The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Using active fail-open kits

Prev Next

Trellix supports the following types of passive and active fail-open kits:

  • 10/100/1000 Gigabit Copper Passive Fail-Open Bypass Kit

  • 1 Gigabit Optical Passive Fail-Open Bypass Kit

  • 10 Gigabit Optical Passive Fail-Open Bypass Kit

  • 10/100/1000 Copper Active Fail-Open Bypass Kit

  • 10/100/1000 Copper Active Fail-Open Bypass Kit with SNMP monitoring

  • 1 Gigabit Optical Active Fail-Open Bypass Kit

  • 10 Gigabit Optical Active Fail-Open Bypass Kit

  • 100 Gigabit Modular Active Fail-Open Bypass Kit Guide

  • 40 Gigabit Modular Active Fail-Open Bypass Kit Guide

Fail-open kits can be deployed in production networks for the following reasons:

  • Reduce the network downtime to seconds during any Sensor reboot or Sensor failure.

  • Protect your network during link failure on the Sensor.

  • Bypass the traffic when troubleshooting network issues. This will help you identify or eliminate the Sensor as the cause of network issues.

In the passive fail-open kit, if the Sensor goes down, the link has to be renegotiated again between the peer devices and this causes the link to go down for some time. In case of an active fail-open kit, a physical link will be established between the active fail-open kit and the two peer devices even when the Sensor is active. There would not be any link flap even when the Sensor goes down. Trellix recommends deploying active fail-open kits for protection of mission critical networks.

For Virtual IPS Sensors, only 10/100/1000 Copper Active Fail-Open Bypass Kit and 10/100/1000 Copper Active Fail-Open Bypass Kit with SNMP monitoring are supported. For more information, see Virtual IPS Sensor deployment section in the Trellix Virtual Intrusion Prevention System Product Guide.

Passive Fail-open

In passive fail-open kits, during normal Sensor in-line, fail-open operation, the Fail-Open Controller or built-in Control port (depending on which controls the Bypass Switch) supplies power and a heartbeat signal to the Bypass Switch.

If this signal is not presented within its programmed interval, the Fail-Open Bypass Switch removes the Sensor from the data path, and moves into bypass mode, providing continuous data flow with little network interruption. While the Sensor is in bypass mode, traffic passes directly through the switch, bypassing the Sensor. When normal Sensor operation resumes, you may or may not need to manually re-enable the monitoring ports from the Manager interface, depending on the activity leading up to the Sensor's failure.

Active Fail-open

In case of active fail-open kits, during normal Sensor in-line fail-open operation, the built-in monitoring sends a heartbeat signal (1 every second) to the Bypass Switch. If the Sensor does not receive 3 heart beat signals within its programmed interval, the Fail-Open Bypass Switch removes the Sensor from the data path, and moves it into the bypass mode, providing continuous data flow.

When the Bypass Switch loses power, traffic continues to flow through the network link, but is no longer routed through the Bypass Switch. This allows network devices to be removed and replaced without network downtime. Once power is restored to the Bypass Switch, network traffic is seamlessly diverted to the monitoring device, allowing it to resume its critical functions.