The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Stateless Scanning Exceptions

Prev Next

The Scanning exceptions feature bypasses the scanning of traffic from a configured VLAN, TCP, or UDP port. The scanning exceptions configurations that are defined can be enabled or disabled at the Sensor level.

Note

Scanning exception feature rules are applied to both the Sensors in a fail-over pair. On creating a fail-over pair, the template Sensor rules are copied to the peer Sensor.

Scanning Exceptions feature is supported only in the following Sensor models:

  • NS9600

  • NS9500

  • NS9300

  • NS9200

  • NS9100

  • NS7350

  • NS7250

  • NS7150

  • NS7300

  • NS7200

  • NS7100

  • NS5200

  • NS5100

  • NS3200

  • NS3100

Note

NS3500 Sensors do not support Scanning Exception feature.

Note

Scanning exceptions rules can be configured on ports running in inline mode. Once set, these rules take precedence over Firewall access rules. Fail-over ports cannot be configured for scanning exceptions.