The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

The IPS Sensor interface node

Prev Next

The Interface-x nodes under IPS Interfaces represent an interface (a single physical port, peer ports, or an interface group) on a particular Sensor. The number of interface nodes displayed depends upon the type of Sensor. Interface nodes are displayed individually by default because the default monitoring mode is SPAN mode.

Full-duplex Tap and Inline modes require two physical ports, and each mode uses these two ports to form a single logical interface. Therefore, all configuration and policy decisions are made at a logical interface level.

After a new Sensor is installed, a policy is inherited from the admin domain and enforced on all Sensor interfaces. Subinterfaces are user created within this resource, and can be edited here or from the Sub-interface-x resource node.

Tip

Interfaces can be allocated to child domains for specialized management.

The navigation path to the interface nodes is as follows:

  1. Click the Devices tab.

  2. Select the domain from the Domain drop-down list.

  3. On the left pane, click the Devices tab.

  4. Select the device from the Device drop-down list.

  5. For a standalone Sensor, select IPS Interfaces → <interface name>.

    For Sensors in a stack, select IPS Interfaces → <Stackname-node id> → <interface name>.

The primary tasks that you can perform are customizing policies, assigning policies, and configuring inspection options.