The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Managing network interfaces

Prev Next

Communicating with devices uses the public and private interfaces of the traffic paths. This means that the device is invisible in the network because it doesn't require an IP address.

Management interface

Alternately, network administrators can configure a management interfaces with IP addresses for communication between Trellix ESM and the device. These device features require the use of a management interface:

  • Full control of bypass network cards

  • Use of NTP time synchronization

  • Device-generated syslog

  • SNMP notifications

Devices equipped with at least one management interface gives the device an IP address. With an IP address, Trellix ESM can access devices directly without directing communication toward another target IP address or host name.

Important

Do not attach the management network interface to a public network because it's visible to the public network and its security could be compromised.

Trellix ESM interface bonding

Trellix ESM tries to auto-enable bonded NIC mode when it detects two management interfaces that both use the same IP address. Ethernet bonding allows two (or more) ethernet interfaces to be combined so that they act like a single ethernet link. This allows for load sharing, load balancing and fault tolerance. When bonded mode is enabled, both interfaces are assigned the same IP address and MAC address. By default, the bonding mode used is mode 0 (round-robin), which provides fault tolerance.

To disable NIC bonding, change the IP address of one of the interfaces so that it no longer matches the other. The system then automatically disables bonded NIC mode.