The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Block DoS attacks in Attack Log

Prev Next

All attacks, except ICMP echo anomaly and TCP control anomaly, can be configured to be blocked from within the Attack Log.

Steps:

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.

  2. Select the DoS alert for which you want to enable blocking and click Other Actions.

  3. Select Update Policy, and click (Domain IPS) /<Admin Domain Name>/<Policy Name> or (Interface IPS) /<Admin Domain Name>/<Device Name>/<Interface>.

    The <Attack Name> panel opens.

  4. Under the Appliance Action section, select Enable DoS Blocking for Block.

  5. Click Update.

    The respective policy is updated with the DoS blocking for the attack selected.

    Blocking attacks in Attack Log
    Blocking attacks in Attack Log