The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Non-payload rule options

Prev Next

This section explains Snort non-payload rule options.

flags

Use this if you want the Sensor to check for TCP flags. You can check for the following flags:

  • F - FIN (LSB in TCP Flags byte)

  • S - SYN

  • R - RST

  • P - PSH

  • A - ACK

  • U - URG

  • 1 - Reserved bit 1 (MSB in TCP Flags byte)

  • 2 - Reserved bit 2

  • 0 - No TCP Flags Set

You can apply the following operators on the flags option:

  • + — Checks if all the specified flags are set

  • * — Checks if at least one of the specified flags is set

  • ! — Checks if none of the flags are set

Syntax: flags:[!|*|+]<FSRPAU120>[,<FSRPAU120>];

Example rule:

alert tcp 10.1.1.1 any -> any any (msg:"example for flags"; flags:R; sid:2019; priority:3;)

This rule raises an alert when the host 10.1.1.1 resets a TCP connection.

flow

This option enables you to write rules specific to a direction of the traffic flow. For example, you can write a rule that the Sensor applies only on the traffic from the clients.

The following table describes the flow options that you can use in Trellix IPS:

Option

Description

to_client

Rule is applicable only to the response traffic from the server in a TCP session.

to_server

Rule is applicable only to the request traffic from the client in a TCP session.

from_client

Same as to_server

from_server

Same as to_client

Syntax: flow: [,(to_client|to_server|from_client|from_server)];

Example rule:

alert tcp !$HOME_NET any -> 10.1.1.1 80 (msg:"example for flow"; flow:to_server; content:"cmd.exe";sid:2015; priority:1;)

For this rule, the Sensor checks for cmd.exe in the request traffic from outside network to 10.1.1.1.

Notes:

  • Make sure you specify the flow option in the Snort custom attacks to avoid false-positives.

  • If you do not specify flow for a TCP rule, then it is saved in the Manager with Conversion Result, "warning" and State Published.

itype

Use this if the Sensor is to check for a specific ICMP type value.

Syntax: itype:[<|>]<number>[<><number>];

icode

Use this if the Sensor is to check for a specific ICMP code value.

Syntax: icode: [<|>]<number>[<><number>];

Example rule:

alert icmp !$HOME_NET any -> $HOME_NET any (msg:"example for itype and icode"; itype 8; icode:0; sid:2022; priority:3;)

This rule is triggered for inbound traffic where the type is 8 and code is 0.

icmp_seq

This is to check for a specific ICMP sequence value.

Syntax: icmp_seq:<number>;

Example rule:

alert icmp !$HOME_NET any -> $HOME_NET any (msg:"example for icmp_seq"; icmp_seq:0; sid:2041; priority:3;)