When you submit samples for analysis through Trellix IPS, the source and destination IP information is swapped for the submitted samples.
To reverse the aberration caused by Trellix IPS, Intelligent Sandbox enables set IPAddressSwap command. This command nullifies the swap effect of Trellix IPS and displays the correct the source and destination IP information for samples submitted through Trellix IPS. When samples are submitted from Forcepoint NGFW to Intelligent Sandbox, the source and destination IP information are displayed correctly. Based on the preference, you can use the following command to enable or disable IPAddressSwap.
Syntax: set ipAddressSwap <enable><disable>
By default, set ipAddressSwap is enabled.
Example: set ipAddressSwap enable