The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get TCP Settings Configuration at Sensor Level

Prev Next

This URL gets the TCP settings on the Sensor.

Resource URL

GET /sensor/<sensor_id>/tcpsettings

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor id

Number

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

TCPSettings

The TCP settings on the Sensor

Object

Details of fields in TCPSettings:

Field Name

Description

Data Type

tcpParameter

The parameters of TCP settings

Object

Details of fields in tcpParameter:

Field Name

Description

Data Type

supportedUDPFlows

The supported UDP flows

Number

tcbInactivityTimesInMinutes

The TCP inactivity timer (minutes)

Number

tcpSegmentTimerInSeconds

The TCP segment timer (seconds)

Number

tcp2MSLTimerInSeconds

The TCP 2MSL timer (seconds)

Number

coldStartTimeInMinutes

The cold start time (minutes)

Number

coldStartAckScanAlertDiscardIntervalInMinutes

The cold start ack scan alert discard interval(minutes)

Number

coldStartDropAction

The cold start drop action. The value can be:

  • DROP_FLOWS

  • FORWARD_FLOWS

String

tcpFlowViolation

The TCP flow violation. The value can be:

  • PERMIT

  • DENY

  • PERMIT_OUT_OF_ORDER

  • DENY_NO_TCB

  • STATELESS_INSPECTION

String

unsolicitedUDPPacketTimeOutInSeconds

The unsolicited UDP packets timeout (seconds)

Number

Normalization

The normalization. The value can be:

  • ON

  • OFF

String

tcpOverlapOption

The TCP overlap option. The value can be:

  • OLD_DATA

  • NEW_DATA

String

synCookie

The SYN cookie data

Object

resetUnfinished3WayHandshakeConnection

The reset unfinished 3 way handshake connection. The value can be:

  • DISABLED

  • SET_FOR_ALL_TRAFFIC

  • SET_FOR_DOS_ATTACK_TRAFFIC_ONLY

String

dnsSinkholingTimeToLive

DNS sinkholing time to live

Number

dnsSinkholingIPAddress

DNS sinkholing IP address

String

http2FlowAllocPrcnt

HTTP2 flow allocation %

Number

slowPostTimeout

Slow post timeout

Number

slowPostThresholdFrameSize

Slow post threshold frame size

Number

slowPostMinStreamsCnt

Slow post minimum number of streams

Number

slowPostMinTinyFramesCnt

Slow post minimum number of tiny frames

Number

slowReadTimeout

Slow read timeout

Number

slowReadWindowSize

Slow read window size

Number

slowReadMinStreamsCnt

Slow read minimum number of streams

Number

http2DecodedPktInAtckPktLogFlag

HTTP2 decoded packets in attack packet log

Number

ftpAcceleration

FTP acceleration

String

Details of fields in synCookie:

Field Name

Description

Data Type

synCookieOption

The SYN cookie option. The value can be:

  • DISABLED

  • INBOUND_ONLY

  • OUTBOUND_ONLY

  • BOTH_INBOUND_AND_OUTBOUND

String

inboundThresholdValue

The inbound threshold value

Number

outboundThresholdValue

The outbound threshold value

Number

Example

Request

GET https://<NSM_IP>/sdkapi/sensor/1002/tcpsettings

Response

{
"tcpParameter": {
"supportedUDPFlows": 100,
"tcbInactivityTimesInMinutes": 10,
"tcpSegmentTimerInSeconds": 10,
"tcp2MSLTimerInSeconds": 10,
"coldStartTimeInMinutes": 0,
"coldStartAckScanAlertDiscardIntervalInMinutes": 0,
"coldStartDropAction": "FORWARD_FLOWS",
"tcpFlowViolation": "PERMIT_OUT_OF_ORDER",
"unsolicitedUDPPacketTimeOutInSeconds": 10,
"normalization": "OFF",
"tcpOverlapOption": "NEW_DATA",
"synCookie": {
"synCookieOption": "INBOUND_ONLY",
"inboundThresholdValue": 14112,
"outboundThresholdValue": 10000
},
"resetUnfinished3WayHandshakeConnection": "DISABLED",
"dnsSinkholingTimeToLive": 720,
"dnsSinkholingIPAddress": "127.0.0.1",
"http2FlowAllocPrcnt": 5,
"slowPostTimeout": 5,
"slowPostThresholdFrameSize": 10,
"slowPostMinStreamsCnt": 50,
"slowPostMinTinyFramesCnt": 1,
"slowReadTimeout": 60,
"slowReadWindowSize": 10,
"slowReadMinStreamsCnt": 50,
"http2DecodedPktInAtckPktLogFlag": "2",
"ftpAcceleration": "DISABLED"
}
}

Error Information

Following error code is returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor