The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Setting device profiling parameters for all Sensors belonging to a domain

Prev Next
  1. Go to Devices → <Admin Domain Name> → Global → IPS Devices Settings → Passive Device Profiling.

    The Passive Device Profiling page appears.

  2. Select the technique that you would like the Manager to use for device profiling.

    You will notice three checkboxes:

    • DHCP indicates the use of DHCP DISCOVER and REQUESTS packets for device profiling.

    • TCP indicates the use of TCP SYN and SYN + ACK packets for device profiling.

    • HTTP indicates the use of HTTP User Agent field for device profiling.

    Important

    The above mentioned techniques are enabled by default at the global level. However, to ensure that device profiling is enabled, you must configure the settings per device or per interface using the Policy Manager page.

  3. Specify the Profile Expiration duration.

    This timer ensures that the periodic re-profiling of a device happens only once within that interval. Trellix recommends this duration be set at 5 minutes. However, you can alter this and increase it up to 12 hours.

  4. Specify the Endpoint Inactivity Timer duration.

    This value specifies the duration after which information for a device is considered invalid. It occurs when the host has remained idle for the said duration. This timer ensures that the Sensor will renew its detection of the IP if it is noticed again. Trellix recommends this duration be set at 1 hour. However, you can alter this and increase it up to 24 hours.

    Note

    The parameters set in steps 2, 3, and 4 can be overridden or inherited at the device or interface level using the Policy Manager page.

  5. Click Save.