The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Components of Connection Limiting rules

Prev Next

You define Connection Limiting rules in a Connection Limiting policy. To effectively use Connection Limiting policies, familiarize yourself with the components that make up a Connection Limiting rule.

Connection Limiting rules options


Connection Limiting rules option definitions
Option Definition
# Displays the serial number of the rule. This is referenced in the alerts.
State Displays whether a rule is enabled or disabled. Sensor does not apply disabled rules. This option might help you during troubleshooting.
Description Optionally enter additional information about the rule. You can enter a description up to 64 characters long and click OK.
Direction
  • Inbound — To apply this rule only to traffic seen at the outside port.
  • Outbound — To apply this rule only to traffic seen at the inside port.
  • Any — To apply this rule at both the ports.
Rule Type
  • Protocol — To limit TCP/UDP/ICMP active connections or connection rate from a host.
  • GTI — To limit connection rate based on reputation and/or geo-location of external hosts.

    Note

    Trellix GTI-based rules are only applicable when Trellix GTI IP Reputation is enabled.

Note

Both the rule types are specified on a per-direction (inbound/outbound) basis.

Threshold Type :
  • Connection Rate — The rate of the connection defined per second.
  • Active Connections — The number of active connections.

    Note

    Only Connection Rate is available for Trellix GTI rules.

Value: Define the connections per second or the number of active connections based on the threshold type you selected.

External Reputation : Select one of the external Trellix GTI reputations (risk levels):
  • High Risk
  • Medium Risk or High Risk
  • Unverified, Medium or High Risk
  • Any

    Note

    This option is applicable only for Trellix GTI rule type.

Location : Select the external geo-location (Trellix GTI countries).

Note

This option is applicable only for Trellix GTI rule type.

Service Select one of the following transport protocols from the Transport Protocol drop-down list:
  • TCP (You can specify the port number for TCP protocol.)
  • UDP (You can specify the port number for UDP protocol.)
  • Ping (ICMP echo Request)
  • All TCP & UDP
    Service option


Note

Service component is only applicable for protocol rule type.

Response Select the response action that the Sensor must perform when the traffic matches the options you specified in the Connection Limiting rule. The following are the response options:
  • Alert Only
  • Alert & Drop Excess Connection
  • Alert & Deny Excess Connection
  • Alert & Quarantine
Prompt for assignment after save

When selected, the Assignments window opens when you save a policy and you can assign the policy to the required Sensor resources. When deselected, the rule is saved in the Manager database and the policy appears in the Connection Limiting list.

Save Saves the Connection Limiting rules in the Manager database. The Connection Limiting policy is listed in the Connection Limiting list.