The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Usage guidelines

Prev Next
  • VPCs with overlapping IP addresses should use different vIPS clusters.
  • Though same policy group can be applied to all the VM groups, VM groups cannot span across multiple VPCs.
  • Probe installation packages are cluster specific and they cannot be interchanged across clusters.
  • The name of the attacker VM will be derived by querying your AWS account for the attacker IP address. If the attacker is external, and has an IP address that matches with any of the instances in the AWS account, then the instance with the matching IP address will be identified as the attacker.
  • Based on the instance type, AWS has limitations on the traffic. Redirection of traffic to the Sensor is within this limit. For example, in a web server type of application, 50% of the bandwidth is consumed for redirection of traffic to the Sensors.

    Trellix recommends you to deploy the Virtual IPS Sensor and the protected groups in the same Availability Zones with private IP addresses.

  • When you search for Trellix software images in the AWS UI, it may not be possible to know all the details such as version number, build number, and so on from the name of the image. To identify a specific Trellix software image, select the image from the search results, and verify the following fields:
    • Owner - Specifies the owner of the image. In case of vIPS solution components, the owner will be the Trellix account ID.
    • Description - Specifies the version of the image. For example, if you are searching for a 10.1 image, the description text will be like trellix_vips.