The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

VLAN bridging for Sensors in fail-over mode

Prev Next

This section explains a sample scenario in which Sensors in fail-over mode are configured for VLAN Bridging.

Sensors in fail-over mode
VLAN Bridging in fail-over mode


The network design in the diagram above is as follows:

  • This scenario represents an active/standby network path.

  • Client 10.1.1.20 is in VLAN 100 and the server 11.1.1.20 is in VLAN 200.

  • The client is connected to an access switch AS 1 and the server is connected to the access switch AS 2.

  • The access switches, AS 1 and AS 2 are connected to two L3 switches (DS 1 and DS 2) for redundancy.

  • Spanning Tree Protocol is disabled in both DS 1 and DS 2.

  • DS1 is connected to Sensor 01 and DS 2 is connected to Sensor 02. These Sensors are in fail-over mode.

  • Sensor ports G0/1 and G0/2 are configured to bridge VLANs 100 and 150.

  • In DS 1 and DS 2 only the ports connecting to G0/1 and AS 1 are configured for VLAN 100.

  • Only the switch ports connected to port G0/2 are configured for VLAN 150.

  • The ports of DS 1 and DS 2 connecting to G0/2 are configured as one Hot Standby Routing Protocol (HSRP) group. This provides an active/standby network path.

  • The ports of DS 1 and DS 2 that connect to AS 2 are configured as one HSRP group to provide the active/standby network path for the response traffic.

  • It is critical that the HSRP Hello multicasts from HSRP group members reach all the participating HSRP group members to trigger a HSRP switchover.

The flow of traffic when the client tries to access the server is as follows:

  • Traffic from the client is tagged VLAN 100 by AS 1 and then sent to either DS 1 or DS 2 based on which path is active. Let us assume that currently DS 1 is active and DS 2 is in standby.

  • From DS 1, the only path available for the VLAN 100 traffic is it to port G0/1 of Sensor 01.

  • If the traffic is clean, the Sensor changes the VLAN tag to 150 and sends it out through G0/2.

  • DS 1 does inter-VLAN routing accordingly and the traffic reaches the server through AS 2.

  • If Sensor 01 is down, then HSRP failover is triggered and DS 2 becomes the active path. As a result, IPS and VLAN bridging are performed by Sensor 02. All the flows that were processed by Sensor 01 are intact since Sensor 02 has the updated state information for all those flows and it takes over seamlessly.