The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Debugging issues with Connection Limiting policies

Prev Next

Connection Limiting policies consist of a set of rules that enable the Sensors to limit the number of connections a host can establish or a connection rate. This section provides troubleshooting steps to resolve few issues with Connection Limiting policies.

Prerequisites:

Check that the Connection Limiting policy is correctly configured.

  • You can configure the Connection Limiting policy with the monitoring ports in SPAN, tap, or inline modes. The response actions differ for SPAN and tap modes. In these modes, the Sensor cannot block the connections or quarantine the hosts.

  • The connections are limited based on the predefined threshold value. The threshold value is defined as connections per second or active connections. For example, if you define 1 connection per second as the threshold value, then, 10 connections are allowed per 10 seconds. So, if there are 10 connections in the first second, all other connections from the second to the tenth second are dropped. On the other hand, if you have 1 connection for each second, all the 10 connections until the tenth second are allowed.

  • Connection Limiting rule based on Protocol applies to both IPv4 and IPv6 traffic. Connection limiting rule based on Trellix GTI applies to only IPv4 traffic. GTI does not support IPv6 traffic.

  • The Connection Limiting alert raised is IP: Too many TCP/UDP/ICMP sessions. This alert is present in theIPS Policies.

Perform these steps to configure a basic Connection Limiting policy:

  1. Go to Policy → <Admin Domain> → Intrusion Prevention → Policy Types → Connection Limiting Policies.

  2. Click New and configure the rule properties like description and visibility.

  3. Click Next, in Connection Limiting Rules page, set the parameters like state, direction, and response.

    Connection Limiting Rule
    Connection Limiting Rule


  4. Go to Policy → Intrusion Prevention → Policy Manager to apply the Connection Limiting policy on the Sensor interface.

    Note

    Make sure the IP: Too many TCP/UDP/ICMP sessions alert is enabled in the IPS policy that is applied on the Sensor interface.