The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

New features

This Trellix Intrusion Prevention System release includes the following new features:

Trellix Operating System on Manager Appliance

This release of 11.1 introduces the Manager appliance running on the Trellix operating system. The Manager Appliance runs on a pre-installed, hardened Trellix operating system and comes pre-loaded with the Manager software. You can deploy this Linux-based Manager as virtual machines in your ESX, KVM, and Nutanix servers.

The IPS Manager physical appliance now uses refreshed hardware that offers improved storage and performance. This enhancement provides better support for a large volume of alerts.

The Manager appliance uses a 1U rackmount unit, and the size is defined by its standard rack unit height and physical dimensions.

Trellix OS hardware specifications

Parameter

Description

Regulatory Model Name

SYS-121C-TN10R

Model

Trellix Intrusion Prevention System Manager

Device Type

Manager for NS-Series sensors

Form Factor

1U

Dimensions

23.5 inches (Depth) x 17.2 inches (Width) x 1.7 inches (Height)

Weight

11.8 Kg

Power

100 - 127VAC / 50-60Hz

200 - 240VAC / 50-60Hz

Typical Power Consumption

150W

Maximum Power Consumption

300W

Temperature

Operating Temperature: 10°C to 35°C

Non-Operating Temperature: -30°C to 60°C

CPU

Supports 1X Intel (R) Xenon (R) Silver 4510

2.4 Ghz

12C

1 per system

Hard Drive

3.2 TB

Enterprise class NVMe drive

PCIe Gen4x4

2 per system

DVD ROM

None

DIMM

64 GB

DDR5

5600 MHz

LAN Ports

2 x 10 Gbe, RJ45

USB Ports

2 x USB 2.0 Type-A ports on front panel and 2 x USB 3.0 ports Type-A ports on back panel

Video

DB-15 HD VGA on the back panel

Serial Port

DB9 on the back panel



For hardware-related information, see Trellix Intrusion Prevention System Manager Appliance Hardware Guide.

Migrating the Manager appliance from 11.1 Update 9 version to 11.1 Update 10 (Trellix OS) version

You must follow the warnings below and perform the mandatory actions before and after migration.

This upgrade migrates MLOS to Trellix OS. It is intended for IPS Manager physical appliances only.

Warning

This is not a regular upgrade. The entire DISK will be FORMATTED, and a fresh Trellix OS will be imaged onto the disk. All data will be lost, including Network configurations, backups, and any local appliance customization or hardening.

MANDATORY ACTIONS BEFORE MIGRATION:

  • Documentation Review: You must carefully read the mandatory steps under the "Migration Procedures" section in the MLOS to Trellix OS migration document.

  • The latest available Signature Set must be applied to the MLOS appliance.

  • Backup: Ensure the "All Table Backup" from MLOS is taken, along with necessary file backups, and moved to an external disk.

  • Customization: All customization done on this setup must be carefully documented, as they need to be repeated post-migration.

MANDATORY ACTIONS POST MIGRATION:

  • The "All Table Backup" must be manually restored on the setup.

  • The list of files specified in the "Migration Procedures" section must be replaced.

  • Ensure the latest available Signature Set is present in the appliance. Please reach out to the support team if you need assistance.

For more information, see Migrating from 11.1 Update 9 MLOS Manager Appliance to 11.1 Update 10 Trellix OS Manager Appliance in Trellix Intrusion Prevention System Manager Appliance Hardware Guide.

For VM instances deployment, refer to Prepare for 11.1 Update 10 Trellix OS Manager fresh virtual machine instance deployment in Trellix Intrusion Prevention System 11.1.x Installation Guide.

For simplicity of usage and security, with this release, Manager shell commands with the Trellix operating system are introduced. The shell commands allow you to configure and view the Manager configuration and network information. For more information, see Trellix OS Manager Shell Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhanced protection with STIX-based threat intelligence feeds

Starting with this release of 11.1, Trellix IPS enables you to leverage external threat intelligence data from third-party providers to strengthen your network defenses. You can import JSON-based STIX files from third-party providers to Manager and Central Manager and use the included Indicators of Compromise (IoCs) to proactively monitor and block malicious activity on your network.

Trellix IPS supports importing the following IoC types from STIX files - IPv4 and IPv6 endpoints, IPv4 and IPv6 CIDRs, Domains, URLs, and file hashes (MD5 and SHA-256). Sensors use the IoC types to inspect and block the network traffic as per configuration -

  • IPv4/IPv6 endpoints and CIDRs: Traffic is blocked, and alerts are forwarded to the syslog server configured for firewall access rule logging.

  • Domains, URLs, and file hashes: Traffic is blocked (per IPS/ Advanced Malware policy), and an alert is generated in the Attack Log.

Configuring threat feeds in Trellix IPS: Perform the following steps to configure and use threat feeds in Trellix IPS.

1. Configure threat feed in the Manager

On the Policy → <Admin Domain Name> → Threat Intelligence → Feed Configuration page:

  1. Create and import a feed: Upload the JSON file and configure the required fields in the Configure Feed tab.

  2. Customize the IoC values: Upon saving the threat feed, you can view and exclude one or more imported IoC values for each IoC type from the IoC Values tab. The excluded values appear on the Exclusions tab.

  3. Assign the feed to Sensors: After the configuration of the threat feed, you must assign it to one or more Sensors from the Device Assignments tab.

2. Configure Sensor alert logging for threat feeds based on IoC types

  • IPv4/IPv6 endpoints and CIDRs: Configure a syslog server using the Firewall Access Logging Page in the Manager to log the alert messages.

  • Domains, URLs: Add or update an inspection policy and do the following -

    • Enable Layer 7 Data Collection in the required direction on the Traffic Inspection tab.

    • Enable URL Reputation Analysis from the GTI Reputation Services tab, and assign the policy to the required Sensor(s).

  • File Hash: Create an advanced malware policy, select the required file types for Threat feed / Local Block List malware engine, and assign the policy to the required Sensor(s).

For more information, see STIX-based threat intelligence feed support for enhanced protection in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This Trellix Intrusion Prevention System release includes the following enhancements:

Extending IPv6 support in Trellix IPS

With this release of 11.1, IPv6 support has been extended across Trellix IPS components, such as IPS Manager, Central Manager, IPS Sensors, and their functionalities. This enhancement enables significant management, threat detection, analysis, and administrative capabilities within IPv6 network environments.

  • You can access IPS Manager and Central Manager web-based user interfaces (UI) via IPv6 addresses. This is applicable to Windows-based Manager and Manager appliance with Trellix operating system.

  • You can assign IPv6 addresses to IPS Sensors. This is applicable to all NS-series and virtual Sensor models.

  • IPv6 support has been extended to Managers and Central Managers in MDR pair, and Sensors in stack setup (applicable only to NS9500 and NS9600) and Sensors in fail-over configuration.

  • You can now configure IPv6 geolocation-based firewall rules. However, when you configure IPv6 firewall rules, you must configure one field (Source Address or Destination Address) as a country, and the other as a country along with any other rule object, such as IPv6 Endpoint or IPv6 Network to ensure IPv6 geolocation-based traffic detection.

    Important

    Configuration of IPv6 geolocation-based firewall policy in an environment in which you have a Manager with 11.1 Update 10 version and Sensor(s) running on 11.1 Update 9 or lower is not supported. Policies containing IPv6 GeoDB rules must not be applied to these Sensors, as it might result in signature set push failure.

  • Integration with Trellix Network Investigator is supported in IPv6 environment.

IPv6-compatible features and functionalities in Trellix IPS

Inbound and outbound SSL decryption

Database maintenance - backup, pruning, and tuning, alert archival

Firewall policies

Trellix IPS custom attack definitions and Snort signatures

Jumbo frame parsing

Inspection policies

Layer 7 data collection (except SMB and DCERPC)

Malware policies (compatible Malware engines - Threat feed / Local Block List, IVX and PDF)

IPv6 proxy server configuration

IPv6 email server configuration

IPv6 Active directory and trusted domain controller configuration

IPv6 TFTP server configuration

NMS clients

IPv6 SCP server configuration

Connection limiting policies

CA migration with IPv6 address

HTTP2 traffic inspection

HTTP POST

Event logging for public GTI certificate bundle downloads

Starting with this release 11.1, the Manager now logs events when it downloads client certificate bundles for public GTI IP and URL reputation from the Trellix IPS Update Server. You can review these events on the Manager → <Admin Domain Name> → Troubleshooting → Logs → User Activities tab to verify if the download was successful or failed.

For more information, see Configuring Trellix Global Threat Intelligence server for URL and IP Reputation in Manager in Trellix Intrusion Prevention System 11.1.x Product Guide.

Increased default value for alert suppression window

Until the 11.1 Update 10 release, the default value for alert suppression window was 120 seconds. Starting with the 11.1 Update 10 release, the default value is 24 hours. You can configure this value in seconds, minutes, or hours.

This enhancement is not supported for NS7100, NS7200, NS7300, NS9100, NS9200, and NS9300 Sensors.

Terminology updates in the UI

Navigation Path

Prior to 11.1.7.154

11.1.7.154 and later

Policy → <Admin Domain Name> → Policy Types → Advanced Malware

Malware engine is named as Allow and Block Lists.

Malware engine is renamed to Threat feed / Local Block List.

Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions

The option available: Outbound SSL Decryption Exclusions.

The option is renamed to SSL Decryption Exclusions.

IPS CLI enhancements

The following Sensor CLI commands are included:

Normal Mode

Command

Description

show alert-throttle config

This CLI command displays the current configuration settings for alert throttling.

show alert-throttle stats

This CLI command displays operational statistics for alert throttling, including various counters for resource allocation failures.



The following Sensor CLI commands are updated:

Normal Mode

Command

Description

show malwareenginestats

This CLI command now shows malware statistics of the IOC threat feed engine.



Debug Mode

Command

Description

show geoloc ip

This CLI command enables users to lookup the geographical location for a specified IPv4 or IPv6 address. It replaces the show geoloc v4 command.



Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.14, which includes additional security against new vulnerabilities and bug fixes.

OpenSSH security update

Starting with this release, the OpenSSH package on Sensor is patched to include the fix associated with CVE-2025-32728.