The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Connection limiting with Trellix GTI integration enabled

Prev Next

You can define a threshold value to limit the number of connections per second or the number of active connections to prevent connection based DoS attacks.

The Sensor provides the ability to define threshold values to limit number of connections (three-way TCP handshakes) a host can establish. The number of connections or connection rate that is less than or equal to the defined threshold value is allowed. When this number is exceeded, the subsequent connections are dropped. This helps in minimizing the connection-based DoS attacks on server.

The threshold value is defined as the number of connections/second or active connections. For example, if you define 1 connection per second as the threshold value then, there are 10 connections in the first second, all the other connections from the second to the tenth second will be dropped. On the other hand, if you have 1 connection for each second, all the 10 connections until the tenth second will be allowed. This is also known as traffic sampling.

You can define the Connection Limiting rules of the following types:

  • Protocol — use this to limit TCP/UDP/ICMP active connections or connection rate from a host.

  • GTI — In this case, the Sensor integrates with Trellix GTI IP Reputation to obtain the reputation score and geo-location of the external host. Therefore, use this to define Connection Limiting rules for traffic to and from external hosts based on reputation and geo-location of the external hosts.