The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring the detection threshold for brute-force attacks (CLI)

Prev Next

When the IPS-enabled rules engine detects a certain number of failed login attempts to or from the same IP address occurring within a rolling 60‑second window, a brute-force attack is suspected. Based on this and other criteria, the rules engine determines whether the suspicious activity constitutes a brute-force event.

The system initializes with a default threshold value for detecting brute-force events. You can configure a higher threshold to reduce false positive IPS events.

Prerequisites
  • You are logged in to the IPS appliance as an Operator or Admin.

Procedure
To configure the detection threshold for brute-force attacks:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Check the current value of the threshold. In the following example, the feature is enabled with default values.

    hostname (config) # show ips reconnaissance
    Ping sweep threshold  : 20
    Port scan threshold   : 200
    Brute force threshold : 5
  3. Configure a new brute-force threshold value. In the following example, the threshold is raised to 10.

    hostname (config) # ips brute-force threshold 10
  4. Confirm your changes.

    hostname (config) # show ips reconnaissance
    Ping sweep threshold  : 20
    Port scan threshold   : 200
    Brute force threshold : 10
  5. Save your changes.

    hostname (config) # write memory