The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor critical faults

Prev Next

These are the critical faults for a Sensor device.

Fault

Severity

Description/Cause

Action

Temperature Error

Critical

Device temperature is outside its normal range.

Check the fan LEDs to ensure all internal fans are functioning and contact Trellix Technical Support if it persists.

Fan Error

Critical

{0} is {1}. The fan has failed.

Check the fan LEDs to confirm fan status. Switch off the device and contact Trellix Technical Support.

Power Supply Error

Critical

The {0} power supply to the device {1}

Confirm that the power supply is connected to a working outlet. If the outlet is working, replace the power supply.

Link Error on {0}

Critical

The link on {0} is {1}

Confirm that the device to which this port is connected is online and the cable connecting them is secure. If this port is not actually being used, disable it on the Physical Ports page.

Generic Memory Error

Critical

A generic, memory-related error has been detected.

A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.

Generic Hardware Error

Critical

A generic, hardware-related error has been detected.

A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.

Device Software Error

Critical

A recoverable software error has occurred within the device.

A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.

GAM Engine Process Failure

Critical

Device {0} has detected a failure in the GAM engine process, which may impact GAM file analysis.

Run the "status" CLI command.

If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured).

Malware Server Process Failure

Critical

Device {0} has detected a failure in the malware server process, which may impact all advanced malware file analysis.

Run the "status" CLI command.

If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured).

Datapath Process Failure

Critical

Device {0} has detected a failure in the datapath process, which may impact datapath inspection.

Run the "status" CLI command.

If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured).

GTI Engine Process Failure

Critical

Device {0} has detected a failure in the GTI file reputation lookup process, which may impact GTI file analysis.

Run the "status" CLI command.

If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured).

Frontend Datapath Process Failure

Critical

Device {0} has detected a failure in the frontend datapath process, which may impact datapath inspection.

Run the "status" CLI command.

If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured).

Packet Buffer Overflow

Critical

A packet buffer overflow has been detected.

A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.

Generic Error

Critical

A generic error has been detected

A device reboot may resolve the issue. Check device logs for additional details and contact Trellix Technical Support if it persists.

Firewall Connectivity Failure

Critical

The connectivity between the device and the firewall is down.

This fault can occur in situations where, for example, the firewall machine is down or the network is experiencing problems. Ping the firewall to see if the firewall is available. Contact your IT department to troubleshoot connectivity issues.

Late Collision of {0}

Critical

The link on {0} detects {1}.

Check both, the device and the one to which it is connected for compatible ethernet settings.

Port Pair {0} in Bypass Mode

Critical

Device {0} is configured in in-line, fail-open mode, but it is in bypass mode. The port pair is not inspecting traffic.

Confirm that the port is connected properly and operational. Additionally disable and re-enable the port. Check if the traffic rate is above the supported port throughput (this forces the device into bypass mode).

Port Pair {0} in In-Line, Fail-Open Mode

Critical

{0} has returned from bypass mode to in-line, fail-open mode.

Confirm if the traffic statistics are incrementing and traffic is being inspected.

Fail-Open Bypass Switch Timeout

Critical

The device is not able to communicate with the fail-open bypass switch.

Run the CLI command "show intfport all" to confirm connectivity. If disconnected, disable and re-enable the port.

Invalid Fail-Open Configuration: {0}

Critical

An invalid configuration has been applied to {0} (The device requires appropriate hardware to support in-line, fail-open configuration on its gigabit ports).

Ensure that hardware is available and correct ports are configured to run in in-line mode.

Inspection Disabled

Critical

The device is operating in layer 2 bypass mode. Inspection is disabled. The device has either been explicitly placed into bypass mode via the CLI/GUI, or it has experienced multiple errors, surpassing the configured threshold, and switched to bypass mode as a precaution.

Check for faults and the device status. Use the "layer2 mode deassert" CLI command to re-enable inspection. On GUI, Navigate to Device → Troubleshooting → Layer 2 Bypass & Update layer 2 mode to Deassert.

Invalid SSL Decryption Certificate

Critical

The device has detected an invalid SSL decryption certificate: {0}

Re-import the SSL decryption certificate.

Generic Device Error

Critical

{0}

Review the device status.

Port Media Type Mismatch

Critical

{0}: Configured media type is {1}. Inserted media type is {2}

Ensure the configured media type matches with the media inserted.

Port Certification Mismatch

Critical

{0}: Trellix Certified pluggable interface. Trellix certification status is {1}.

Replace the non-certified transceiver with a Trellix-certified one or update the physical port's settings to allow a non-certified connector type.

Temperature Status

Critical

{0} temperature is {1}.

Bootloader Upgrade Failure

Critical

Bootloader upgrade status is {1}.

Temperature Error

Critical

Chassis temperature (device index {0}) is {1}.

Check the Fan LEDs to ensure all internal chassis fans are functioning and contact Trellix Technical Support if the problem persists.

Device Dropping Packets Internally

Critical

Device front end is overloaded.

If this problem is an ongoing occurrence, a model with a higher system capacity should be considered. (Tip: Multiple capacities are supported on some models with a license change to increase the capacity)

Device Dropping Packets Internally

Critical

Device capacity has been reached.

If this problem is an ongoing occurrence, a model with a higher system capacity should be considered. (Tip: Multiple capacities are supported on some models with a license change to increase the capacity)

Incompatible Device Model Detected

Critical

Device {0} has been replaced by a model ({2}) that is not the same as the original model. The alert channel cannot establish a connection.

Ensure you replace the device with another device of the same model.

Device Disconnected

Critical

The Manager cannot communicate with the device {0} through its command channel. The connection between the device and the Manager is down.

Check the device status using the "status" CLI command. Make sure the device can ping its default gateway and the Manager. Make sure any firewalls between the devices have the proper ports open.

Load Balancer Disconnected

Critical

The Manager cannot communicate with load balancer {0} through its command channel. The connection between the load balancer and the Manager is down.

Check load balancer status. Make sure the load balancer can ping its default gateway and the Manager. Make sure any firewall between the devices and the Manager have proper ports open.

Device in Bad Health

Critical

Device {0} is reporting bad health. This fault occurs due to device software failure. (It usually occurs in conjunction with a software error fault.)

If this fault persists, refer the system log and contact Trellix Technical Support.

Uninitialized Device

Critical

Device {0} is not initialized properly and is therefore not passing traffic. If the device is newly added, this is expected until it receives its initial configuration from the Manager.

If this is a new device, it will start passing traffic once it receives its initial configuration from the Manager, once it establishes trust with it. If the device has rebooted, it normally auto recovers once the device has finished its boot process. If the problem persists, check the device status using the "status" CLI command to ensure that a signature set is present. If no signature set is available, re-deploy the settings from the Manager.

Trellix Intelligent Sandbox Certificate Deployment Failure

Critical

Deployment of the Trellix Intelligent Sandbox certificate to the device {0} by the Manager failed. This could be due to a network connectivity issue.

If the problem persists, consult the system log for details.

Device Discovered without License

Critical

Device {0} was discovered without a license.

Add a license.

Device Discovered with Cluster Secondary License

Critical

Device {0} was discovered with a cluster secondary license. This device should not be connected to the Manager directly.

To obtain a standard license now, please contact Technical Support or your local reseller.

Device License Expired

Critical

Device {0} ({1}) license expired.

Add a license.

Device Support License Expired

Critical

Device {0} (support {1}) license expired.

Add a license.

Expired Device License

Critical

Device {0} ({1}) license expired.

Add a license.

Expired Device Support License

Critical

Device {0} (support {1}) license expired.

Add a license.

No Valid License Detected for {0} of Type {1}

Critical

A license is required.

Add a license.

Pending Support License Expiration for {0} of Type {1}

Critical

Support license for this device expires in {0} days.

Renew the license.

Expired License for {0} of Type {1}

Critical

A license is required.

Add a license.

Expired Support License for {0} of Type {1}

Critical

A license is required.

Add a license.

Insufficient Licenses Detected

Critical

The Manager does not have enough licenses to support the number of Trellix Virtual IPS sensors and/or Virtual Probes it is currently managing. Additional licenses are required to become compliant. Virtual Sensors: {0} in use ({1} allowed) Additional Virtual Sensor Licenses Required: {2}

Add enough licenses to become compliant.

Expired License

Critical

Proxy Decryption License with key {0} has expired. Updates to the Sensor to which it is assigned will be prevented until a valid license is assigned. License details - Model:{1}, Capacity:{2}, Required Devices:{3}, Grant ID:{4}, Customer Name:{5}, Expiration:{6}, Assigned To:{7}

Replace the expired license with a valid one.

Expired License

Critical

The system license with key {0} has expired and 30 days passed beyond expiry. Updates to the Sensor to which it is assigned will be prevented until a valid license is assigned. License details - Model:{1}, Capacity:{2}, Required Devices:{3}, Grant ID:{4}, Customer Name:{5}, Expiration:{6}, Assigned To:{7}

Replace the expired license with a valid one.

Expired License

Critical

The system license with key {0} has expired. Post 30 days from expiry, Updates to the Sensor to which it is assigned will be prevented until a valid license is assigned. License details - Model:{1}, Capacity:{2}, Required Devices:{3}, Grant ID:{4}, Customer Name:{5}, Expiration:{6}, Assigned To:{7}

Replace the expired license with a valid one.

Expired License

Critical

The evaluation system license with key {0} has expired. Updates to the Sensor to which it is assigned will be prevented until a valid license is assigned. License details - Model:{1}, Capacity:{2}, Required Devices:{3}, Grant ID:{4}, Customer Name:{5}, Expiration:{6}, Assigned To:{7}

Replace the expired license with a valid one.

GTI File Reputation DNS Error

Critical

{1}.

Confirm that the device has name resolution enabled, and properly configured, and that it can communicate with the configured DNS servers.

Port Pair {0} Fail-Open Kit Status

Critical

Device {0} is configured to run in-line and to fail open, but it is in {1} mode. This fault indicates that some failure has occurred, causing the fail-open control module to switch operation to {1} Mode. No traffic is flowing through the device.

Consult the system log for details. If the problem persists, remove and re-add the fail-open kit.

CLI Login After Device Initialization

Critical

Device reports user "{0}" login via CLI after device initialization. This is a FIPS 140-2 Level 3 violation.

Link Error on {1}

Critical

The link on port {1} is {2}

Confirm that the device to which this port is connected is online and the cable connecting them is secure. If this port is not actually being used, disable it on the Physical Ports page.

Load Balancer HA Configuration Mismatch

Critical

Load Balancer "{0}" reports HA peer configuration is not matching.

Verify the load balancer configuration and recreate the HA Pair if needed. (Both load balancers in the HA Pair are expected to have the same configuration.)

FFP File Update Error

Critical

Failed to send FFP file update to device.

Check sensor connectivity and consult the device system logs for details.

Device Reboot Required

Critical

The device requires a manual reboot due to "{1}".

Reboot the device.

Solid State Drive ({0}) Error

Critical

The Solid State Drive {0} is "{1}". Restore the SSD to clear this fault.

Check the SSD status. On failure, replace the failed SSD.

GTI Connectivity Error

Critical

The device is {1} to communicate with GTI server.

Confirm device connectivity and name resolution.

Trellix Intelligent Sandbox Connectivity Error

Critical

The device is {0} to communicate with the Trellix Intelligent Sandbox appliance due to {1}.

Confirm connectivity between the devices, port, and credentials used to send Intelligent Sandbox files.

Attack Detection Error

Critical

IPS device attack detection has stopped on one or more engine.

Consult the device system logs for details. A reboot may be required to resolve the issue.

Invalid Device Trust Certificate Detected

Critical

Device {0} tried to establish trust with the Manager using an invalid CA-signed certificate. Validation error: {1}.

Replace the invalid certificate with a valid one.

Device CSR File Generation Error

Critical

An error occurred while the device {0} was attempting to upload the CSR file to the Manager. (The CSR file is used to create a CA-signed certificate, which is in turn used by the device to establish trust with the Manager)

The use of special characters when creating the CSR may lead to an error. If using special characters, try to generate the CSR again without them. Otherwise, consult the system log for details.

Device Trust Certificate Deployment Error

Critical

An error occurred while attempting to deploy a CA-signed certificate to device {0}. (The CA-signed certificate is used by the device to establish trust with the Manager)

Check the connectivity between the Manager and the device, and then consult their system logs for details.

Internal Configuration Error

Critical

Unsupported configuration detected after upgrade/downgrade. The device is restored to default configuration.

An internal application communication error occurred in the device during {0}.

Unsupported Callback Detectors configuration detected after upgrade/downgrade. The device is restored to default configuration.

Image downgrade detected. Execute "resetconfig" on the device CLI to complete the downgrade.

This is an internal error. Check the device status to ensure the device is connected to the Manager and in good health.

NI Connectivity from Sensor Failed

Critical

Connectivity to NI server from Sensor {0} failed.

Please check authorization token input is correct.

NI Connectivity from Sensor Failed

Critical

Connectivity to NI server from Sensor {0} failed.

Please check network connection and reachability of NI server from Trellix IPS Manager.