The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update configuration of a Sensor

Prev Next

Configuration updates refer to changes to device and interface/subinterface configurations, such as port configuration, non-standard ports, interface traffic types, and configuration changes to the Sensor.

Signature updates have new and modified signatures that can apply to the attacks enforced in a chosen policy. Policy changes update the device in case of a newly applied policy or changes made to the current enforced policy.

You can schedule configurations to be pushed to the Sensors from Manager → <Admin Domain Name> → Trellix IPS Protection Status. Select Signature Sets tab. The Signature Sets tab is displayed. Schedule the frequency at which the automatic deployment must occur by enabling the Automatically Deploy New Signature Sets option from Automatic Deployment (Manager to Devices). The configurations are automatically deployed to Sensors from Manager based on schedule.

All configurations in the Policy page that apply to your Sensors can also be manually pushed from Devices → <Admin Domain Name> → Global → Device Manager. Select Sensors tab. From the list, select the required Sensors. Select Sync (all Sensors in a domain) or Devices → <Admin Domain Name> → Devices → <Device Name> → Deploy Pending Changes (to a single Sensor) action.

Scheduled deployment

Steps:

  1. Select Manager → <Admin Domain Name> → Trellix IPS Protection Status. Select Signature Sets tab. The Signature Sets tab is displayed.

    Automatic Deployment (Manager to Devices)
    Automatic Deployment (Manager to Devices)


  2. Enable Automatically Deploy New Signature Sets? option. By default, it is disabled.

    • To push signature sets update to all Sensors immediately after it is downloaded to the Manager, select Immediate (after download) from Deployment drop-down. Click Save to setup the automatic deployment.

    • To configure the required interval of automatic deployment, select Scheduled from Deployment drop-down option. Choosing this provides, When option.

    • From the When option, customize the interval at which the deployment must occur. The following options are displayed in the drop-down list:

      • Daily: To deploy new signature sets daily. Set the time at which the deployment must occur.

      • Weekly: To deploy new signature sets weekly. Set the day of the week and time at which the deployment must occur.

      • Custom: To customize the interval at which the deployments must occur. The following options are displayed:

        • Every: Set the recurrence of time for the devices to poll the Manager.

        • Between: Set the time range at which the deployment must occur.

  3. Click Save.

On-demand deployment

Steps:

  1. Select Devices → <Admin Domain Name> → Devices → <Device Name> → Deploy Pending Changes.

    The Deploy Pending Changes page is displayed.

    Deploy Pending Changes page
    Deploy Pending Changes page


    Tip

    SSL key push failures can be caused by missing or corrupted certificates or an inconsistency in the shared secret key between the Sensor and Manager. Trellix Manager version 11.1.7.x and later displays the precise reason and resolution steps to address such SSL key push failures.

  2. View the update information. If changes have been made, the Configuration & Signature Set column is checked by default.

  3. Click Deploy.

    A pop-up window displays configuration download status.