Resource groups with overlapping IP addresses should use different vIPS clusters.
Though same policy group can be applied to all the VM groups, VM groups cannot span across multiple resource groups.
The name of the attacker VM will be derived by querying your Azure subscription account for the attacker IP address. If the attacker is external, and has an IP address that matches with any of the virtual machines in the Azure subscription account, the virtual machine with the matching IP address will be identified as the attacker.
Based on the virtual machine type, Azure has limitations on the traffic. Redirection of traffic to the Sensor is within this limit. For example, in a web server type of application, 50% of the bandwidth is consumed for redirection of traffic to the Sensors.
Trellix recommends you to deploy the Virtual IPS Sensor and the protected groups in the same Region with private IP addresses.
Usage guidelines
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?