirm if the traffic statistics are incrementing and traffic is being inspected.
Fail-Open Bypass Switch Timeout Critical The device is not able to communicate with the fail-open bypass switch. Run the CLI command "show intfport all" to confirm connectivity. If disconnected, disable and re-enable the port.
Invalid Fail-Open Configuration: {0} Critical An invalid configuration has been applied to {0} (The device requires appropriate hardware to support in-line, fail-open configuration on its gigabit ports). Ensure that hardware is available and correct ports are configured to run in in-line mode.
Inspection Disabled Critical The device is operating in layer 2 bypass mode. Inspection is disabled. The device has either been explicitly placed into bypass mode via the CLI, or it has experienced multiple errors, surpassing the configured threshold, and switched to bypass mode as a precaution. Check for faults and the device status. Use the "layer2 mode deassert" CLI command to re-enable inspection.
Invalid SSL Decryption Certificate Critical The device has detected an invalid SSL decryption certificate: {0} Re-import the SSL decryption certificate.
Generic Device Error Critical {0} Review the device status.
Port Media Type Mismatch Critical {0}: Configured media type is {1}. Inserted media type is {2} Ensure the configured media type matches with the media inserted.
Port Certification Mismatch Critical {0}: Trellix Certified pluggable interface. Trellix certification status is {1}. Replace the non-certified transceiver with a Trellix-certified one or update the physical port's settings to allow a non-certified connector type.
Temperature Status Critical {0} temperature is {1}.
Bootloader Upgrade Failure Critical Bootloader upgrade status is {1}.
Temperature Error Critical Chassis temperature (device index {0}) is {1}. Check the Fan LEDs to ensure all internal chassis fans are functioning and contact Trellix Technical Support if the problem persists.
Device Dropping Packets Internally Critical Device front end is overloaded. If this problem is an ongoing occurrence, a model with a higher system capacity should be considered. (Tip: Multiple capacities are supported on some models with a license change to increase the capacity)
Device Dropping Packets Internally Critical Device capacity has been reached. If this problem is an ongoing occurrence, a model with a higher system capacity should be considered. (Tip: Multiple capacities are supported on some models with a license change to increase the capacity)
Incompatible Device Model Detected Critical Device {0} has been replaced by a model ({2}) that is not the same as the original model. The alert channel cannot establish a connection. Ensure you replace the device with another device of the same model.
Device Disconnected Critical The Manager cannot communicate with the device {0} through its command channel. The connection between the device and the Manager is down. Check the device status using the "status" CLI command. Make sure the device can ping its default gateway and the Manager. Make sure any firewalls between the devices have the proper ports open.
Load Balancer Disconnected Critical The Manager cannot communicate with load balancer {0} through its command channel. The connection between the load balancer and the Manager is down. Check load balancer status. Make sure the load balancer can ping its default gateway and the Manager. Make sure any firewall between the devices and the Manager have proper ports open.
Device in Bad Health Critical Device {0} is reporting bad health. This fault occurs due to device software failure. (It usually occurs in conjunction with a software error fault.) If this fault persists, refer the system log and contact Trellix Technical Support.
Uninitialized Device Critical Device {0} is not initialized properly and is therefore not passing traffic. If the device is newly added, this is expected until it receives its initial configuration from the Manager. If this is a new device, it will start passing traffic once it receives its initial configuration from the Manager, once it establishes trust with it. If the device has rebooted, it normally auto recovers once the device has finished its boot process. If the problem persists, check the device status using the "status" CLI command to ensure that a signature set is present. If no signature set is available, re-deploy the settings from the Manager.
Trellix Intelligent Sandbox Certificate Deployment Failure Critical Deployment of the Trellix Intelligent Sandbox certificate to the device {0} by the Manager failed. This could be due to a network connectivity issue. If the problem persists, consult the system log for details.
Device Discovered without License Critical Device {0} was discovered without a license. Add a license.
Device Discovered with Cluster Secondary License Critical Device {0} was discovered with a cluster secondary license. This device should not be connected to the Manager directly. To obtain a standard license now, please contact Technical Support or your local reseller.
Device License Expired Critical Device {0} ({1}) license expired. Add a license.
Device Support License Expired Critical Device {0} (support {1}) license expired. Add a license.
Expired Device License Critical Device {0} ({1}) license expired. Add a license.
Expired Device Support License Critical Device {0} (support {1}) license expired. Add a license.
No Valid License Detected for {0} of Type {1} Critical A license is required. Add a license.
Pending Support License Expiration for {0} of Type {1} Critical Support license for this device expires in {0} days. Renew the license.
Expired License for {0} of Type {1} Critical A license is required. Add a license.
Expired Support License for {0} of Type {1} Critical A license is required. Add a license.
Expired License for {0} of Type {1} Critical A license is required. Add a license.
Expired Support License for {0} of Type {1} Critical A license is required. Add a license.
Insufficient Licenses Detected Critical The Manager does not have enough licenses to support the number of Trellix Virtual IPS sensors and/or Virtual Probes it is currently managing. Additional licenses are required to become compliant. Virtual Sensors: {0} in use ({1} allowed) Additional Virtual Sensor Licenses Required: {2} Add enough licenses to become compliant.
Expired License Critical Proxy Decryption License with key {0} has expired. Updates to the Sensor to which it is assigned will be prevented until a valid license is assigned. License details - Model:{1}, Capacity:{2}, Required Devices:{3}, Grant ID:{4}, Customer Name:{5}, Expiration:{6}, Assigned To:{7} Replace the expired license with a valid one.
Expired License Critical The system license with key {0} has expired. Updates to the Sensor to which it is assigned will be prevented until a valid license is assigned. License details - Model:{1}, Capacity:{2}, Required Devices:{3}, Grant ID:{4}, Customer Name:{5}, Expiration:{6}, Assigned To:{7} Replace the expired license with a valid one.
GTI File Reputation DNS Error Critical {1}. Confirm that the device has name resolution enabled, and properly configured, and that it can communicate with the configured DNS servers.
Port Pair {0} Fail-Open Kit Status Critical Device {0} is configured to run in-line and to fail open, but it is in {1} mode. This fault indicates that some failure has occurred, causing the fail-open control module to switch operation to {1} Mode. No traffic is flowing through the device. Consult the system log for details. If the problem persists, remove and re-add the fail-open kit.
CLI Login After Device Initialization Critical Device reports user "{0}" login via CLI after device initialization. This is a FIPS 140-2 Level 3 violation.
Link Error on {1} Critical The link on port {1} is {2} Confirm that the device to which this port is connected is online and the cable connecting them is secure. If this port is not actually being used, disable it on the Physical Ports page.
Load Balancer HA Configuration Mismatch Critical Load Balancer "{0}" reports HA peer configuration is not matching. Verify the load balancer configuration and recreate the HA Pair if needed. (Both load balancers in the HA Pair are expected to have the same configuration.)
FFP File Update Error Critical Failed to send FFP file update to device. Check sensor connectivity and consult the device system logs for details.
Device Reboot Required Critical The device requires a manual reboot due to "{1}". Reboot the device.
Solid State Drive ({0}) Error Critical The Solid State Drive {0} is "{1}". Restore the SSD to clear this fault. Check the SSD status. On failure, replace the failed SSD.
GTI Connectivity Error Critical The device is {1} to communicate with GTI server. Confirm device connectivity and name resolution.
Trellix Intelligent Sandbox Connectivity Error Critical The device is {0} to communicate with the Trellix Intelligent Sandbox appliance due to {1}. Confirm connectivity between the devices, port, and credentials used to send Intelligent Sandbox files.
Attack Detection Error Critical IPS device attack detection has stopped on one or more engine. Consult the device system logs for details. A reboot may be required to resolve the issue.
Invalid Device Trust Certificate Detected Critical Device {0} tried to establish trust with the Manager using an invalid CA-signed certificate. Validation error: {1}. Replace the invalid certificate with a valid one.
Sensor CSR File Generation Error Critical An error occurred while Sensor {0} was attempting to upload its CSR file to the Manager. (The CSR file is used to create a CA-signed certificate, which is in turn used by the Sensor to establish its trust with the Manager.) The use of special characters when creating the CSR may lead to an error. If using special characters, try the CSR again without them. Otherwise, consult the system log for details.
Sensor Trust Certificate Deployment Error Critical An error occurred while attempting to deploy a CA-signed certificate to Sensor {0}. (The CA-signed certificate is used by the Sensor to establish its trust with the Manager.) Check the connectivity between the Manager and the Sensor and consult their system logs for details.
Internal Configuration Error Critical Unsupported configuration detected after upgrade/downgrade. The device is restored to default configuration.

An internal application communication error occurred in the device during {0}.

Unsupported Callback Detectors configuration detected after upgrade/downgrade. The device is restored to default configuration.

Image downgrade detected. Execute "resetconfig" on the device CLI to complete the downgrade.

This is an internal error. Check the device status to ensure the device is connected to the Manager and in good health.