The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the SSL Configuration at the Sensor Level

Prev Next

This URL gets the SSL configuration at the Sensor level for 9.2 NS-series Sensors.

Resource URL

GET /sensor/<sensorId>/decryptionsettings

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor id

Number

Yes

Response Parameters

Following fields are returned.

Field Name

Description

Data Type

inheritSettings

Inherit settings from parent domain

Boolean

decryptionState

SSL state. The values can be:

  • DISABLED

  • INBOUND

  • OTBOUND

String

anticipatedSSLTrafficUsageAnticipated

Anticipated inbound SSL traffic usage. The values can be:

  • VERY_LIGHT

  • LIGHT

  • MEDIUM

  • HEAVY

  • VERY_HEAVY

String

maxFlow

Maximum flow allowed in the Sensor.

Number

decryptedFlow

Flows allocated to the Sensor.

Number

sslInactivityTimeoutInMinutes

The maximum amount of time a Sensor will keep an outbound SSL flow open when no data has been seen on the Sensor.

Number

includeDecryptedPCAPS

Include decrypted packets while packet capture.

Boolean

enableDhSupport

DH support

Boolean

maxConcurrent

Maximum concurrent connection allowed between a Trellix Agent and a Sensor. The value can range from 1 to 1024.

Number

permittedIPv4CIDRBlocks

IPv4 CIDR blocks

Object

permittedIPv6CIDRBlocks

IPv6 CIDR blocks

Object

Details of permittedIPv4CIDRBlocks and permittedIPv6CIDRBlocks:

Field Name

Description

Data Type

id

ID of CIDR added

Number

cidr

CIDR block

String

Details of failureHandling:

Field Name

Description

Data Type

untrustedOrExpiredServerCertificate

Action to take if the target web server's certificate is not on the Sensor's trusted CA list. Used only in case of outbound SSL. The value can be:

  • Block flow

  • Decrypt

Number

Example

Request

GET https://<NSM_IP>/sdkapi/sensor/1001/decryptionsettings

Response

{
  "inheritSettings": false,
  "decryptionState": "INBOUND",
  "anticipatedSSLTrafficUsage": "VERY_HEAVY",
  "sslInactivityTimeoutInMinutes": 6,
  "maxFlow": 1600000,
  "enableDhSupport": true,
  "maxConcurrent": 210,
  "permittedIPv4CIDRBlocks": [
    {
     "id": 428,
     "cidr": "4.4.4.4/32",
     "action": null
    },
    {
     "id": 366,
     "cidr": "1.1.1.1/32",
     "action": null
    }
   ],
 "permittedIPv6CIDRBlocks": [
  {
   "id": 429,
   "cidr": "2001:0DB9:0000:0000:0000:0000:0000:0000/123",
   "action": null
  },
  {
   "id": 367,
   "cidr": "2001:0DB9:0000:0000:0000:0000:0000:0000/128",
   "action": null
  }
],
"decryptedFlow": 1600000,
"includeDecryptedPCAPS": true
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

500

1124

The Sensor is inactive

3

500

1001

Internal error