The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Synchronizing policies

Prev Next

All Central Manager policies (Trellix IPS-defined and user-defined) are synchronized with the Managers. While viewing the policies from the added Managers, the Central Manager policy names have NSCM prefixed to differentiate them from the Manager policies. For example, a Default Prevention policy defined in the Central Manager will be seen as NSCM Default Prevention in the Manager IPS Policy Editor. The same applies to user-defined Central Manager policies also.

The Central Manager policies are non-editable in the Managers. The Central Manager Attack Defaults settings are merged with the Central Manager policy. The Managers Attack Defaults settings do not affect any Central Manager policy and vice versa.

Each Manager must import signature sets independently. The policies and attack set profiles are evaluated based on the Manager signature set.

If the Central Manager removes a policy and the policy is being used in a Manager, then, during synchronization, the Central Manager policy in the Manager is renamed and the ownership changed to that of the Manager. A fault is raised in the Manager indicating that the policy has not been removed in that Manager.

For more information on configuring policies, refer to the chapter Working with IPS policies.

Configuring policy synchronization

The Policy tab in Devices → <Admin Domain Name> → Manager Management → Synchronization page allows you to view and synchronize configurations between the Central Manager and all the Managers.

Field

Description

Synchronization Type

  • Incremental (default: Enabled) - Based on last synchronization time

  • Full - Complete synchronization

Manager Name

Name of the Manager added

Synchronization Required

  • Yes - If synchronization is required

  • No - If synchronization is not required

Synchronization Status

  • Trellix IPS Manager - Enabled/Disabled for Manager

  • Trellix IPS Central Manager - Enabled/Disabled for Central Manager

To trigger manual synchronization with the Manager, click Synchronize.

To individually synchronize configurations between a Manager and the Central Manager, go to Devices → <Admin Domain Name> → <Manager Name> → Synchronization and click on Policy tab.

Field

Description

Synchronization Type

  • Incremental (default: Enabled) — Based on last synchronization time

  • Full— Complete synchronization

Manager Name

Name of the Manager added

Last Synchronized

Time when last synchronization took place.

Time is displayed as per the client time zone. For more information, see Viewing the server/client date and time.

Synchronization Required

If synchronization is required or not

  • Yes - If synchronization is required

  • No - If synchronization is not required

Reason

Reason for synchronization

Synchronization Status

  • Trellix IPS Manager - Enabled/Disabled for Manager

  • Trellix IPS Central Manager - Enabled/Disabled for Central Manager

To trigger synchronization with the Manager, click Synchronize.

Note

You can also access Synchronize Policies menu from Policy → Intrusion Prevention.

Note

If the Central Manager contains a rule object with more than 10 entries, the Central Manager synchronizes only those rule objects containing 10 entries or lesser with a Manager running on or before 10.1.7.55.

Scheduling policy synchronization

You can configure the polices to be synchronized at regular time intervals. To set the policy scheduler in Central Manager, do the following:

  1. Select Manager → Setup → Synchronization → Policy Scheduler

    Note

    Yes is selected by default in the Automate Synchronization field of the Policy Scheduler section. Select No to turn off the scheduled synchronization.

  2. Select time from the drop-down list of the Recur every field.

  3. Click Save.