LICENSEWARE

Trellix appliance, network and email security licensing

This article is about licence keys for Trellix appliances (Network Security, Email Security - Server, Endpoint Security (HX), Central Management and related products), virtual appliance licensing, Intrusion Prevention System capacity licences, Email Security - Cloud subscriptions and Helix.

On This Page

Trellix appliance licensing covers the network, email, endpoint and analysis appliances that Trellix sells as hardware, virtual appliances or cloud-hosted servers. It also covers the Intrusion Prevention System sensors and the Email Security - Cloud service. Unlike the node-counted endpoint products managed in ePolicy Orchestrator, appliances enforce their entitlement through named licence keys. The system administration guides say plainly that “License keys are required for system operation”.[1] Several keys carry a FIREEYE_ prefix.[1] The overview is in Trellix licensing.

Editions

The licence keys named for Network Security (NX), Email Security - Server (EX) and Endpoint Security (HX) appliances are:

Licence key Purpose Appliances Catalog 
FIREEYE_APPLIANCE “Required to register your system and use the product features”[1] All FIREEYE_APPLIANCE product license 
CONTENT_UPDATES Access to the Dynamic Threat Intelligence (DTI) network; one-way or two-way sharing[1] All CONTENT_UPDATES license (one-way or two-way sharing) 
FIREEYE_SUPPORT Software image updates and guest images; telemetry upload depends on sharing[1] All FIREEYE_SUPPORT license 
CLOUD_MVX Submission to Trellix Cloud MVX or a Private Cloud MVX[1] NX CLOUD_MVX license 
ATI (optional) Advanced Threat Intelligence; not supported on the SmartVision edition[1] NX ATI license 
MD_ACCESS (optional) Connection to the Managed Defense VPN[3] NX, HX MD_ACCESS license 
HX_ADVANCED (optional) Exhaustive Enterprise Search and bulk acquisition via the API; the “Power license”[3] HX HX_ADVANCED (Endpoint Security Power) license 
EMPS_ATTACHMENT_SCAN Submission of email attachments for analysis[2] EX EMPS_ATTACHMENT_SCAN license 
EMPS_URL_SCAN Submission of URLs in emails for analysis[2] EX EMPS_URL_SCAN license 

The functionality of every optional licence is disabled if the FIREEYE_APPLIANCE licence is invalid.[1] When an EX analysis licence expires or is deleted, attachments or URLs are still counted but no longer submitted for analysis.[2] The HX appliance shows warnings when licences have expired or will expire within 30 days.[3] Catalog: Appliances need a product licence; optional licences depend on it.

Metrics

The appliance metric is the appliance, physical or virtual, identified for virtual appliances by a unique appliance ID.[5] IPS sensors are licensed by throughput. Virtual IPS sensors use 1 Gbps licences.[12][14] Licences on IPS sensors record the customer, the Trellix Grant ID and the licence key. This makes the Grant ID the link between an appliance and the customer’s entitlement records.[13]

Counting / floors

Obtaining and installing keys

With the licence update feature enabled, an appliance “automatically download[s] and apply licenses to which you are contractually entitled”.[8] Without it, keys are installed manually. They come from the Assets tab of the Trellix Customer Support Portal, or from Trellix licensing on request with the appliance’s MAC address. Licences must be reinstalled when an evaluation or regular licence expires, and replacement licences are needed after a Return Material Authorization (RMA).[7] Catalog: The licence update feature applies only contractually entitled licences.

IPS capacity

NS-series sensors need a licence to activate their baseline throughput. A higher throughput needs a new, higher licence. NS9600 stacks may combine licences of different capacity, for example 20 + 40 + 60 Gbps for a 120 Gbps two-node stack.[12] Upgrade capacity licences are not available for NS9600, NS7600 and NS3600 sensors.[12] For older models, upgrading an existing capacity licence applies “only for Sensors running with perpetual licenses”. Demo licences cannot be upgraded, and an old licence cannot be re-imported after it has been replaced.[16] Catalog: IPS sensors are licensed by throughput capacity; Capacity upgrade licences apply only to perpetual sensor licences; NS9600 capacity licence.

Sensor Capacity licences named Source 
NS9600 20, 40, 60 Gbps (standalone or 2-node stack) [12] 
NS7600 5, 10, 15 Gbps [12] 
NS3600 1, 3, 5 Gbps [12] 
NS9500 10 Gbps baseline; licences to 20 or 30 Gbps [15] 
VM600 / VM5000 (virtual) 1 / 5 licences of 1 Gbps [14] 

Grace periods

Product Grace period Source 
IPS subscription System licences 30 days after expiry; afterwards the sensor keeps inspecting with existing signatures, but no new signature sets or policies can be deployed [15] 
Virtual appliance token None at first; 6 hours after 3 hours of continuous licensing; 3 days if Trellix determines the network cannot reach DTI [5] 
Email Security - Cloud 90 days to renew after licences expire [11] 

Catalog: Subscription sensor licences have a 30-day grace period; Email Security - Cloud has a 90-day grace period after expiry.

Virtualization & partitioning

A virtual appliance receives two secure emails. One holds the appliance ID, a unique activation code and the image download link. The other holds the licence keys.[5] The activation code gives the appliance its identity, activates the FIREEYE_APPLIANCE licence, grants access to the token server and the DTI network, and “Protects you from fraudulent use of the virtual appliance”. The appliance stays disabled until the code is applied.[6]

The product licence is held on a one-hour lease from a token server, which validates the appliance’s DTI credentials every hour. If the licence becomes inactive, malware detection is disabled.[5] The token server detects duplicate virtual appliances from the appliance ID, the virtual machine UUID and the last renewal request. It allows a brief overlap for a legitimate migration to another ESXi server, or for a backup and restore.[5] In practice a cloned virtual appliance does not create a second licence. Running a clone alongside the original is treated as duplicate use; this is an editorial reading of the duplicate-detection rule. Catalog: Virtual appliance licences are validated hourly by a token server.

From Manager 11.1.7.41, virtual IPS sensors need one licence for each VM600 and five for each VM5000 instance. Without the licence assignment, signature sets and policy updates cannot be deployed. Licences for clusters in the public cloud are not applicable.[14] The Manager’s Virtual Sensors tab shows Compliant or Non-compliant, the number of additional licences required, and a CSV export of licence usage.[13] Catalog: Virtual IPS: one licence per VM600, five per VM5000; VM5000; VM600.

Cloud / BYOL

Cloud Endpoint Security (HX) servers are deployed by Trellix “with appropriate Trellix licenses already established”. A single cloud ecosystem supports up to 100,000 agents.[9] Catalog: Cloud Endpoint Security (HX) servers come licensed by Trellix. Email Security - Cloud shows expiry banners 30 days before the last licence expires. If a customer tops up an initial bulk subscription later, a reduced-count banner appears as the earlier subscriptions lapse first.[11]

Helix. Appliances need no separate Trellix Helix licence. The “Helix tier: (not licensed for Helix)” line in the appliance’s version output can be ignored.[10] Catalog: Appliances carry no separate Trellix Helix licence.

Programs

Data sharing options

The CONTENT_UPDATES and FIREEYE_SUPPORT licences each come with a one-way or two-way sharing option. The Support option decides whether telemetry and statistics are uploaded. The Content Updates option decides whether security content and AV-Suite and FAUDE requests are uploaded.[4] With both licences on one-way sharing, nothing is uploaded to the DTI cloud.[4] This is an ordering choice with privacy consequences, so the sharing variant should be recorded with the entitlement. Catalog: One-way or two-way sharing licences determine what is uploaded to Trellix.

Support

FIREEYE_SUPPORT controls software image updates on the appliance.[1] Trellix’s general rule is that updates and upgrades require a current Technical Support agreement.[17] See Trellix License Management Services and support.

Out of scope

This page does not cover the Limited Hardware Warranty or hardware support logistics, Trellix Intelligent Sandbox licence counts per analysis image, or the pricing of capacity licences. It also does not cover Skyhigh Security appliances.

References

  1. About Trellix license keys (Network Security 11.x System Administration Guide)Updated 2023-12-13. Catalog: About Trellix license keys (Network Security 11.x System Administration Guide)Effective 2023-12-13. Retrieved 2026-10-02.
  2. About Trellix license keys (Email Security - Server 11.x System Administration Guide)Updated 2023-12-13. Catalog: About Trellix license keys (Email Security - Server 11.x System Administration Guide)Effective 2023-12-13. Retrieved 2026-10-02.
  3. About Trellix license keys (Endpoint Security (HX) 10.x System Administration Guide)Updated 2023-12-13. Catalog: About Trellix license keys (Endpoint Security (HX) 10.x System Administration Guide)Effective 2023-12-13. Retrieved 2026-10-02.
  4. About support and content license sharing combinationsUpdated 2023-12-19. Catalog: About support and content license sharing combinationsEffective 2023-12-19. Retrieved 2026-10-02.
  5. Understanding virtual appliance licensingUpdated 2023-08-10. Catalog: Understanding virtual appliance licensingEffective 2023-08-10. Retrieved 2026-10-02.
  6. Working with virtual appliancesUpdated 2025-10-14. Catalog: Working with virtual appliancesEffective 2025-10-14. Retrieved 2026-10-02.
  7. Manual license installationUpdated 2025-06-19. Catalog: Manual license installationEffective 2025-06-19. Retrieved 2026-10-02.
  8. On-premises appliance deployment steps (Endpoint Security (HX) 10.0.0 Deployment Guide)Updated 2025-02-19. Catalog: On-premises appliance deployment steps (Endpoint Security (HX) 10.0.0 Deployment Guide)Effective 2025-02-19. Retrieved 2026-10-02.
  9. Cloud server deployment steps (Endpoint Security (HX) 10.0.0 Deployment Guide, cloud)Updated 2026-02-26. Catalog: Cloud server deployment steps (Endpoint Security (HX) 10.0.0 Deployment Guide, cloud)Effective 2026-02-26. Retrieved 2026-10-02.
  10. Licensing requirements (Trellix Helix integration guide)Updated 2023-04-05. Catalog: Licensing requirements (Trellix Helix integration guide)Effective 2023-04-05. Retrieved 2026-10-02.
  11. Email Security - Cloud licensesUpdated 2025-12-23. Catalog: Email Security - Cloud licensesEffective 2025-12-23. Retrieved 2026-10-02.
  12. Managing Licenses (Intrusion Prevention System 11.1.x Product Guide)Updated 2025-03-26. Catalog: Managing Licenses (Intrusion Prevention System 11.1.x Product Guide)Effective 2025-03-26. Retrieved 2026-10-02.
  13. Virtual Sensors tab (Intrusion Prevention System 11.1.x Product Guide)Updated 2024-07-12. Catalog: Virtual Sensors tab (Intrusion Prevention System 11.1.x Product Guide)Effective 2024-07-12. Retrieved 2026-10-02.
  14. Managing licenses for Virtual SensorsUpdated 2025-09-30. Catalog: Managing licenses for Virtual SensorsEffective 2025-09-30. Retrieved 2026-10-02.
  15. Managing licenses for NS9500 SensorsUpdated 2024-01-29. Catalog: Managing licenses for NS9500 SensorsEffective 2024-01-29. Retrieved 2026-10-02.
  16. Upgrade an existing capacity licenseUpdated 2024-03-01. Catalog: Upgrade an existing capacity licenseEffective 2024-03-01. Retrieved 2026-10-02.
  17. License Management Services | TrellixCatalog: License Management Services | TrellixRetrieved 2026-10-02.

See also

Catalog Rows Cited

12SKUs11Rules3Metrics

Esc