Follow these considerations for the rule types.
For Protocol rule type:
In one policy, for one direction, only one All TCP/UDP connection rate rule can be defined.
In one policy, for one direction, only one All TCP/UDP active connection rule can be defined.
For Trellix GTI rule type:
For Trellix GTI connection rate rule, geo-location and risk level should not be "any" at the same time.
For Trellix GTI connection rate rule, defined risk level means the selected risk level and above. For example, medium risk rules can be applied to high risk traffic if no high risk rule is defined.
For one specific geolocation, user can only create two Trellix GTI rules:
One Trellix GTI rule with a specific reputation level (high risk, medium risk, unverified, minimal risk) defined: this rule will apply to the traffic for this geo-location has the reputation same or worse than the defined level. The level defined in this rule can be taken as the malicious cut off level for this geo-location.
One Trellix GTI rule with ANY reputation: this rule will apply to ANY traffic for this geo-location (including all reputation levels and even for the traffic that has no reputation information available). This rule is only based on geo-location and can work even without Trellix GTI enabled (as long as the geo-location database is pushed to the Sensor).
For Trellix GTI connection rate rule, for outbound direction, "Quarantine" response action is not applicable.
When different rule types affect same traffic, the action is taken for the threshold hitting first.
The rule applying order is as follows:
Proto-conn-rate-rule->proto-active-conn rule -> all TCP/UDP conn-rate-rule->all TCP/UDP active-conn-rule->geoLocation specific reputation GTI-conn-rate-rule->geoLocation specific Any reputation GTI-conn-rate-rule->Any geoLocation reputation specific GTI_conn_rate_rule
No Trellix GTI rules apply to allowed hosts.
When Trellix GTI is enabled and Connection Limiting rules are configured, you can block the malicious traffic received on the inbound connections. For example, you can deploy a Sensor in front of a web server, and enable Trellix GTI along with Connection Limiting rules to limit access to the server and prevent DoS attacks.