The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Troubleshooting Azure Gateway Load Balancer integration issues

Prev Next

Issues related to the display status of Azure Gateway Load Balancer in the IPS Manager

If the status of Azure Gateway Load Balancer displays Inactive, it means there is a traffic inspection issue. You can follow the below steps to troubleshoot the display error in the Manager:

  • Login to the Azure portal and check if the Sensors are added to the Backend pool.

  • Check the health status of the Sensor. If the Sensor is unhealthy, perform the following:

    • If a new Sensor is added, you can wait for approximately 15 minutes and recheck the Sensor status.

    • Check if the HealthCheck Protocol is set to TCP. Also, confirm if the HealthCheck Port is set to 9001.

  • Run the CLI show cloud-gwlb status and check if HealthCheck counters are increasing. If counters are increasing, there is no issue. The status of GWLB will display as Active in a few minutes. Otherwise, it signifies zero traffic flow due to the GWLB settings issue.

  • Run the CLI show ingress-egress stat to verify if the Sensor receives packets from GWLB.

Note

  • It is recommended to have an auto-scaling group so that if a Sensor becomes inactive, all other Sensors remain active.

  • If the appropriate protocol (VXLAN), type, ports, and identifiers are not configured accurately during the GWLB deployment, you cannot modify these configurations after the deployment. To change the configuration after GWLB deployment, you can delete and reconfigure the backend pool configuration.

User data issue

  • You cannot use the same user data as Probe while configuring the Azure Gateway Load Balancer.

  • If the user data is missing in the Sensor while deploying the Sensor, the Sensor won't be able to connect to the Manager. Therefore, the Manager dashboard fails to display the Sensor details. Hence, log in to the Azure portal and update user data in the Sensor.

  • If incorrect user data is updated, ensure the Traffic Source is configured as GWLB. In such cases, the Manager connects to the Sensor, but not the GWLB, causing a failure in the health check.

For more information related to user data, see Launch the Virtual IPS Sensor virtual machine.

Security group issue

To troubleshoot any security group issue between GWLB and the Sensor, you must first verify the inbound and outbound rules. Ensure the configured rules meet the recommended values. For more information, see Requirements to deploy Trellix vIPS in GWLB-based Azure environment.