The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Troubleshooting the GCP Internal Passthrough Load Balancer integration issues

Prev Next

Issues related to the display status of the GCP Internal Passthrough Load Balancer in the IPS Manager

If the status of GCP Internal Passthrough Load Balancer displays Inactive, it means there is a traffic inspection issue. You can follow the below steps to troubleshoot the display error in the Manager:

  • Login to the GCP portal and check if the Sensors are added to the Backend pool.

  • Check the health status of the Sensor. If the Sensor is unhealthy, perform the following:

    • If a new Sensor is added, you can wait for approximately 15 minutes and recheck the Sensor status.

    • Check if the HealthCheck Protocol is set to TCP. Also, confirm if the HealthCheck Port is set to 9001.

  • Run the CLI show cloud-gwlb status and check if HealthCheck counters are increasing. If counters are increasing, there is no issue. The status of GWLB will display as Active in a few minutes. Otherwise, it signifies zero traffic flow due to the GWLB settings issue.

  • Run the CLI show ingress-egress stat to verify if the Sensor receives packets from GWLB. If the Sensor fails to receive packets, verify if a valid GCP ILB forwarding rule IP is updated in the user data.

Note

  • It is recommended to have an auto-scaling group so that if a Sensor becomes inactive, all other Sensors remain active.

  • If the appropriate protocol (VXLAN), type, ports, and identifiers are not configured accurately during the load balancer deployment, you cannot modify these configurations after the deployment. To change the configuration after load balancer deployment, you can delete and reconfigure the backend pool configuration.

User data issue

  • If the user data is missing in the Sensor while deploying the Sensor, the Sensor won't be able to connect to the Manager. Therefore, the Manager dashboard fails to display the Sensor details. Hence, log in to the GCP portal and update user data in the Sensor.

  • If incorrect user data is updated (specifically, if Traffic Source is not configured as GCPNSI and an invalid GCP ILB forwarding rule IP is added), the Manager will connect to the Sensor but fail to connect to the load balancer, leading to a health check failure.

For more information related to user data, see Launch the Virtual IPS Sensor virtual machine.

Firewall rules issue

To troubleshoot any firewall rules issue between the load balancer and the Sensor, you must first verify the inbound and outbound rules.

The firewall rule for the Sensor's traffic inspection must be configured in the NSI In-band firewall, not within the Trellix vIPS VPC firewall.

For all protected VMs, ensure both ingress (inbound) and egress (outbound) rules are specified within the NSI In-band firewall policy.

Ensure the configured rules meet the recommended values. For more information, see Requirements to integrate the internal passthrough load balancer in the GCP environment.