The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

New features

This release of the Trellix Intrusion Prevention System includes the following new features:

Introducing Trellix Intrusion Prevention System Sensor - NS7600

This release of 11.1 introduces Trellix's next-generation IPS NS7600 Sensor model. The NS7600 Sensor operates at 5 Gbps, 10 Gbps, and 15 Gbps throughput depending on the license purchased.

The NS7600 Sensors are 1RU units equipped with the following components:

  • 4 SFP/SFP+ 1/10 Gigabit Ethernet ports in built-in G0 module

  • Three slots (G1, G2 and G3) for pluggable and hot swappable I/O modules:

    • 6-port RJ45 10/1 Gigabit with internal fail-open interface module

    • 8-port 10/1 Gigabit SM (8.5 micron) with internal fail-open interface module

    • 8-port 10/1 Gigabit MM (50 or 62.5 micron) with internal fail-open interface module

      Caution

      Apart from the network interface modules mentioned above, no other interface modules are compatible with the NS7600 Sensor.

  • SFP+ (SM and MM), SFP Fiber (SM and MM), and SFP Copper transceiver modules are supported in NS7600 Sensor models.

    Note

    Transceiver modules are supported in the built-in G0 module only.

  • One console port

  • Two external USB ports for Storage/Rescue applications

  • One RJ-45 10 Gbps/1 Gbps Management port

  • One RJ-45 10 Gbps/1 Gbps Response port

  • The front and rear panel LEDs provide status information for the health of the Sensor and the activity on its ports

Note that the following features are not supported in NS7600 Sensors:

  • Suricata Snort engine

  • Proxy-based SSL decryption (both inbound and outbound)

For more detailed information, see Trellix Intrusion Prevention System NS7600 Sensor Hardware Guide and Trellix Intrusion Prevention System 11.1.x Product Guide.

Introducing Trellix Intrusion Prevention System Sensor - NS3600

This release of 11.1 introduces Trellix's next-generation IPS NS3600 Sensor model. The NS3600 Sensor model provides 1 Gbps, 3 Gbps, and 5 Gbps throughput.

The NS3600 Sensors are equipped with the following components:

  • Console port

  • USB port

  • RJ-45 10/100/1000 Mbps Ethernet Monitoring ports

  • RJ-45 10/100/1000 Management port (MGMT)

  • RJ-45 10/100/1000 Response port (R1)

  • 2-port 10/1 Gbps Ethernet Monitoring ports (This requires SFP/SFP+ transceivers and they are sold separately.)

The Sensor LEDs provide status information for the health, link, speed, and activity on its management/response/monitoring ports.

The NS3600 Sensors support the 4-port copper and fiber interface modules. These interface modules can be installed in only one slot, which includes ports 11-14 on the Sensor. Note that the interface modules are not hot-swappable. The NS3600 Sensors support the following interface modules:

  • 4-port RJ-45 1 Gbps/100 Mbps/10 Mbps with internal fail-open Network Interface Module

  • 4-port 10/1 GigE MM 50/62.5 μm with internal fail-open Network Interface Module

In NS3600 Sensors, transceiver modules are supported only in ports 5 and 6. It includes SFP+ (SM and MM) and SFP Fiber (SM and MM).

The following features are not supported in NS3600 Sensors:

  • Suricata Snort engine

  • Proxy-based SSL decryption (both inbound and outbound)

For more information, see Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This release of the Trellix Intrusion Prevention System includes the following enhancements:

Attack being mapped to multiple tactics, techniques, and sub-techniques in the Attack Log

Starting with this release of 11.1, if an attack matches with multiple tactics, techniques, and/or sub-techniques, their names along with applicable technique/sub-technique IDs are shown in the respective fields under the Mitre Attack Details column in the Analysis → <Admin Domain Name> → Attack Log page. You can also view the same details by double-clicking an attack.

When an attack is mapped to multiple tactics, techniques, and/or sub-techniques, there is one-to-one correspondence among the tactics, techniques, sub-techniques, and technique/sub-technique IDs. For example, the first tactic corresponds to the first technique, sub-technique, technique/sub-technique ID, and so on.

For more information, refer to the section Filter, sort, and refresh alerts in Trellix Intrusion Prevention System 11.1.x Product Guide

Note

This enhancement is dependent on the availability of compatible signature sets that support multiple tactics, techniques, and sub-technique mappings for attacks.

Sending HTTP2 metadata to Trellix Network Investigator

Starting with this release of 11.1, IPS Sensors support the export of HTTP2 metadata to Trellix Network Investigator when the integration between Trellix IPS and Trellix NI is enabled.

Note

The NS-series Sensors NS9500, NS7600, NS7500, and NS3600 supports HTTP2 traffic inspection.

For more information, see the section Integration with Trellix Network Investigator in Trellix Intrusion Prevention System 11.1.x Integration Guide.

Configure the Linux-based Manager with IPv6 address

Starting with this release of 11.1, you will be able to configure the Linux-based Manager with an IPv6 address on the eth0 network interface.

For more information, see Configure the Manager on MLOS in Trellix Intrusion Prevention System 11.1.x Installation Guide.

The following commands are added:

Command

Description

set network ipv6

This command is used to assign the IPv6 address for the Manager server.

nmcli

This command is used to gather network related information as well as perform network operations.

networkmanager

This command allows you to perform various operations on the system network Manager such as start, stop, restart, and others.

For more information, see Manager Shell Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.

Support for Gateway Anti-Malware version 2023

With this release of 11.1, the Gateway Anti-Malware engine running on NS-series Sensors can be upgraded to version 2023. The upgraded engine offers improved stability and performance. Users also have the option to enable or disable behavioral scan on the GAM engine. This version of Gateway Anti-Malware is supported on Manager version 11.1.7.84 and later, and Sensor version 11.1.5.84 and later.

To view the Gateway Anti-Malware version in the Manager, go to Devices → <Admin Domain Name> → Global → Device Manager, click the Sensors tab, and select a Sensor from the list. The Gateway Anti-Malware version for the selected Sensor can be seen under the Protections column.

For more information, see Gateway Anti-Malware update in Trellix Intrusion Prevention System 11.1.x Product Guide.

Syslog notification format update

Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From this release of 11.1, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.

Refer to the table below to understand the difference in syslog notification format:

Sample Syslog notifications comparison

Till 11.1 Update 4

11.1 Update 5 and later

Syslog variables used: $SENSOR_NAME$ matched $ALERT_DIRECTION$ ACL rule ($ACL_POLICY$/#$ACL_RULE_NUMBER$) $SOURCE_IP$ -> $DESTINATION_IP$:$DESTINATION_PORT$ ($APPLICATION_PROTOCOL$/$APPLICATION$) = $ACL_ACTION$

Sep 10 20:03:39 10.0.0.0 SyslogACLLogForwarder: NS7150_FIPS matched Outbound ACL rule (Test/#1) 1.1.1.0 -> 1.1.0.0:80 (http/N/A) = DROP

Sep 10 20:03:39 10.0.0.0 SyslogACLLogForwarder: Sep 10, 2023 20:03:39 : NS7150_FIPS matched Outbound ACL rule (Test/#1) 1.1.1.0 -> 1.1.0.0:80 (http/N/A) = DROP

This change applies to all syslog notifications that are forwarded via the Manager, which includes syslog notifications configured for IPS Events, Faults, and User Activities in the Manager → <Admin Domain Name> → Setup → Notification page. As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.

IPS Security Vulnerability updates

This release contains the fixes for the following security vulnerabilities in the IPS Manager. You must upgrade both the IPS Manager and IPS Central Manager to the 11.1.7.84 version.

Security Vulnerability details

CVE #

Severity

Description

CVE-2024-5671

High

Insecure deserialization in some IPS Manager workflows allows unauthenticated remote attackers to execute arbitrary code and access the vulnerable Trellix IPS Manager.

CVE-2024-5731

High

This vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to manipulate the destination of the request by altering the IP Address parameter in the request. Additionally, the request parameter contains an encoded string with the username and password, which can be decoded to obtain the original string.

IPS CLI enhancements

The following Sensor CLI commands are added:

Normal Mode

Command

Description

show gam-behavioral-scan status

This command displays the status of the behavioral scan on the Gateway Anti-Malware engine as enabled or disabled.

Debug Mode

Command

Description

set gam-behavioral-scan config

This command allows users to enable or disable behavioral scans on the Gateway Anti-Malware engine.

Note

When both GAM airgap network and GAM behavioral scan configuration are enabled in the Sensor, the GAM engine might get Initialized with the version as 0.0. In such cases, you need to disable the GAM behavioral scan configuration using this command.

getnimdprotostats

This command displays counter specifics related to successful metadata export per protocol to Trellix Network Investigator when the integration with Trellix NI is enabled.

The following Sensor CLI commands are updated:

Normal Mode

Command

Description

show inlinepktdropstats <all>

(Applicable to NS7600 Sensors only) The show inlinepktdropstats all command now shows the count for the following two categories:

  • Count of packets dropped due to oversubscription. This count is triggered when the throughput exceeds the subscription limit. This is a subset of Total Other Layer-2 Packets Dropped.

  • Count of packets not dropped though oversubscribed. This count is triggered when the subscribed license capacity is reached but packets are not dropped.

Debug Mode

Command

Description

getnistats

This command now shows additional counter specifics related to netflow and metadata export to Trellix NI. Some of these counters include the following:

  • NI netflow metadata export failure count

  • NI metadata request timeout error count

  • NI netflow export timeout and NI netflow metadata export timeout count

  • NI netflow template creates success and failure count

  • NI netflow metadata template creates success and failure count

  • NI netflow queue drop and netflow metadata queue drop count

For more information, see CLI Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.16 which includes additional security against new vulnerabilities and bug fixes.

JDK upgrade

Starting with this release of 11.1, the IPS Manager uses JDK version 1.8u401-b03 which includes additional security against new vulnerabilities.

Apache Tomcat server upgrade

Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.85. This server update provides a collection of security fixes.