The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Background

Prev Next

Each interface and subinterface has a unique ID called its "VIDS ID," and each VIDS ID is associated with the IPS policy that you apply to the corresponding interface or subinterface. Each IPS policy in turn, is associated with inbound and outbound attack set profiles, and each attack set profile contains a list of rules that determine whether attack definitions are to be included or excluded in your IPS policies. The Sensor must therefore track the VIDS ID and direction of each flow to eventually know which attacks (signatures, Reconnaissance, or DoS) to use when scanning it.

Note

Similar to IPS policy, a VIDS ID is associated with the other security policies that you have applied to the interface or subinterface.

Every time a new flow is established through a Sensor, information about the flow is added to the Sensor's state table. The state table includes standard connection tracking information, such as source and destination IP address/port, protocol ID, and TCP state and sequence numbers. Each state table entry also includes the VIDS ID and direction of the flow in question.

The VIDS ID and direction are determined at the outset of the connection, for example, by the SYN packet. The Sensor scans the entire flow using the attack signatures corresponding to the stored VIDS ID and direction. It does not apply the inbound attack set profile in one direction and the outbound attack set profile in the other.

The determination of VIDS ID and direction depends directly on the operational mode and interface type in question.