The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

New features

This release of the Trellix Intrusion Prevention System includes the following new feature:

Introducing Trellix Intrusion Prevention System Sensor - NS9600

This release of 11.1 introduces Trellix's next-generation IPS NS9600 Sensor model. The NS9600 Sensor operates at 20 Gbps, 40 Gbps, and 60 Gbps throughput depending on the license purchased. This release also offers the solution of stacking two NS9600 Sensors to achieve scalability. 120 Gbps throughput license is required for a NS9600 stack of 2 nodes to run.

The NS9600 Sensors are 1RU units equipped with the following components:

  • 4 QSFP28 /QSFP+ 100/40 Gigabit Ethernet ports in built-in G0 module

  • Three slots for pluggable and hot swappable I/O modules:

    • In G1 and G2:

      • 4-port 100/40 Gigabit SR MTP/MPO interface module

    • In G1, G2, and G3:

      • 6-port RJ45 10/1 Gigabit with internal fail-open interface module

      • 8-port 10/1 Gigabit SM (8.5 micron) with internal fail-open interface module

      • 8-port 10/1 Gigabit MM (50 or 62.5 micron) with internal fail-open interface module

    Caution

    Apart from the network interface modules mentioned above, no other interface modules are compatible with the NS9600 Sensor.

  • QSFP28 (MM and SM) and QSFP+ (MM and SM) transceiver modules are supported in NS9600 Sensor models.

    Note

    Transceiver modules are supported in the built-in G0 module only.

  • One console port

  • Two external USB ports for Storage/Rescue applications

  • One RJ-45 10 Gbps/1 Gbps Management port

  • One RJ-45 10 Gbps/1 Gbps Response port

  • The front and rear panel LEDs provide status information for the health of the Sensor and the activity on its ports

NS9600 licensing: In case of the NS9600 (standalone and in fail-over pair), a new license with a higher throughput is required to increase the throughput of the Sensor.

For NS9600 stack (2-node) or stacked Sensors in fail-over setup, you can combine multiple licenses of different capacity to achieve the throughput required and assign them to the stack. For example, you can import and assign any combination of licenses (20 + 40 + 60 Gbps) or, (60 + 60 Gbps) to achieve the throughput requirement of 120 Gbps. For more information, see Managing licenses in Trellix Intrusion Prevention System 11.1.x Installation Guide.

Unsupported features: Note that the following features are not supported in NS9600 Sensors:

NS9600 standalone

NS9600 stack (2-node)

  • Suricata Snort engine

  • Proxy-based SSL decryption (both inbound and outbound)

  • Suricata Snort engine

  • Proxy-based SSL decryption (both inbound and outbound)

  • SSL resumption for stack

  • Configure packet capture settings in span port

  • Import and export Sensor configuration

  • Denial of Service management, profiles, and filters

  • Allocating interfaces at child domain

For more detailed information, see Trellix Intrusion Prevention System NS9600 Sensor Hardware Guide and Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This release of the Trellix Intrusion Prevention System includes the following enhancements:

Support for RSA 4096-bit key self-signed and CA-signed certificates

Starting with this release of 11.1, trust between the Manager and Sensor could also be established by using self-signed and CA-signed certificates with a 4096-bit key.

For more information, see Managing Certificates for Manager and Sensor in Trellix Intrusion Prevention System 11.1.x Product Guide

Support for DNS response fields for layer 7 data collection

In 11.1 Minor 6 release, Trellix IPS provided support for the collection of layer 7 data for DNS request fields. In this release of 11.1, Trellix IPS extends its support for the collection layer 7 data for DNS response fields as well, and the export of DNS response based L7 metadata to other Trellix products, such as Trellix Network Investigator (NI).

You can navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection page and enable L7 data collection for DNS request and response fields per interface or sub-interface of selected Sensors.

Note

To view or customize both DNS request and response fields, you need to use Manager and Sensor that are running on 11.1 Update 7 release versions, and a compatible signature set (11.10.23.3 and above) with DNS related attack signatures.

For more information, Enable Layer 7 Data Collection for an interface or sub-interface in Trellix Intrusion Prevention System 11.1.x Product Guide.

Introduction of SmartVision attacks

Trellix IPS now includes SmartVision attacks, a new set of native IPS attack definitions. These attacks generate base events that allow for more comprehensive and effective detection and correlation of network activities and potential threats, particularly for the lateral movement, when the integration between Trellix IPS and Trellix NI is enabled.

SmartVision attack definitions are included in the IPS signature set and automatically added into the default IPS policies (except Default DoS and Reconnaissance Only policy) with severity levels set to Low and higher, when a compatible signature set is in use.

When a SmartVision alert/attack is detected in any customer network environment, Manager sends the relevant alert data in JSON format to Trellix NI. NI consumes and utilizes these base events that enable it to perform more effective threat detection and correlation.

Note the following when you start working with SmartVision attacks:

  • You need a Manager and Sensor running on 11.1 Update 7 versions or later, along with a compatible signature set (11.10.23.3 and above) that includes SmartVision attack signatures.

  • There should be successful integration between Trellix IPS and Trellix NI. The Manager sends SmartVision attack signatures to only those Sensors that have integration with Trellix NI enabled at the domain or device level.

  • After changing NI integration configuration in selected Sensors over the Client Group Association tab (at both domain and device levels), you must deploy configuration changes to the Sensor

  • You can configure and update the settings of SmartVision attacks in the Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS page. However, the Quarantine, Block, and Capture Packets (for Attack and Pre-Attack and Post Attack) sections are not available for configuration for the attack IDs related to SmartVision attacks in the Manager, as these options are disabled by the signature set.

For more information, see Harnessing SmartVision attacks for effective threat detection and response in Trellix Intrusion Prevention System 11.1.x Product Guide.

Terminology updates in the UI

Navigation Path

Prior to 11.1.7.111

11.1.7.111 and later

Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection

The page includes Flows and Protocols/Fields sections and associated configuration options with one Save button.

The page includes two tabs - Flows and Protocols. Each tab includes a corresponding Save button.

In the Protocols/Fields section of the page:

  1. You can Enable, Disable, or Customize to personalize the settings for a specific protocol.

  2. Click GUID-64007DBE-A893-4782-83D1-485E177DBBDE-low.png icon to view the corresponding fields of a specific protocol. All fields are enabled by default.

  3. To disable a specific field for any protocol, you must first select Customize.

On the Protocols tab of the page:

  1. Use the expand_all_button.jpg button to view or customize the associated fields of all protocols listed on the tab. All fields are collapsed by default.

  2. Click Arrow.jpg icon to view or customize the corresponding fields of a specific protocol. All fields are enabled by default.

  3. To disable a specific field for any protocol, deselect the associated check-box.