•
•
•
NS9500 Sensors
:
About Sensors
Trellix Intrusion Prevention System Sensors are high-performance, scalable, and exible content processing appliances built for
the accurate detection and prevention of:
Network intrusions
Network misuse
Distributed Denial-of-Service (DDoS) attacks
Trellix Intrusion Prevention System Sensors are specically designed to handle trac at wire speed, eciently inspect and detect
intrusions with a high degree of accuracy, and exible enough to adapt to the security needs of any enterprise environment.
When deployed at key network access points, the Sensor provides real-time trac monitoring to detect malicious activity and
respond to the malicious activity as congured by the administrator.
After you deploy a Sensor successfully, you congure and manage it using the Trellix Intrusion Prevention System Manager. The
process of conguring a Sensor and establishing communication with the Manager is described in subsequent chapters of this
guide. For the details about the Trellix IPS Manager, see the Manager Administration section in Trellix Intrusion Prevention System
Product Guide.
:
Functions of an NS-series Sensor
The NS-series Sensors are a third-generation hardware platform for Trellix IPS Sensors designed for high bandwidth links to
oer Next Generation IPS (NGIPS) capability and provide high aggregate throughput across various Sensor models. The NS9500
Sensor is a 1RU unit providing an aggregate throughput up to 30 Gbps.
The primary function of an IPS Sensor is to analyze trac on selected network segments and to respond when an attack is
detected. The Sensor examines the header and data portion of every network packet, looking for patterns and behavior in the
network trac that indicate malicious activity. The Sensor examines packets according to user-congured policies, or rule sets,
which determine what attacks to watch for, and how to respond with countermeasures if an attack is detected.
If an attack is detected, a Sensor responds according to its congured policy. Sensor can perform many types of attack
responses, including generating alerts and packet logs, resetting TCP connections, "scrubbing" malicious packets, and even
blocking attack packets entirely before they reach the intended target.
:
Deployment of an NS-series Sensor
Trellix Intrusion Prevention System NS-series Sensor Product Guide
| NS9500 Sensors1
16