The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Considerations for Connection Limiting policies

Prev Next

Consider the following when you use Connection Limiting policies:

  • Threshold values defined in any rule are based on the source IP address.

  • A maximum of 1024 rules can be defined for each Sensor.

  • Traffic sample time for the connection rate monitoring is 10 seconds. This means if you define 5 connections per second, then, 50 connections are limited in 10 seconds. So, an alert will only be raised if you send more than 50 connections in 10 seconds.

  • In a fail-over setup, each Sensor monitors the traffic based on its own system time. As the system time for each Sensor differs, the time each Sensor samples a traffic might not be exactly same. This can result in a mismatch of the connection limiting response actions for each Sensor.

  • Each Sensor model has a limitation of a maximum number of new hosts that it can handle per second. When the new host rate exceeds this value, the connections are not limited by the Sensor.

  • Protocol based connection limiting rule type applies to both IPv4 and IPv6 traffic. Trellix GTI does not support IPv6 traffic, so GTI-based connection limiting rule type applies to IPv4 traffic only.

  • Connection Limiting rules can be applied to SPAN ports. If CIDRs are not defined for the SPAN port, inbound connection limiting rules are applied to all traffic on SPAN port. If CIDR is defined for the SPAN port, the traffic to the CIDR is treated as inbound traffic and traffic from the CIDR is treated as outbound traffic.

  • Trellix GTI IP Reputation has to be enabled for Trellix GTI rule type.

  • Connection Limiting is applicable for stateless inspection.

The following table shows the maximum host entries supported for different Sensor models.

Sensor

Maximum host entries supported

NS9600 stack (2-node) - 120 Gbps throughput

256,000

NS9600 standalone - 60 Gbps throughput

256,000

NS9600 standalone - 40 Gbps throughput

256,000

NS9600 standalone - 20 Gbps throughput

256,000

NS9500 stack - 100 Gbps throughput

256,000

NS9500 stack - 60 Gbps throughput

256,000

NS9500 stack - 40 Gbps throughput

256,000

NS9500 standalone - 30 Gbps throughput

256,000

NS9500 standalone - 20 Gbps throughput

256,000

NS9500 standalone - 10 Gbps throughput

256,000

NS9300, NS9200, NS9100

256,000

NS7600 - 20 Gbps

256,000

NS7600 - 15 Gbps

256,000

NS7600 - 10 Gbps

256,000

NS7600 - 5 Gbps

256,000

NS7500 - 7.5 Gbps

256,000

NS7500 - 5 Gbps

256,000

NS7500 - 3Gbps

256,000

NS7350, NS7250, NS7150

256,000

NS7300, NS7200, NS7100

256,000

NS5200, NS5100

128,000

NS3600 - 5 Gbps

256,000

NS3600 - 3 Gbps

256,000

NS3600 - 1 Gbps

256,000

NS3500

128,000

NS3200, NS3100

128,000

IPS-VM600

128,000

IPS-VM5000

128,000