The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor software upgrade using a TFTP or SCP server

Prev Next

To download a software image directly to the Sensor through a TFTP or SCP server, you must first download the software image to your TFTP or SCP server. See your TFTP or SCP server documentation for specific instructions on how to download the image to your TFTP or SCP server.

Task

  1. If you have not already done so, download the latest 10.9.x signature set from the Update Server.
    In the Manager, select Manager → <Admin Domain Name> → Trellix IPS Protection Status. Then, select Signature Sets tab. The Signature Sets tab is displayed. Select Download Latest Signature Set option. See the Trellix Intrusion Prevention System Product Guide for step-by-step information on how to download the signature set. For a list of currently supported protocols, see KB61036 at Trellix Support Portal.

    Note

    If you are using the Advanced Callback Detection feature, make sure you have downloaded the latest callback detectors to the Manager. See Trellix Intrusion Prevention System Product Guide for the details on downloading callback detectors.

  2. Download the software image from the Update Server to your TFTP or SCP server.
    This file is compressed in a .jar file.
  3. Rename the .jar file to .zip file.
  4. Unzip the file using Winzip.
  5. Extract the files to your TFTP boot folder [/tftpboot]. In case of SCP, extract the files to any directory.
  6. Once the image is on your TFTP/SCP server, upload the image from the TFTP/SCP server to the Sensor.
    From your Sensor console, perform the following steps:
    1. Log in to the Sensor.
      The default user name is admin and default password admin123.
    2. Make sure you have set the TFTP or SCP server IP on the Sensor. Use the set tftpserver ip or set scpserver ip command as described in the CLI commands section in the Trellix Intrusion Prevention System Product Guide.
    3. Load the image file on the Sensor. Use the loadimage command as described in the CLI commands section in the Trellix Intrusion Prevention System Product Guide.
    4. To use the new software image, you must reboot the Sensor. At the prompt, type reboot.

      You must confirm that you want to reboot.

      Note

      For some Sensor models, the hitless reboot option is available, wherein only the required software processes are restarted. However, for Sensor software upgrades and updates, you must do a full reboot.

      For NS-series Sensors, you must do a full reboot as hitless reboot is not supported when SSL decryption is enabled. For information on these reboot options, see the Trellix Intrusion Prevention System Product Guide.

      After the reboot process is complete, the Sensor deletes the old signature set. Because the signature set is incompatible with the current Manager version, the Sensor's system health status on the CLI is displayed as uninitialized. Then, the Sensor contacts the Manager for the latest signature set. After the signature set is downloaded to the Sensor, its system health status is displayed as good. Signature set update could fail because of Snort custom attacks that contain unsupported PCRE constructs. In such cases, the Incompatible custom attack fault is raised in the Faults tab in Manager → <Admin Domain Name> → Troubleshooting → Logs.

  7. Verify the Sensor's system health status is good; check the Sensor status from CLI by typing the status command.
    You can also check whether the Sensor is updated with the latest software version as well as latest signature set in the Summary page.
    1. Click the Devices tab.
    2. Select the domain from the Domain drop-down list.
    3. On the left pane, click the Devices tab.
    4. Select the device from the Device drop-down list and click Summary.