The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Block DoS attack traffic from a specific host

Prev Next

This section provides the high-level steps, with examples, on how to block a host that is launching a DoS attack.

  1. Keep the inline Sensor in learning mode for 48 hours so that normal traffic pattern is learnt.

  2. Send some particular type of traffic from selected IP addresses through the Sensor during the learning mode, that is, for the first 48 hours.

    For example, send 5 Mbps of UDP packet type to the Sensor from selected IP address, such as 10.10.0.1, 198.19.0.2, 120.100.10.1, 100.10.10.11 and 99.40.10.30.

    Note

    The Sensor automatically switches to detection mode after the first 48 hours.

  3. Enable blocking for the corresponding attack in the DoS policy.

    For example, enable blocking for Inbound UDP Packet Volume Too High attack definition in the DoS policy.

  4. Set the maximum value on the Sensor using the CLI command: set dospreventionseverity <packet type> <direction> <value>

  5. Send significantly more similar traffic from the selected IP address through the Sensor than what was sent during the learning mode.

    For example, send more than 50 Mbps traffic from the IP address 10.10.0.1. Now, the traffic from the IP address 10.10.0.1 is blocked.