Intrusion Prevention System
Signature and signature-less IPS that holds line rate up to 100 Gbps.
Trellix Intrusion Prevention System (IPS) is a next-generation IDPS that layers multiple signature and signature-less detection engines to block sophisticated malware, DoS, and zero-day attacks across the network. It scales past 30 Gbps in a single device and to 100 Gbps stacked, without the throughput collapse that hits other IPS solutions under strict policy. Faltrox tunes and operates it as part of your managed defence.
Overview
What Intrusion Prevention System is
Trellix Intrusion Prevention System (IPS) is a next-generation intrusion detection and prevention system that layers multiple signature and signature-less detection engines to block sophisticated malware, DoS, and zero-day attacks inline. It moves beyond traditional pattern matching with full protocol analysis, threat reputation, and behavioural analysis, so it stops the stealthy attacks that evade signature-only defences.
It scales past 30 Gbps in a single device and to 100 Gbps stacked, and — unusually — preserves performance regardless of security settings, where many IPS products lose up to half their throughput under strict policy. It was the first IDPS to combine threat prevention with Layer 7 visibility of over 2,000 applications, and integrates with Trellix Intelligent Sandbox, ePO, and Enterprise Security Manager. Faltrox tunes and operates it as part of your managed defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
High-Throughput Networks
Line-rate inspection from 30 Gbps in one device to 100 Gbps stacked, without a throughput cliff.
Data Centre & Perimeter
Inline protection for internet-facing perimeter and east-west data-centre traffic.
Encrypted Traffic
Inbound and outbound SSL decryption inspects encrypted flows with no sensor performance impact.
2,000+ Applications
Layer 7 visibility of over 2,000 applications and protocols informs what you allow on the network.
DoS & DDoS
Threshold, heuristic, and self-learning detection defend availability alongside confidentiality.
Botnet C2
DNS/DGA callback detection, sinkholing, and a C2 database break the attacker’s path home.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Inspect
A single-pass, protocol-based inspection architecture on carrier-class hardware performs deep inspection without collapsing throughput.
- 02
Detect
Multiple signature and signature-less engines combine full protocol analysis, threat reputation, and behavioural analysis to identify threats.
- 03
Verdict
Integration with Trellix Intelligent Sandbox validates suspect files, reducing the false alerts that plague signature-only IPS.
- 04
Block
Confirmed attacks are blocked inline at line rate, with host quarantine and rate limiting for risky hosts.
- 05
Correlate
Integration with ePO and Enterprise Security Manager adds device, user, and posture context for real-time event correlation.
Capabilities
Key capabilities
Multi-Engine Detection
Full protocol analysis, threat reputation, and behavioural analysis combine with signature matching to detect malware callbacks, DoS, and zero-day attacks that evade traditional pattern matching.
Line-Rate Performance
Single-pass, protocol-based inspection on carrier-class hardware holds real-world inspection up to 100 Gbps, and preserves performance regardless of security settings — where rivals can lose up to 50% throughput under strict policy.
Application Awareness
The first IDPS to combine threat prevention with Layer 7 visibility of 2,000+ applications and protocols, so you decide what runs on your network from evidence, not assumption.
Inbound & Outbound SSL Decryption
Inspects encrypted traffic with Diffie-Hellman and ECDH cipher support via an agent-based shared-key solution, with no impact on sensor performance and no extra licence.
Intelligent Sandbox Integration
Integrates with Trellix Intelligent Sandbox for static code analysis, dynamic malware sandboxing, and machine learning that catches evasive zero-days and ransomware.
DoS / DDoS Prevention
Threshold and heuristic detection, host-based connection limiting, and self-learning profile-based detection defend availability alongside confidentiality.
Botnet & Callback Protection
DNS/DGA fast-flux callback detection, DNS sinkholing, heuristic bot detection, and a command-and-control database break the attacker’s path home.
High Availability
Active-active and active-passive modes with stateful failover, external and built-in fail-open, and disaster recovery of critical configuration — so inline protection does not become a single point of failure.
Specifications
Technical detail
- Single-Device Throughput
- More than 30 Gbps
- Stacked Throughput
- Up to 100 Gbps (NS9500 stacking)
- Appliance Series
- NS7500 and NS9500; virtual appliances available
- Application Visibility
- Layer 7 for 2,000+ applications and protocols
- Signatures
- Trellix, user-defined, open-source, and native Snort (NS-series)
- Management
- IPS Manager — tiered management up to 1,000 sensors; RADIUS/LDAP
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Intrusion Prevention System for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Will turning on full security policy tank our throughput?
That is the specific weakness Trellix IPS claims to avoid. Its single-pass architecture preserves performance regardless of security settings, where many IPS products lose up to 50% throughput when you prioritise security over speed. You do not have to choose between coverage and line rate.
02Can it inspect encrypted traffic?
Yes — inbound and outbound SSL decryption is included, supporting Diffie-Hellman and elliptic-curve ciphers through an agent-based shared-key approach with no sensor performance impact and no additional licence fee.
03Does it work with our existing Snort rules?
The NS-series has native support for Snort signatures alongside Trellix, user-defined, and open-source signatures, so existing rule investment carries over rather than being thrown away.
04How does it scale as our network grows?
The NS7500 and NS9500 let you buy for today and scale throughput later via a software licence, and you can stack multiple NS9500 appliances to add capacity — up to 100 Gbps — without a forklift replacement.
05How is this different from Network Security or NDR?
IPS is inline prevention — it blocks known and signature-detectable attacks at line rate. Network Security adds signature-less MVX sandbox detection behind it, and NDR adds encrypted-traffic detection and response. They layer; Faltrox scopes which combination your traffic and risk profile need.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us