The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes about upgrading from 9.1, 9.2, 10.1 to 10.1.7.61

Prev Next

Rule object members limit enhancement for Firewall Policy

Starting with this release of 10.1, Network Security Platform offers support for enhanced rule object member count for Firewall Policy.

Following table lists the maximum count of rule object members (Rule Members) that can be added under each rule object type:

Rule object type

Rule Members (Maximum count)

Host DNS Name

5000

IPv4 Address Range

20000

IPv4 Endpoint

140000

IPv4 Network

140000

IPv6 Address Range

20000

IPv6 Endpoint

140000

IPv6 Network

140000

Application Group, Application on Custom Port, Finite Time Period, Network Group, Network Group for Ignore Rules, Recurring Time Period, Recurring Time Period Group, Service, Service Group, Service Range

10

Note

The rule member count specified in the above table is applicable only for Firewall policy, and it varies with the Sensor model being used.

For QoS policy, Ignore Rules, Outbound SSL Decryption Exclusions, Quarantine Zones and NTBA Communication Rules, the maximum rule member count applicable for each rule object type is 10.

The above rule object count specified for IPv4/IPv6 based rule objects is also applicable for Central Managers starting 10.1.7.61. Central Managers running on older versions, however, support only 10 rule members per each rule object.

If you are using a Central Manager, do not add more than 10 entries in the Central Manager Rule Objects which are associated with QoS policies, Ignore Rules, Outbound SSL Decryption Exclusions, Quarantine Zones or Quarantine Exceptions in a Manager.

The following table lists the cumulative rule object member count of all the rule objects selected in a Firewall policy for each NS-series Sensor model. This table provides comparison of the limits supported on each Sensor model in this release and the previous releases.

Model

Cumulative rule object member count of all the rule objects selected

For Sensors before 10.1.5.170 For Sensors starting 10.1.5.170
NS9500 stack - 100 Gbps throughput 140000 240000
NS9500 stack - 60 Gbps throughput 140000 240000
NS9500 stack - 40 Gbps throughput 140000 170000
NS9500 standalone - 30 Gbps throughput 140000 240000
NS9500 standalone - 20 Gbps throughput 140000 240000
NS9500 standalone - 10 Gbps throughput 70000 170000
NS9300 140000 240000
NS9200 140000 240000
NS9100 70000 170000
NS7500 - 7.5 Gbps throughput 35000 135000
NS7500 - 5 Gbps throughput 35000 135000
NS7500 - 3Gbps throughput 35000 135000
NS7350 35000 135000
NS7250 21000 121000
NS7150 21000 121000
NS7300 35000 135000
NS7200 21000 121000
NS7100 21000 121000
NS5200 14000 34000
NS5100 14000 34000
NS3500 7000 17000
NS3200/NS3100 7000 17000

Note

The increment in the cumulative rule member count for Sensors starting 10.1.5.170 is with respect to the Source and Destination Address fields you set in the Firewall Access Rules. This is done to support more IOCs (Indicators of compromise) for blocking matching traffic.

This release also comes with an option to enable automatic deployment of Firewall rule objects to specific Sensors whenever any changes are made in the Firewall Rule Objects. These changes include addition, deletion or modification of IPv4 and IPv6 addresses or CIDRs.

A new page has been added to enable users to automatically deploy Firewall rule objects to the Sensors. This page can be found under Devices → <Admin Domain Name> → Global → IPS Device Settings → Firewall Rule Objects.

Note

Automatic deployments are applicable only if:

  • The rule object being modified is of the following type: IPv4 Endpoint, IPv4 Network, IPv6 Endpoint, or IPv6 Network.

  • The rule object being modified is used in a Firewall policy and assigned to a Sensor running on software version 10.1.5.170 and later.

Terminology updates in the UI

This release contains the following terminology updates in the Manager UI:

Navigation Path Prior to 10.1.7.61 10.1.7.61 and later
Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions The option available:

SSL Decryption Exclusions

The option is renamed to Outbound SSL Decryption Exclusions
Policy → <Admin Domain Name> → Intrusion Prevention → Advanced → Policy Import The option available:

SSL Decryption Exclusions

The option is renamed to Outbound SSL Decryption Exclusions
Policy → <Admin Domain Name> → Intrusion Prevention → Advanced → Policy Export The option available:

SSL Decryption Exclusions

The option is renamed to Outbound SSL Decryption Exclusions