The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor software upgrade requirements

Prev Next

This section details the requirements to upgrade the Sensor software to 10.1. In this section, the term   Sensor refers to NS-series and Virtual IPS Sensors unless otherwise specified.

License file requirement  

The NS9500, NS7500, and NS3500 Sensors require a system license (Manager → <Admin Domain Name> → Setup → Licenses) to activate the baseline throughput of 10 Gbps on NS9500 Sensors, 3 Gbps on NS7500, and 750 Mbps on NS3500 Sensors. In case of standalone NS9500, additional system license or an upgrade system license is required to increase the throughput from 10 Gbps to 20 Gbps or 30 Gbps. In case of NS9500 Sensor stack, additional system license or an upgrade system license is required to increase the throughput to 40 Gbps, 60 Gbps, or 100 Gbps. In case of NS7500, additional system license or an upgrade system license is required to increase the throughput from 3 Gbps to 5 Gbps or 7.5 Gbps. The system license is provided as a .zip or .jar file. The Manager supports both formats. The system license procured contains the details of the throughput for the Sensors.  

Note

Other physical appliances do not require system licenses.  

For more information, see   Managing licenses for NS9500, NS7500, and NS3500 Sensors.  

The NS9500 (Standalone), NS9200, NS9100, NS7500, NS7300, and NS7200 Sensors require an outbound proxy-based SSL license. The NS9500 (Standalone) and NS7500 Sensors require an inbound proxy-based SSL license (Manager → <Admin Domain Name> → Setup → Licenses). The SSL decryption feature can be enabled now even before adding the proxy-based SSL license to the Manager. Upon license expiration, the SSL decryption feature is not disabled automatically. But configuration updates to the Sensor will not be possible until a new proxy-based SSL license is assigned to the Sensor. Configuration updates like signature set update and policy update are disabled when an invalid license is assigned to the Sensor.  

Note

You must first purchase a license to enable outbound and inbound SSL decryption feature. To obtain a demo license for outbound and inbound SSL decryption, contact MB Licensing. An email containing the license will be sent from MB Licensing. If you are a first-time user, you must register with your email ID and Grant number to log in to the portal. In the Service Portal, click   Patches and Downloads to register and log in to the portal.  

For more information, see   Managing licenses for proxy based SSL decryption.  

Prerequisites for Sensor software upgrade  

Caution

Starting with release 10.1.7.50, the Manager software version supports only TLS 1.2 ciphers for Manager and Sensor communication.  

Caution

If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 10.1.7.50 or later, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 10.1.7.50 or later versions. Post this, you can upgrade the Sensor to 10.1.5.190  

For example, if you have a NS9500 Sensor running on software version 9.2.5.52 (TLS 1.0) and Manager software version 10.1.7.44, and you plan to upgrade the Sensor to 10.1.5.190 and Manager to 10.1.7.65, you must follow the upgrade path as listed below:  

  1. Upgrade your NS9500 Sensor from 9.2.5.52 (Supports TLS 1.0) to 10.1.5.107 (Supports TLS 1.2).  

  2. Upgrade the Manager from 10.1.7.44 to 10.1.7.65  

  3. Upgrade the Sensor from 10.1.5.107 to 10.1.5.190  

Similarly, if you have a NS9300 Sensor running on software version 9.2.5.72 (TLS 1.0) and Manager software version 10.1.7.44, you must follow the upgrade path as listed below:  

  1. Upgrade your NS9300 Sensor from 9.2.5.72 (Supports TLS 1.0) to 9.2.5.190 or 10.1.5.106 (Supports TLS 1.2).  

  2. Upgrade the Manager from 10.1.7.44 to 10.1.7.65.  

  3. Upgrade the Sensor from 9.2.5.190 or 10.1.5.106 to 10.1.5.190.  

  Upgrade paths for NS-series Sensor software versions  

Sensor models  

Version  

TLS support  

Upgrade path to 10.1  

NS9500 (Standalone)  

9.2.5.50, 9.2.5.52, 9.2.5.88, 9.2.5.91  

TLS 1.0  

10.1.5.107 | 10.1.5.190  

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170  

TLS 1.2  

10.1.5.190  

NS9500 (Stack)  

9.2.5.88, 9.2.5.91  

TLS 1.0  

10.1.5.107 | 10.1.5.190  

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170  

TLS 1.2  

10.1.5.190  

NS-series (NS9300, NS9200, NS9100, NS7300, NS7200, NS7100, NS5200, NS5100, NS3200, NS3100)  

9.1.5.9, 9.1.5.20, 9.1.5.23  

TLS 1.2  

9.1.5.102 | 10.1.5.190  

9.1.5.40, 9.1.5.56, 9.1.5.63, 9.1.5.80, 9.1.5.102  

TLS 1.2  

10.1.5.190  

9.2.5.6, 9.2.5.25, 9.2.5.27, 9.2.5.72  

TLS 1.0  

9.2.5.190 or 10.1.5.106 | 10.1.5.190  

9.2.5.153, 9.2.5.163, 9.2.5.190  

TLS 1.2  

10.1.5.190  

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170  

TLS 1.2  

10.1.5.190  

NS7500  

10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170  

TLS 1.2  

10.1.5.190  

NS7x50  

9.1.5.15, 9.1.5.20, 9.1.5.23  

TLS 1.2  

9.1.5.102 | 10.1.5.190  

9.1.5.40, 9.1.5.56, 9.1.5.63, 9.1.5.80, 9.1.5.102  

TLS 1.2  

10.1.5.190  

9.2.5.27, 9.2.5.72  

TLS 1.0  

9.2.5.190 or 10.1.5.107 | 10.1.5.190  

9.2.5.153, 9.2.5.163, 9.2.5.190  

TLS 1.2  

10.1.5.190  

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170  

TLS 1.2  

10.1.5.190  

NS3500  

9.2.5.34  

TLS 1.0  

10.1.5.106 | 10.1.5.190  

10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170  

TLS 1.2  

10.1.5.190  

Important

If you are using a hotfix release, contact   Trellix Support for the recommended upgrade path.  

Important

When you perform a Sensor upgrade and reboot the Sensor, you need to verify the status of Sensor through CLI and confirm if it displays   SIGFILE or   NO_SIGFILE. If the Sensor displays   NO_SIGFILE, it is in an abnormal state. You can recover the Sensor immediately by manually deploying sigfile to the Sensor using Manager.  

Upgrade paths for Virtual IPS Sensor software versions  

Prerequisites for Virtual IPS Sensor software upgrade  

Caution

Starting with release 10.1.7.50, the Manager software version supports only TLS 1.2 ciphers for Manager and Sensor communication.  

Caution

If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 10.1.7.50 or later, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and then, upgrade your Manager to 10.1.7.50 or later versions. Post this, you can upgrade the Sensor to 10.1.7.96 or later versions.  

For example, if you have a Virtual IPS Sensor running on 9.2.7.10 (TLS 1.0) and Manager on 10.1.7.44, and you plan to upgrade the Sensor to 10.1.7.155 and Manager to 10.1.7.65, you must follow the upgrade path as listed below:  

  1. Upgrade your Virtual IPS Sensor from 9.2.7.10 (Supports TLS 1.0) to 10.1.7.86 (Supports TLS 1.2).  

  2. Upgrade the Manager from 10.1.7.44 to 10.1.7.65.  

  3. Upgrade the Sensor from 10.1.7.86 to 10.1.7.155.  

Virtual IPS Sensor software ESXi (IPS-VM600):  

Sensor models  

Version  

TLS support  

Upgrade path to 10.1  

Virtual IPS Sensor software ESXi (IPS-VM600)  

9.1.7.13, 9.1.7.18, 9.1.7.22, 9.1.7.25, 9.1.7.27  

TLS 1.2  

10.1.7.155  

9.2.7.10, 9.2.7.26  

TLS 1.0  

10.1.7.86 | 10.1.7.155  

9.2.7.20, 9.2.7.54, 9.2.7.56, 9.2.7.65  

TLS 1.2  

10.1.7.155  

10.1.7.1, 10.1.7.42, 10.1.7.51, 10.1.7.65, 10.1.7.86, 10.1.7.96, 10.1.7.123, 10.1.7.135  

TLS 1.2  

10.1.7.155