The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

System requirements

Prev Next

Before you configure the Network Security high availability pair, make sure the following requirements are met.

Hardware requirements

  • HA support is available for NX x600 appliance models. The following appliances are supported:

    NX2600
    NX3600
    NX4600
    NX5600
    NX6600
    NX8600

    Note

    On all x600 and 4500, 5500, 6500 models, any monitoring port pairs can be configured as HA port pair.

  • Two Network Security appliances of the same model type. The following models are supported:

    NX 4500
    NX 5500
    NX 6500
  • One Central Management System appliance to manage the Network Security appliances.

  • Cable connection from the HA control port on one Network Security appliance to the same port on the other appliance. These are SFP+ ports that can take copper or fiber SFPs, so you can use a straight-through or crossover cable.

Note

The default HA control port is pether9 for the NX 4500, NX 5500, and NX 6500 appliances

  • Cable connection from the HA data port on one Network Security appliance to the same port on the other appliance. These are SFP+ ports that can take copper or fiber SFPs, so you can use a straight-through or crossover cable.

Note

The default HA data port is pether10 for the NX 4500, NX 5500, and NX 6500 appliances

Network requirements

  • Single-site LAN deployment

  • HA control port to exchange heartbeat messages and configuration information between the two appliances.

Note

The HA control port is pether9 for the NX 4500, NX 5500, and NX 6500 appliances

  • HA data port to replicate traffic from the monitor ports of one appliance to the other appliance.

Note

The HA data port is pether10 for the NX 4500, NX 5500, and NX 6500 appliances

  • Network deployment capable of switching traffic to the other appliance if the monitor port link on one of the appliances goes down.

Note

Contact Trellix customer support to have different HA control and data ports configured for HA support on the NX 4500, NX 5500, and NX 6500 appliances.

A reboot of both appliances is required after HA port configuration.

Software requirements

  • The same major and minor version (Release 7.8.0 or later) of the Network Security software image running on both appliances.

  • Release 7.8.0 or later of the Central Management System software image running on the Central Management System appliance that manages the appliances.

  • Both Network Security appliances connected to the same Central Management System appliance.

  • The same guest images (profile and version) running on both appliances.

  • The same security content version running on both appliances.

  • Inline block mode or monitor mode configured on both appliances.

  • The same policies applied to both appliances, and the same configuration settings for most features on both appliances. See Synchronizing configuration settings for details.

  • The same detection-related feature licenses installed on both appliances. For example, both appliances need an IPS license if IPS is enabled on either one.

  • The same Network Security edition (Power or classic) on both appliances.

  • IPv6 must be enabled on the Network Security appliances.

Licensing requirements

Valid licenses must be installed on each Network Security appliance in a Network Security HA pair. One appliance has a full Network Security appliance license. The other appliance can have either a full license or a restricted (or secondary) license.

After a restricted license is installed, a 90-day grace period begins. The appliance with the restricted license must be added to a Network Security HA pair within 90 days. If the secondary appliance is not paired before the grace period ends, detection functionality will be disabled on that appliance until it is added to an HA pair. A notice in the Network Security Web UI and in the Network Security CLI login message states the number of days left before detection will be disabled. In the following examples, the notice indicates that there are 89 days left in the grace period.

Examples

The following example shows a grace period notice in the Network Security Web UI.

NXHA_DashboardLicense_scap.PNG

The following example shows a grace period notice in the Network Security CLI.

***************************************
*** NX-HA License Expiration notice ***
***************************************

    The system is not paired but is still within the grace period; 
    detection is still working, but the grace period expires in 89 days.

The following example shows that the grace period is disabled because the appliance with the restricted license has been added to the Network Security HA pair. If this appliance is later removed from the pair, the grace period is re-enabled and the 90-day countdown restarts.

nx-2 # show ha status
        High Availability          :Enable
        HA Cluster Name            :Acme_NX
        HA Peer Name               :nx-1
        HA Peer ID                 :2XXXXXXXXXXX
        HA Status                  :Good
        HA Status Description      :OK
        HA License                 :Restricted
        HA Grace Period Status     :Disabled
        HA Grace Period Days Left  :90