The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

New features

This Trellix Intrusion Prevention System release includes the following new features:

New performance monitoring capabilities

With the 11.1 Update 9 release, you can now monitor the Packets usage and Inspection Time from Performance Charts. You can access them through Device → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Performance Charts. This functionality is supported on IPS-VM600, IPS-VM600-SSL, IPS-VM5000, and IPS-VM5000-SSL Sensors.

Packets tab details:

You can view the number of packets transferred within a specified time frame. By default, the system displays device-level packet data. To access port-specific data, select Port from the available drop-down menu.

You can customize your view of network packets by selecting or deselecting any of the five available size ranges: Total, 0-64, 65-127, 128-255, and 256-511. By default, all ranges are displayed. For any chosen interface, the system displays the number of packets in the format: <Device Name>, <Number> packets of <packet size range>, and time in MMM DD HH:MM:SS YYYY.

Inspection Time tab details:

You can monitor the total inspection time, along with the inspection time contributed by each of the top 5 contributors. By default, the system does not display the top five contributors to this delay. To enable the visibility of these top five contributors, select the Top 5 Contributors checkbox.

For any chosen interface, the system displays the inspection time in the format: <Device Name>, <time in microseconds> Inspection Time <contributor details>, and time in MMM DD HH:MM:SS YYYY.

For more information, see Performance metrics in Trellix Intrusion Prevention System 11.1.x Product Guide.

OpenID Connect (OIDC)-based Identity Provider (IdP) authentication in the Manager

Starting with this release, the Manager supports user authentication through an OpenID Connect (OIDC)-based Identity Provider (IdP) to enhance security and streamline the user login experience with Single Sign-On (SSO) capabilities. This allows users to log in to the Manager with their IdP credentials, including Multi-Factor Authentication (MFA) if enabled. Supported IdPs are Okta, Microsoft Entra, and Google IdP.

Before configuring IdP authentication in the Manager, ensure the following requirements are met:

  • The Manager client application must be registered with the IdP. This process provides the necessary Client ID and Client Secret keys required for the IdP server configuration in the Manager.

    Note

    You need to have access to IdP with required privileges to register the IPS Manager client application. Or else, contact your IdP system administrator and request for the registration.

  • Users must have an active account with the required IdP and be assigned appropriate user profile and user policy by their IdP system administrator so that they can access the Manager using IdP credentials.

  • A proxy server must be configured in the Manager for internet access.

Enabling IdP authentication is a two-step process:

  1. Configure IdP Server(s) in Manager using the Manager → <Admin Domain Name> → Setup → GUI Access → IdP Authentication page.

  2. Add a user with ODIC as Authentication Type, specifying their IdP User Name, email address (which must match the one configured in IdP), and assigning them a role (barring No Role)

If Allow IdP access only? option is enabled during the IdP server configuration, users are directly authenticated by the configured IdP on accessing the Manager. Otherwise, they can choose between the local Manager login and IdP-based login. For more information, refer to Leveraging OIDC for IdP Authentication in the Manager in Trellix Intrusion Prevention System 11.1.x Product Guide.

New alert and audit notifications in syslog messages

From this 11.1 release, a new token $IV_MANAGER_DETAILS$ is introduced to display the hostname and IP addresses of the Manager. You can access it from Manager → <Admin Domain Name> → Setup → Notification → IPS Events → Syslog and Manager → <Admin Domain Name> → Setup → Notification → User Activity → Syslog. For an MDR setup, it further specifies if the Manager is "primary" or "secondary".

For more information, see Add a Syslog notification profile to forward alerts and Forward audit information to Syslog Server in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This Trellix Intrusion Prevention System release includes the following enhancements:

Enhanced throughput monitoring capabilities

Starting with this 11.1 release, the unit used for plotting the device throughput charts is Mbps. This functionality is supported on IPS-VM600, IPS-VM600-SSL, IPS-VM5000, and IPS-VM5000-SSL Sensors. The Maximum, Average, or Minimum summarized data are replaced with the Average and Peak throughput usage at both device and port levels. The data update frequency has improved from every 3 minutes to every 30 seconds.

For more information, see Performance metrics in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhanced SNMP scalability

From this 11.1 release, while adding NMS users and IP addresses from Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Remote Access → NMS, you can add a maximum of 50 users, IPv4, and IPv6 addresses.

For more information, see Management of NMS users in Trellix Intrusion Prevention System 11.1.x Installation Guide.

Enhanced fault notifications in syslog messages

From this 11.1 release, $IV_DEVICE_NAME$ will also display the hostname and IP addresses of the Manager. You can access it from Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog. For an MDR setup, it further specifies if the Manager is "primary" or "secondary".

For more information, see Forward faults to a Syslog server in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhanced security for User Accounts

Starting with the 11.1 Update 9 release, all information displayed in the user details panel is encrypted. This signifies that sensitive user data, including personal information and account credentials, is now protected through encryption, thereby strengthening user privacy and overall security.

For more information, see How to view user account information in Trellix Intrusion Prevention System 11.1.x Product Guide.

Terminology updates in the UI

Navigation Path

Prior to 11.1.7.136

11.1.7.136 and later

At domain level: Devices → <Admin Domain Name> → Global → IPS Device Settings → IVX Integration → Enable IVX Integration → Enable IVX Cloud

At device level: Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → IVX Integration → Enable IVX Integration → Enable IVX Cloud

The hostname for IVX Cloud service is preconfigured and is not editable.

You can enter the hostname for IVX Cloud service manually.

Manager → <Admin Domain Name> → Integration → GTI

Go to Endpoint/URL Reputation and view Public GTI Endpoint/URL Reputation Queries, the link is displayed as https://nsp.repl.gti.trellix.com.

Go to Endpoint/URL Reputation and view Public GTI Endpoint/URL Reputation Queries, the link is displayed as https://ips.repm.gti.trellix.com.

IPS CLI enhancements

The following Sensor CLI commands are updated:

Debug Mode

Command

Description

getnistats

Several counters have been added to identify specific errors and statistics related to exporting data to the Trellix Network Investigator (NI), such as the following:

  • Counters to track the Sensor's configuration polling requests to the NI device, including total requests, successes, failures, and specific errors like invalid tokens, timeouts, or gateway errors

  • Counters for the export of Netflow and Metadata, which include total POST requests, export successes and failures, various timeouts, and connection errors such as authentication failures or bad gateway responses

  • Counters that monitor the success and failure of creating the necessary Netflow and Metadata templates

  • Counters for the Sensor's internal data handling, including memory map (memmap) enqueue success and failure, discarded messages, and errors related to invalid data or system function failures

ninetflowstat

Some of the counters that have been added are the following:

  • Counters to track the lifecycle of memory buffers (mbufs) used for Netflow and Metadata, including successful allocations, frees, and their corresponding failures

  • Count of total Netflows and Metadata ring enqueue failures from l7ae to NI

  • Counters for other issues, such as Total Netflow send failed and Total Metadata invalid event type.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.11, which includes additional security against new vulnerabilities and bug fixes.

Apache Tomcat server upgrade

With this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.104. This server update provides a collection of security fixes.