The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor-Manager Connectivity Issues

Prev Next

Scenario

Connectivity issues between the Sensor and Manager

Applicable to Sensor models: NS-series and Virtual IPS Sensors

Sensor software versions: 10.1, 11.1

Problems type to be solved

Sensor is not detected on the Manager.

Trust establishment does not happen between the Sensor and Manager.

Data/Information Collection

Steps:

  1. Execute the following commands on the Sensor:

    • status

    • show

    • show sbcfg

    • show mgmtcfg

    • show doscfg

    • show mgmtport

    • getccstats

    • show netstat

    • checkmanagerconnectivity

  2. Collect the Manager infocollector logs. If possible, perform the following:

    For Windows-based Manager, enable detailed debugging messages by modifying <Manager_Install_Dir>\config\log4j2.xml file.

    Note

    The default Manager installation directory is %programfiles%\Trellix\IPS Manager\App.

    For Linux-based Manager, enable detailed debugging messages by modifying log4j2.xml file. To open the file, execute edit log4j2.xml.

    Find out and modify the following lines in the log4j2.xml file:

    • <Logger name="iv.core.DiscoveryService" additivity="false" level="debug">
                  <appender-ref ref="DEVICE_CONFIG_LOG"/>
              </Logger>
    • <Logger name="iv.core.SensorConfiguration" additivity="false" level="debug">
                  <appender-ref ref="DEVICE_CONFIG_LOG"/>
              </Logger>

    The modified logs will be available in <Manager_Install_Dir>\logs\device_config.log file.

  3. Collect the Sensor trace files.

  4. Collect packet capture at the Manager (for the problematic Sensor).

  5. Network diagrams clearly mentioning where the Sensor and Manager are located.

Troubleshooting Steps

  1. Check if there is any network connectivity issue such as conflicting IP address of the Sensor. This can result in alert/pktlog channel flaps.

  2. Verify that the Management Interface speed and duplex settings are configured correctly on the Manager and Sensor and that they are hard-coded. If this fails, change one link to auto and change the other side's duplex and speed settings until communications are established or combinations are exhausted.

  3. Ping from the Sensor to Manager and Manager to Sensor, and make sure the ping is successful.

  4. Check if the other Sensors connected to the same Manager are also facing this issue.

    If yes, it is a Manager issue.

  5. Check the IP address of the system on which the Manager is installed. Make sure the correct IP address is provided in the set manager ip command at Sensor CLI.

  6. Try a deinstall and establish the trust again with the Manager.

  7. Check if the Manager machine has multiple NIC cards. If yes, do the following:

    • For Windows-based Manager, open <Manager_Install_Dir>\bin\tms.bat file.

    • For Linux-based Manager, open tms.sh file. To open the file, execute edit tms.sh.

    Later, modify the following line to assign the relevant IP address that is also used in the Sensor configuration: set JAVA_OPTS=%JAVA_OPTS% -Dlumos.fixedManagerSNMPIPaddress=""restart Manager

  8. Check the Sensor name, which is given on the Manager while adding the Sensor using the Add New Device wizard. Sensor name is case-sensitive. So make sure it exactly matches the one given on the Manager.

  9. Check that the device type is selected as IPS Sensor while adding the Sensor using Add New Device. Selecting incorrect device type can also lead to connectivity issues.

  10. Make sure that firewall is not blocking traffic between the Manager and Sensor for the following ports:

    Manager:4167 -> Sensor:8500 (UDP)

    Sensor:Any -> Manager:8501-8504,8510 (TCP) for 1024-bit trusts

    Sensor:Any -> Manager:8504,8506-8509 (TCP) for 2048-bit trusts

  11. If using the malware policy, check if the file save option is enabled. Make sure firewall is not blocking ports 8509 and 8510, which are used for saving malware files.

  12. Check that UDP port 8500 is open and allows the Manager to Sensor SNMP communication.

  13. Use the netstat -na command to verify that ports 8501 - ,8505 are listening on the Manager. Click Start → Run type cmd, press Enter, then type netstat -na at the command prompt.

  14. Make sure large UDP and/or fragmented UDP packets are not dropped between the Sensor and Manager communication. This can lead to SNMP timeout. Look for the following logs in ems.log:

    Ems log

    ******

    014-06-27 15:47:29,150 INFO [Thread-135] iv.core.SensorConfiguration - M1450 Experience a SNMP error during set/get, Change the STATUS to DISCCONECTED

    2014-06-27 15:47:29,163 ERROR [Thread-135] iv.core.SensorConfiguration - Fail to process SNMP return node:

    com.intruvert.ext.sensorconfig.leap.SensorConfigException: Time Out

  15. Capture UDP traffic using Wireshark on the Manager. Check if the Manager is receiving UDP response packets from the Sensor.

    Sample capture on the Manager:

    GUID-5C8DEC19-417F-403E-8E65-5ABA210E1B2A-low.png
  16. Check the time on the Sensor, and if it matches with the Manager system time.

  17. Check if there are any Out Of Memory related logs in the Manager. This can lead to connectivity issues between the Sensor and Manager.

  18. Check if the Manager is an MDR pair. If yes, verify that the IP of primary Manager in the sensor matches the IP of the active Manager. Also check whether the Sensor is treating the standby Manager as the primary Manager. This might lead to connectivity issues.

    If the problem still persists, contact Trellix Support for further assistance.