The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure Protocol Settings

Prev Next

You can customize the protocol parameters for a Sensor using the Protocol Settings page.

  1. Click the Devices tab.

  2. Select the domain from the Domain drop-down list.

  3. On the left pane, click the Devices tab.

  4. Select the device from the Device drop-down list.

  5. Select Setup → Advanced → Protocol Settings.

  6. To edit a parameter, type or select a new value and click Update for that parameter.

    To restore the default values, scroll down to the bottom of the page and click Restore.

    Caution

    To prevent system errors, Trellix recommends that only users with detailed knowledge of TCP configure these settings.

    Option

    Definition

    TCP

    TCB Inactivity Timer

    If a TCB (Transmission Control Block) does not receive any packets before this timer expires, the TCB is marked inactive. TCBs are limited, therefore inactive TCBs can be allocated to new session (or connections).

    TCP Segment Timer

    Time to wait for the out of order segments to become ordered before dropping them.

    TCP 2MSL Timer

    Time to wait for a connection control block to be freed before it is torn down. The maximum segment lifetime (MSL) is the amount of time that a packet can be in transit on the network.

    Cold Start Time

    When Sensor is first turned on, it does not have any flow information. Set the Cold Start Time to specify a window of time for the Sensor to allow packets without established control blocks to pass through.

    Cold Start Ack Scan Alert Discard Interval

    After a cold start, the Sensor will not alert for Ack Sweeps or Ack Scans until this interval (timer) expires.

    Cold Start Drop Action

    When starting a Sensor for the first time, you can decide to allow (forward) or drop all packets that do not have a flow control block recognized by the Sensor.

    • Forward Flows

    • Drop Flows

    TCP Flow Violation

    • Permit — For out-of-order packets, the Sensor holds packets up to (TCP Segment Timer) seconds for re-assembly before performing inspection. If re-assembly fails because some packets are still missing, the Sensor simply forwards the traffic. When the TCP state is not established, the Sensor allows the packets to pass through.

    • Deny — For out-of-order packets, the Sensor holds packets up to (TCP Segment Timer) seconds for re-assembly before performing inspection. If re-assembly fails because some packets are still missing, the Sensor drops the traffic. When the TCP state is not established, the Sensor drops the traffic.

    • Permit out-of-order — The Sensor allows out-of-order packets to continue to transmit without processing. When the TCP state is not established, the Sensor allows the packets to pass through.

    • Deny no TCB (Deny if State Not Established) — For out-of-order packets, the Sensor holds packets up to (TCP Segment Timer) seconds for re-assembly before performing inspection. If re-assembly fails because some packets are still missing, the Sensor simply forwards the traffic. When the TCP state is not established, the Sensor drops the traffic.

    • Stateless Inspection — The Sensor detects attacks without requiring a valid TCP state. This option should be used only when Sensors are placed in a network where the Sensors do not see all packets of a TCP flow like in an asymmetric network configuration. Stateless Inspection can only be implemented in IPv4 packets.

      When Stateless Inspection is enabled:

      • Firewall and syn cookie protection cannot be enabled.

      • HTTP redirection to the Remediation Portal may or may not work depending on your network deployment scenario for example, in a setup where SYN+ACK packets cannot be sent from the Sensor to the client.

    Normalization On/Off Option

    Sensor performs TCP/IP/ICMP options checking to normalize the traffic.

    TCP Overlap Option

    TCP segments may overlap, thus you need to select which data to process: the newer data or the older data.

    • New Data — Common for Linux, Solaris, HP_UX, and FreeBSD systems

    • Old Data — Common for Windows systems

    SYN Cookie

    SYN cookies are used to counter SYN flood attacks. With SYN cookies enabled, whenever a new connection request arrives at a server, the server sends back a SYN+ACK with an Initial Sequence Number (ISN) uniquely generated using the information present in the incoming SYN packet and a secret key. If the connection request is from a legitimate host, the server gets back an ACK from the host.

    • Disabled — Disable SYN cookies.

    • Inbound Only — Use SYN cookies for inbound traffic only.

    • Outbound Only — Use SYN cookies for outbound traffic only.

    • Both Inbound and Outbound — Use SYN cookies for inbound and outbound traffic.

    Caution

    • SYN cookie feature is not enabled by default.

    • Do not enable SYN cookies when passing MPLS traffic through a Sensor.

    • Sensors using SYN cookie settings must be in inline mode. If you don't have any ports in inline mode, configure at least one port to be inline.

    • A Sensor will only see a packet once on any interface. However, if a Sensor is monitoring an interface containing VLAN-tagged traffic, a separate subinterface must be configured for each VLAN to ensure a packet is not seen more than once.

    Inbound Threshold Value

    The number of incomplete SYNs beyond which SYN cookies have to be enabled for an incoming connection.

    Outbound Threshold Value

    The number of incomplete SYNs beyond which SYN cookies have to be enabled for an outgoing connection.

    Reset unfinished 3 way handshake connection

    When enabled, automatically sends a TCP RST to the source when the TCP SYN timer has expired for a connection.

    • Disabled

    • Set for all traffic

    • Set for DoS attack traffic only

    UDP

    Supported UDP Flows

    Number of UDP transmissions allowed per Sensor. This varies for each Sensor model. The default number of UDP transmissions that is supported is displayed, which you can change.

    See the NS-series Sensor capacity by model number for the default and maximum number of supported UDP flows for each Sensor model.

    Unsolicited UDP Packets Timeout

    Time to wait to receive a response packet for a sent packet. If time not met, the packet is dropped.

    DNS

    DNS Sinkholing Time-To-Live (TTL)

    The TTL to be included in the crafted DNS response packets sent by the Sensor.

    Note

    The default and the maximum values are 720 minutes.

    DNS Sinkholing IP Address:

    The IP address to which the bot traffic is sinkholed.

    Note

    The default value is the loop back IP address (127.0.0.1 for A records and ::1 for quad-A records present in the actual DNS response). You can configure an IPv4 address for the bot to send the bot traffic to that server. You cannot configure an IPv6 address as a sinkhole server IP address.

    FTP

    FTP Acceleration

    Set the fast forward FTP data flows feature.

    HTTP2

    Flow Allocation %

    Set the maximum HTTP2 flows as a percentage of total supported flows. This value differs for each Sensor model.

    • For NS7500 and NS3600, it can range between 1% to 5%.

    • For NS9500 and NS7600, it can range between 1% to 10%.

    Note

    The Sensor requires a reboot after updating the flow allocation.

    Include decoded packets in attack packet log

    While inspecting HTTP2 traffic, the Sensor decodes the HTTP2 packets/frames into HTTP requests/responses. By enabling this, the Manager will include decoded HTTP requests/responses along with HTTP2 packets/frames in the attack packet log.

    Slowloris Attack Configuration

    Allows you to configure the values for the following parameters:

    • Slow Post Timeout - Set the value between 5 and 30.

    • Slow Post Threshold Frame Size - Set the value between 1 and 100.

    • Slow Post Minimum Number of Streams - Set the value between 50 and 100.

    • Slow Post Min Number of Tiny Frames - Set the value between 1 and 10.

    • Slow Read Timeout - Set the value between 30 and 300.

    • Slow Read Window Size - Set the value between 1 and 100.

    • Slow Read Minimum Number of Streams - Set the value between 50 and 100.

    Note

    Users are recommended to modify these settings only in consultation with Trellix support team.