The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

NS9x00 Sensor capacity

Prev Next

The following table describes the supported NS9x00 Sensor capacity:

Maximum Type

NS9300

NS9200

NS9100

Aggregate HTTP Performance

40 Gbps

20 Gbps

10 Gbps

Max Throughput with test equipment sending UDP packet size of 1512 Bytes

up to 70 Gbps

up to 35 Gbps

up to 30 Gbps

Concurrent Connections

32,000,000

16,000,000

13,000,000

Connections established per second

1,000,000

575,000

450,000

Latency

(Average UDP per packet Latency)

<100 µs

<100 µs

<100 µs

SSL Flow Count

3,200,000

1,600,000

1,200,000

Number of SSL certificates that can be imported into the Sensor

1,024

1,024

1,024

Throughput with Inbound SSL Decryption (based on 10% SSL traffic)

40 Gbps

20 Gbps

10 Gbps

Quarantine rules per Sensor- IPv4

7,999

7,999

7,999

Quarantine rules per Sensor- IPv6

500

500

500

Quarantine Zones per Sensor

50

50

50

Quarantine Zone ACLs per Sensor

1,000

1,000

1,000

Virtual Interfaces (VIDS) per Sensor (Number of Virtual IPS Systems)

1,000

1,000

1,000

VLAN / CIDR Blocks per Sensor

3,000

3,000

3,000

VLAN / CIDR Blocks per Interface

254

254

254

Customized attacks

See the note below on how the number of customized attacks is affected.

100,000

100,000

100,000

Ignore rules

262,144

262,144

262,144

Number of attacks with ignore rules

128,000

128,000

128,000

DoS Profiles

5,000

5,000

5,000

SYN cookie rate (64 ‑ byte packets per second)

13,500,000

9,000,000

5,000,000

Effective (Firewall) access rules

20,000

20,000

10,000

Firewall rule objects

140,000

140,000

70,000

Firewall DNS rule objects

5,000

5,000

2,500

Firewall rule object groups

1,000

1,000

500

Application on Custom Port rule objects

2,000

2,000

1,000

Firewall user-based rule objects

5,000

5,000

2,500

Firewall user groups in access rules

10,000

10,000

10,000

Number of exclusion list entries permitted for IP Reputation

128

128

128

Maximum host entries supported for Connection Limiting policies

256,000

256,000

256,000

Maximum file size during packet capture

100 MB

100 MB

100 MB

Passive device profile limits

100,000

100,000

100,000

Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor

See the note below for more information.

1,000

1,000

1,000

Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor

See the note below for more information.

4,094

4,094

4,094

New HTTP connections per second (using 1 GET with 5000 HTTP response)

700,000

375,000

260,000