The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

New features

This release of Trellix Intrusion Prevention System includes the following new feature:

Support for HTTP2 based traffic inspection

Starting with this release of 11.1, the Trellix IPS supports HTTP2 inspection for the following scenarios:

  • HTTP2 Prior Knowledge

  • Externally decrypted HTTP2 over TLS

Note

HTTP2 upgrade (h2c) scenario is not supported.

When you install/upgrade the Manager, by default, HTTP2 traffic inspection is not enabled. You can enable HTTP2 traffic inspection at both Global and Devices level in the Manager.

Few points to consider prior to enabling the HTTP2 traffic inspection:

  • The Sensor requires a reboot when you enable or disable HTTP2 Traffic Scanning. You can check the Sensor reboot status from Device Manager or status CLI.

  • HTTP2 Traffic Scanning can be enabled only when HTTP Response Traffic Scanning is enabled.

  • HTTP2 Server Push Traffic Scanning can be enabled only when HTTP2 Traffic Scanning is enabled.

  • HTTP2 traffic inspection requires a sigset with HTTP2 features.

  • Only NS7500 and NS9500 Sensors support HTTP2 traffic inspection.

  • HTTP2 performance numbers align with HTTP 1.1 for the supported Sensor models.

For more information, see How to enable HTTP2 in Trellix Intrusion Prevention System 11.1.x Product Guide.

The following Sensor CLI commands are included:

Normal Mode

Command

Description

show h2 config

Displays details related to HTTP2 status, flow allocation, and decoded packet status.

show h2 connections

Displays statistics details related to HTTP2 context connections.

show h2 frames

Displays multiple frames counter details and settings-frames statistics.

show h2 header-decoder

Displays the HTTP2 header block decode status.

show h2 resource

Displays statistics details related to available and total allocations of HTTP2 resources.

show h2 streams

Displays statistics details related to HTTP2 streams.

For more information, see IPS CLI Commands - Normal Mode in Trellix Intrusion Prevention System 11.1.x Product Guide.

The following Sensor CLI command is updated:

Debug Mode

Command

Description

show feature status

Displays the enable/disable status for a certain features.

For more information, see IPS CLI Commands - Debug Mode in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This release of Trellix Intrusion Prevention System includes the following enhancements:

Defining and enforcing user-specific blocking strategy to make self-adaptable IPS policies

Previously, if users wanted any attack to be blocked as per their blocking strategy, they had to identify all matching attacks during IPS Policy configuration, bulk edit them, and manually set the Sensor Actions to Enable Blocking. Also, they had to identify the attack signatures that were added or modified in a new signature set release and reconfigure their IPS policies to enable the Sensor blocking response action for the attack signatures that matched their blocking criteria.

Starting with this release of 11.1, Trellix IPS Manager offers a more simplified and automated IPS policy management mechanism for blocking attacks. It enables users to define and store one or more customizable rules for blocking attacks as per their network requirements during attack set profile configuration. When the same attack set profile is used in the IPS policy, the Manager automatically correlates the blocking criteria set by the user with the new and existing attack signatures. This enables IPS policies to automatically block attacks that match the user's blocking strategy and makes them self-adaptable to any new signature set release.

This automated IPS policy management for blocking attacks minimizes the need to manually edit the IPS policies for the blocking of attacks. Moreover, as the attack set profile mapped to the IPS policy stores the user-defined blocking criteria for attacks, it is automatically applied to any new/modified attack definitions included in any signature set update that match the set criteria. This eliminates the requirement of repeated manual intervention and provides user-customizable and automated attack blocking mechanism that helps users maintain their network security posture.

You need to perform the following steps to automate the process of blocking attacks in the Manager and Sensor:

  • Create or edit an attack set profile that includes rules for blocking attacks as per your blocking strategy. On the Attacks to Block tab during attack set profile configuration, you can create one or more rules with the categories, subcategories and minimum severity level of attacks that you want to be explicitly blocked by the Sensor.

  • Once the attack set profile with your blocking criteria is configured, you can use the same attack set profile during IPS policy configuration. Double-clicking any attack that falls under your blocking criteria and is set to be automatically blocked shows the Block field under Sensor Actions - Response to be Inherit (Enable Blocking). This Sensor response action is only visible for attacks that are set to be automatically blocked in the selected attack set profile.

    Important

    If you wish, you can override the automatic blocking behavior of any attack by manually setting the Sensor blocking action during IPS policy configuration. Sensor response actions customized in the IPS policy always takes precedence over automatic blocking of attacks criteria set in the Attack Set Profiles page.

  • Once the desired IPS policy is mapped to the attack set profile that includes the rules for attack blocking, you need to enforce the IPS policy at the interface and sub-interface level for the required Sensor(s).

  • You need to then deploy these configuration changes to the required devices in the admin domain level or at a device level.

When the policy and rule updates are applied to the required Sensor(s), those automatically block all attacks that match your blocking criteria as set in the attack set profile and send an alert to the Manager.

Note

  • Automating the blocking of attacks as per user-defined blocking strategy is available in both Trellix IPS Manager and Central Manager from 11.1 Update 3 release onwards.

  • The default or preconfigured attack set profiles are read-only. So, the rules for blocking can be created for custom attack set profiles only.

For more information, refer to the section Defining and using user-customizable blocking strategy to make self-adaptable IPS policies in Trellix Intrusion Prevention System 11.1.x Product Guide.

Forwarding MITRE Attack Details to Syslog and SNMP servers

Starting with this release of 11.1, users can configure the Manager to forward MITRE attack details to Syslog and SNMP servers. The variables introduced to forward MITRE attack details are IV_TACTIC, IV_TECHNIQUE, IV_SUBTECHNIQUE, and IV_TTPID. Users can choose the appropriate variables while configuring the Notification Profile.

For more information, refer to the section Add a Syslog notification profile to forward alerts in Trellix Intrusion Prevention System 11.1.x Product Guide.

IPS CLI enhancements

The following Sensor CLI command is updated:

Debug Mode

Command

Description

show acl stats

Displays the count of packets matching the Stateless ACL rule which skipped the proxy engine.

Note

This counter appears in the output only when SSL Decryption on Inbound/Outbound traffic is enabled.

For more information, see IPS CLI Commands - Debug Mode in Trellix Intrusion Prevention System 11.1.x Product Guide.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.14 that includes additional security against new vulnerabilities.

JDK upgrade

Starting with this release of 11.1, the IPS Manager uses JDK version 8u372 that includes additional security against new vulnerabilities.