The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Jumbo frame parsing

Prev Next

Jumbo frames are Ethernet frames, which carry larger payloads per packet than the standard Ethernet frame. They are designed to enhance network throughput and improve CPU utilization for large file transfers, by enabling more efficient payloads per packet. For example, a jumbo frame size packet can carry more than 1500 bytes of payload in an Ethernet frame.

Trellix IPS parses jumbo frames in attack detections. Sensors support jumbo frame parsing in the inline, tap, and SPAN modes.

The following Sensor models support jumbo frame parsing of up to 9,216 bytes (9 KB) of IP payload:

  • IPS-VM600, IPS-VM5000, IPS-VM5000-SSL, and IPS-VM600-SSL on ESXi and KVM.

    IPS-VM600-VSS-SSL on AWS, Azure and GCP.

  • NS9600, NS9500, NS9300, NS9200, NS9100, NS7600, NS7500, NS7350, NS7250, NS7150, NS7300, NS7200, NS7100, NS5200, NS5100, and NS3600

Note

1 Gigabit Sensor ports will inline forward jumbo frames that are greater than 9KB (9216 bytes) of IP payload and up to 9724 bytes. Frames with IP payload greater than 9724 bytes will be dropped on a 1 Gigabit port. However, 10 Gigabit Sensor ports will inline forward jumbo frames greater than 9KB (9216 bytes)of IP payload and up to 16KB (16384 bytes). Frames with IP payload greater than 16KB will be dropped on a 10 Gigabit port.

Jumbo frame parsing is not supported on NS3500, NS3200, and NS3100 Sensors.