The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

NS9x00 Sensor capacity

Prev Next

The following table describes the supported NS9x00 Sensor capacity:

Maximum Type NS9300 NS9200 NS9100
Aggregate HTTP Performance 40 Gbps 20 Gbps 10 Gbps
Max Throughput with test equipment sending UDP packet size of 1512 Bytes up to 70 Gbps up to 35 Gbps up to 30 Gbps
Concurrent Connections 32,000,000 16,000,000 13,000,000
Connections established per second 1,000,000 575,000 450,000
Latency

(Average UDP per packet Latency)

<100 µs <100 µs <100 µs
SSL Flow Count 3,200,000 1,600,000 1,200,000
Number of SSL certificates that can be imported into the Sensor 1,024 1,024 1,024
Throughput with Inbound SSL Decryption (based on 10% SSL traffic) 40 Gbps 20 Gbps 10 Gbps
Quarantine rules per Sensor- IPv4 7,999 7,999 7,999
Quarantine rules per Sensor- IPv6 500 500 500
Quarantine Zones per Sensor 50 50 50
Quarantine Zone ACLs per Sensor 1,000 1,000 1,000
Virtual Interfaces (VIDS) per Sensor (Number of Virtual IPS Systems) 1,000 1,000 1,000
VLAN / CIDR Blocks per Sensor 3,000 3,000 3,000
VLAN / CIDR Blocks per Interface 254 254 254
Customized attacks

See the note below on how the number of customized attacks is affected.

100,000 100,000 100,000
Ignore rules 262,144 262,144 262,144
Number of attacks with ignore rules 128,000 128,000 128,000
DoS Profiles 5,000 5,000 5,000
SYN cookie rate (64 ‑ byte packets per second) 13,500,000 9,000,000 5,000,000
Effective (Firewall) access rules 20,000 20,000 10,000
Firewall rule objects 140,000 140,000 70,000
Firewall DNS rule objects 5,000 5,000 2,500
Firewall rule object groups 1,000 1,000 500
Application on Custom Port rule objects 2,000 2,000 1,000
Firewall user-based rule objects 5,000 5,000 2,500
Firewall user groups in access rules 10,000 10,000 10,000
Number of exclusion list entries permitted for IP Reputation 128 128 128
Maximum host entries supported for Connection Limiting policies 256,000 256,000 256,000
Maximum file size during packet capture 100 MB 100 MB 100 MB
Passive device profile limits 100,000 100,000 100,000
Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor

See the note below for more information.

1,000 1,000 1,000
Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor

See the note below for more information.

4,094 4,094 4,094
New HTTP connections per second (using 1 GET with 5000 HTTP response) 700,000 375,000 260,000