The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Verify successful installation

Prev Next
  1. Type status in the Sensor CLI.

    The status report appears.

    Status_CLI.png

    The Sensor parameter System Initialized should be yes, and for Manager communications Trust Established should be yes.

  2. From the Manager Dashboard, view the Manager status in the System Faults monitor.

    The Manager status displays as Up and the Sensor status is Active.

    Dashboard_SystemFaults.png
  3. From the Manager, click Devices → <Admin Domain> → Devices → Setup → Physical Ports to view the port details of the Sensor.

    To view port settings, select the port on the Sensor that you cabled. Ensure that your port settings match the cabling. For example, if port 1 is cabled for inline mode, the mode of operation in the port setting should be inline mode.

    Note

    For more information on port settings, see the chapter Configuring the monitoring and response ports of a Sensor in the Trellix Intrusion Prevention System 11.1.x Product Guide.

    PhysicalPorts_MonitoringPorts_NS3600.png
  4. A policy named Default Prevention is active upon the addition of the Sensor. To view this policy, select Policy → <Admin Domain> → Intrusion Prevention → Policy Types → IPS Policies.

    The Default Prevention policy contains attacks already configured with a "blocking" Sensor response action. If any attack in the policy is triggered, the Sensor automatically blocks the attack. To tune this or any other Trellix-provided policies, you can clone the policy and then customize it as described in the Trellix Intrusion Prevention System 11.1.x Product Guide.