The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

NS9600 (stack and standalone) Sensor capacity

Prev Next

The following table describes the supported NS9600 (stack and standalone) Sensor capacity:

Maximum Type

NS9600 Standalone

NS9600 Stack

20 Gbps throughput

40 Gbps throughput

60 Gbps throughput

(2-node)

120 Gbps throughput

Aggregate HTTP Performance

20 Gbps

40 Gbps

60 Gbps

120 Gbps

Max Throughput with test equipment sending UDP packet size of 1512 Bytes

Upto 80 Gbps

Upto 90 Gbps

Upto 100 Gbps

Upto 200 Gbps

Concurrent Connections

18,000,000

32,000,000

36,000,000

72,000,000

Connections established per second

800,000

1,000,000

1,200,000

2,400,000

Latency

(Average UDP per packet Latency)

20 µs

20 µs

20 µs

20 µs

SSL Flow Count

1,800,000

3,200,000

3,600,000

7,200,000

Number of SSL certificates that can be imported into the Sensor

1,024

1,024

1,024

1,024

Throughput with Inbound SSL Decryption (based on 100% SSL traffic)

20 Gbps

40 Gbps

60 Gbps

120 Gbps

Quarantine rules per Sensor- IPv4

24,000

24,000

24,000

24,000

Quarantine rules per Sensor- IPv6

1,500

1,500

1,500

1,500

Quarantine Zones per Sensor

50

50

50

50

Quarantine Zone ACLs per Sensor

1,000

1,000

1,000

1,000

Virtual Interfaces (VIDS) per Sensor (Number of Virtual IPS Systems)

1,000

1,000

1,000

1,000

VLAN / CIDR Blocks per Sensor

3,000

3,000

3,000

3,000

VLAN / CIDR Blocks per Interface

254

254

254

254

Customized attacks

See the note below on how the number of customized attacks is affected.

100,000

100,000

100,000

100,000

Ignore rules

262,144

262,144

262,144

262,144

Number of attacks with ignore rules

128,000

128,000

128,000

128,000

DoS Profiles

5,000

5,000

5,000

5,000

SYN cookie rate (64 ‑ byte packets per second)

9,000,000

14,000,000

18,000,000

36,000,000

Effective (Firewall) access rules

30,000

40,000

80,000

80,000

Firewall rule objects

150,000

170,000

200,000

200,000

Firewall DNS rule objects

5,000

6,000

7,000

7,000

Firewall rule object groups

1,000

1,250

1,500

1,500

Application on Custom Port rule objects

2,000

2,000

2,000

2,000

Firewall user-based rule objects

5,000

6,000

7,000

7,000

Firewall user groups in access rules

10,000

10,000

10,000

10,000

Number of exclusion list entries permitted for IP Reputation

512

512

512

512

Maximum host entries supported for Connection Limiting policies

256,000

256,000

256,000

256,000

Maximum file size during packet capture

100 MB

100 MB

100 MB

100 MB

Passive device profile limits

100,000

100,000

100,000

100,000

Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor

1,000

1,000

1,000

1,000

Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor

4,094

4,094

4,094

8,188

New HTTP connections per second (using 1 GET with 5000 HTTP response)

400,000

700,000

800,000

1,600,000