The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure TTL and IP address for DNS sinkholing

Prev Next

When a Sensor detects a C&C server domain in a DNS response packet, the Sensor crafts a DNS response. You can configure the TTL for this crafted DNS response. The TTL value applies for both A and quad-A records. For A records, you can also configure the sinkhole IPv4 address.

  1. In the Manager, select Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → Protocol Settings.

  2. In the Protocol Settings page, scroll down to the DNS section.

  3. For DNS Sinkholing Time-To-Live (TTL) field, enter the TTL you want to include in the crafted DNS response packets sent by the Sensor.

    The default and the maximum values are 720 minutes.

  4. Click Update to save the changes in the Manager database.

  5. The DNS Sinkholing IP Address field indicates the IP address to which the bot traffic is sinkholed.

    The default value is the loop back IP address (127.0.0.1 for A records and ::1 for quad-A records present in the actual DNS response). You can configure an IPv4 address for the bot to send the bot traffic to that server. You cannot configure an IPv6 address as a sinkhole server IP address.

  6. Click Update to save the changes in the Manager database.

    Note

    The Manager sends any changes in the Protocol Settings page immediately to the Sensor through SNMP without the need for a manual configuration update.

    DNS settings
    DNS settings


  7. To restore all the fields in the Protocol Settings page to their default values and deploy the changes to the Sensor, click Restore.

    Important

    Restore applies to all the fields in Protocol Settings page and not just the DNS section.