The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Inspection Options Policy

Prev Next

This URL retrieves the inspection options policy.

Resource URL

GET /protectionoptionspolicy/<policy_id>

Request Parameters

URL Parameter

Field Name Description Data Type Mandatory
policy_id Policy id Number Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
policyId Policy id Number
policyName Policy name String
domainId Domain id Number
visibleToChild Visible to child Boolean
description Description String
lastUpdatedBy Last updated by String
lastUpdated Last updated date String
protectionOptions All options tabs Object

Details of protectionOptions:

Field Name Description Data Type
inspectionOptions Inspection options Object
advancedBotnetDetectionOptions Advanced botnet detection options Object
gtiEndpointReputationAnalysysOptions GTI endpoint reputation analysis options Object
webserverHuresticAnalysysOptions Web server heuristic analysis options Object
webserverDOSOptions Web server DOS options Object

Details of inspectionOptions:

Field Name Description Data Type
httpResponseTrafficScanning HTTP response traffic scanning String
httpResponseDecompression HTTP response decompression String
chunkedHTTPResponseDecoding Chunked HTTP response decoding String
htmlEncodedHTTPResponseDecoding HTML encoded HTTP response decoding String
base64SMTPDecoding Base64 SMTP decoding String
description Description String
quotedPrintableSMTPDecoding Quoted printable SMTP decoding String
msRPCSMBFragmentReassembly MSRPC SMB fragment reassembly String
msOfficeDeepFileInspection Microsoft Office Deep File Inspection String
xffHeaderParsing XFF header parsing String
layer7DataCollection Layer 7 data collection String
passiveDeviceProfiling Passive device profiling String
attackBlockingSimulation Attack blocking simulation String

Possible values for above attributes should be:

  1. INBOUND_ONLY
  2. OUTBOUND_ONLY
  3. DISABLED
  4. INBOUND_AND_OUTBOUND

Details of advancedBotnetDetectionOptions:

Field Name Description Data Type
advancedBotnetDetection Advanced botnet detection String
sensitivity Sensitivity String
fastFluxDetection Fast flux detection String
domainGenerationAlgorithmDetection Domain generation algorithm detection String
domainNameAllowlistProcessing Domain name allow list processing String
exportTrafficToNTBA Export traffic to NTBA Boolean
dnsSinkHooling DNS sink holing String

Possible values for above attributes should be:

  1. INBOUND_ONLY
  2. OUTBOUND_ONLY
  3. DISABLED
  4. INBOUND_AND_OUTBOUND

Possible values for sensitivity should be:

  1. LOW
  2. MEDIUM
  3. HIGH

Details of gtiEndpointReputationAnalysysOptions:

Field Name Description Data Type
gtiEndpointReputationAnalysys GTI endpoint reputation analysis
  • INBOUND_ONLY
  • OUTBOUND_ONLY
  • DISABLED
  • INBOUND_AND_OUTBOUND
String
useToInfluenceSmartBlocking Use to influence SmartBlocking Boolean
excludeInternalEndpoint Exclude internal endpoint Boolean
cidrsExcluded CIDRs excluded Stringlist
protocalsExcluded Protocols excluded Stringlist
urlReputationAnalysis URL reputation analysis String
urlReputationMinimumRisk URL reputation min risk String

Details of webserverHuresticAnalysysOptions:

Field Name Description Data Type
huresticAnalysys Heuristic analysis. Direction value as specified above String
websitePathToProtect Options: ALL or SPECIFIC String
blockedTextList Block text list Stringlist
websitePathToProtectList Website path to protect list Stringlist

Details of webserverDOSOptions:

Field Name Description Data Type
dosPrevention DoS prevention: Direction mode String
maxConnectionAllowedToWS Max connection allowed to WS Number
slowConnectionAttackPrevention Slow connection attack prevention Boolean
maxHTTPRequestPERSecondTOAnyPath Max HTTP request per second to any path Number
websitePathToProtect Website path to protect options: ALL or SPECIFIC String
browserDetectionMethod Browser detection method String
websitePathToProtectList Website path to protect list Objectlist

Example

Request

GET https://<NSM_IP>/sdkapi/protectionoptionspolicy/2

Response

 {
       "policyId": 2,
       "policyName": "httpresponse",
       "domainId": 0,
       "visibleToChild": true,
       "description": "Enable xff",
       "isEditable": true,
       "lastUpdatedBy": "admin",
       "lastUpdated": "2014-Aug-11 16:19",
       "protectionOptions":
       {
           "inspectionOptions":
           {
               "httpResponseTrafficScanning": "INBOUND_AND_OUTBOUND",
               "chunkedHTTPResponseDecoding": "DISABLED",
               "htmlEncodedHTTPResponseDecoding": "DISABLED",
               "base64SMTPDecoding": "DISABLED",
               "quotedPrintableSMTPDecoding": "DISABLED",
               "msRPCSMBFragmentReassembly": "DISABLED",
               "msOfficeDeepFileInspection": "DISABLED",
               "xffHeaderParsing": "DISABLED",
               "layer7DataCollection": "DISABLED",
               "passiveDeviceProfiling": "DISABLED",
               "attackBlockingSimulation": false
           },
           "advancedBotnetDetectionOptions":
           {
               "advancedBotnetDetection": "INBOUND_AND_OUTBOUND",
               "sensitivity": "LOW",
               "exportTrafficToNTBA": false,
               "fastFluxDetection": "DISABLED",
               "domainGenerationAlgorithmDetection": "DISABLED",
               "dnsSinkholing": false,
               "domainNameAllowlistProcessing": true,
               "cidrsExcluded": [],
           },
           "gtiEndpointReputationAnalysysOptions":
           {
               "gtiEndpointReputationAnalysys": "DISABLED",
               "useToInfluenceSmartBlocking": false,
               "excludeInternalEndpoint": false
               "cidrsExcluded": [],
               "protocalsExcluded": [],
               "urlReputationAnalysis": null,
               "urlReputationMinimumRisk": null
           },
           "webserverHuresticAnalysysOptions":
           {
               "huresticAnalysys": "INBOUND_ONLY",
               "websitePathToProtect": "ALL",
               "blockedTextList": [],
               "websitePathToProtectList": [],
           },
           "webserverDOSOptions":
           {
               "dosPrevention": "INBOUND_ONLY",
               "maxConnectionAllowedToWS": 750000,
               "slowConnectionAttackPrevention": false,
               "maxHTTPRequestPERSecondTOAnyPath": 10000,
               "websitePathToProtect": "ALL",
               "clientBrowserDetection": false,
               "browserDetectionMethod": null,
               "websitePathToProtectList": [],
           }
       }
    } 
 

Error Information

No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 4301 Invalid domain id