Consider these restrictions related to QoS policies.
Limitations for configuring interconnect ports
You cannot assign a QoS policy or Rate Limiting profile to the interconnect ports of a Sensor HA pairs because these ports cannot be used for monitoring traffic.
This includes the following Sensor ports when in HA pair:
| Sensor | Restricted ports |
|---|---|
| NS-series (NS9500 standalone and stack, NS9300, NS9200, NS9100, NS7500, NS7350, NS7250, NS7150, NS7300, NS7200, NS7100, NS5200, NS5100, NS3500, NS3200, NS3100) | NA |
| IPS-VM600 | NA |
| M-8000 | In the M-8000 Sensor, interconnect ports XC2, XC3, XC4 and XC5 cannot be used for configuring QoS.
In an M-8000 HA pair, 3A and 3B are used as interconnect ports. You cannot use 3A or 3B for QoS configuration. |
| M-6050, M-8030, M-1450, M-1250 | Port 4A is used as the interconnect port and 4B is unused. You cannot use either 4A or 4B for QoS configuration. |
| M-4050, M-3050, M-6030, M-4030 | Port 2A is used as the interconnect port and 2B is unused. You cannot use either 2A or 2B for QoS configuration. |
| M-2950, M-2850, M-3030 | Port 6A is used as the interconnect port and 6B is unused. You cannot use either 6A or 6B for QoS configuration. |
If you configure QoS on the to-be interconnect ports of a Sensor HA pair, the configuration on those interconnect ports will be removed. For an existing Sensor HA pair, note that the interconnect ports will not be available for QoS configuration.
If you configure QoS on interconnect ports, the configuration will be removed when you configure these ports for HA pair. Note that if you configure HA pairs on the interconnect ports first and then want to configure those ports for QoS, Trellix IPS will not allow this (as these failover ports will not be displayed as available ports for QoS).
Limitations regarding rules
There is a restriction on the total number of entries for a queue and also for a Sensor. There can be a maximum of 64 entries for every queue and a maximum of 1000 entries for a Sensor (across all Ports). Every selection criteria is treated as an entry - one UDP Port, one Defined Protocol, one IP Protocol Number, one Port Range - each of these is one entry. This restriction is evaluated during the signature set generation process. The signature set generation aborts if the maximum value restriction is violated.
Limitations due to load-balanced traffic simultaneously reaching Sensor HA pairs
There is a limitation when each Sensor in a HA pair simultaneously receives load-balanced or asymmetric traffic for a configured Protocol, TCP port, UDP port, and IP protocol number. In this scenario, the QoS rule is applied individually on each Sensor because the Sensor only invokes QoS on traffic at the egress monitoring port; it does not invoke QoS on failover-copy traffic received from its peers through the interconnect ports. Since QoS is invoked only when traffic through the monitoring port(s) of each Sensor in a HA pair exceeds the configured bandwidth, each Sensor must see the configured traffic on its monitoring port(s) for QoS to occur. This is independent of the traffic that the peer Sensor might be monitoring.