The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Connection Limiting policies

Prev Next

Connection Limiting policies consist of a set of rules that enable the Sensors to limit the number of connections a host can establish or a connection rate.

The Sensor provides the ability to define threshold values to limit number of connections (three-way handshakes for TCP) a host can establish. The number of connections or the connection rate that is less than or equal to the defined threshold value is allowed, whereas the same exceeding the value is dropped. This helps in minimizing connection-based DoS attacks on your network.

The integration of this technology with Trellix GTI IP Reputation helps to define the connection limiting rules for traffic to and from external hosts based on reputation and geographical-location of the external hosts. These defined Connection Limiting policies can also be assigned at the interface and subinterface levels.

Examples:

  • When 100 active HTTP connections are limited from a single source, subsequent connections are dropped.

  • When 500 active overall connections (all TCP and UDP) are limited from a single source, subsequent connections are dropped.

  • When 200 DNS requests per second are limited from a single source, subsequent connections within this time interval are dropped.

NS-series Sensors provide capability to limit the number of connections a host can establish or a connection rate.

The policy specifies connection rules of following two types:

  • Trellix GTI based to limit connection rate based on reputation and/or geo location of external hosts.

  • Protocol based to limit TCP/UDP/ICMP connections or connection rate from a host.

Both the above-mentioned rules are specified on a per direction basis. The connection policy is assigned to interface or subinterface level. Trellix GTI-based rules are only applicable when IP Reputation is enabled on the interface or subinterface level. They query the IP Reputation server to get reputation and geographical location of the external host.

Note

In case of Trellix GTI-based rules, connection limiting is applicable only to IPv4 traffic. Protocol-based rules are applicable for both IPv4 and IPv6 traffics.