The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Quality of Service policies

Prev Next

Quality of Service (QoS) policies help in avoiding traffic congestions, controlling the actual traffic flow within the permissible limit of the network, and limiting traffic surges in your network. Trellix IPS provides two traffic management features — DiffServ tagging and IEEE 802.1p (VLAN) tagging.

  • Differentiated services, or DiffServ, operates on the principle of traffic classification, where each data packet is classified and placed into a limited number of traffic classes. You can configure network devices which support DiffServ, such as a router, to differentiate traffic based on its class. So, you can manage each traffic class differently, ensuring preferential treatment for higher-priority traffic on the network. The Sensor provides DiffServ tagging of packets. The tagged packets are used by DiffServ-compliant external network devices for traffic management.

  • IEEE 802.1p specification enables network devices to prioritize traffic at the media access control (MAC) layer, and perform dynamic multi-cast filtering. The 802.1p header includes a three-bit field for prioritization, which allows packets to be grouped into various traffic classes. The three-bit prioritization field provides eight different classes of service to the user. The way the traffic is treated when assigned to any particular class is undefined, and left to the implementation on your network. The Sensor provides VLAN 802.1p tagging of packets, which are sent to VLAN 802.1p-compliant external network devices for traffic management.

Note

For DiffServ tagging and VLAN 802.1p tagging, the Sensor's role is limited to just tagging the traffic. You must configure the corresponding network devices like switches and routers to provide QoS based on these tags.

QoS features

  • Configuring the QoS feature is to some extent similar to the Firewall feature. You define the QoS policy and the component rules for DiffServ tagging and VLAN 802.p tagging. Then you assign this policy to inline ports. These QoS rules are similar to Firewall access rules in the way the Sensor executes them.

  • You can configure the following as the criteria in a QoS rule:

    • Source of the traffic:

      • Country

      • Host name

      • IPv4 or IPv6 addresses, address ranges, or networks

      • Windows Active Directory user names or user groups

    • Destination of the traffic:

      • Country

      • Host name

      • IPv4 or IPv6 addresses, address ranges, or networks

    • Applications such as Facebook, Yahoo! Instant Messenger, and Gmail. You can specify a group of applications. You can also specify features of an application, such as the file transfer feature of Yahoo! Messenger.

    • Services or groups of services

    • You can also set a time period during which the Sensor should apply a QoS rule.

  • You define separate sets of rules for DiffServ and 802.1p that the Sensor executes in a top-down fashion. When the traffic matches a rule, the Sensor tags the traffic with the corresponding DiffServ or 802.1p value specified in the rule.

Advantages

  • You can identify traffic at a very granular level and provide QoS accordingly. For example, you can restrict social-networking traffic to a very low bandwidth so that it does not affect the QoS of your business applications.

  • You can enforce different policies based on time. For example, you can have a higher bandwidth for gaming applications on weekends but a low one during weekdays.

  • You can provide QoS based on geographical locations.

  • You can provide QoS based on the phase of an application. For example, you can differentiate chatting through Yahoo! Messenger from file transfers through Yahoo! Messenger.

  • You can provide differential QoS based on the sub-networks within your enterprise network. For example, you can have a bigger bandwidth for your engineering subnet when compared to your finance subnet. For environments where the IPs are likely to change frequently, you can base QoS on Windows Active Directory user names.

  • You can enable or disable each rule in your QoS policies. This can help you to narrow down on the rules when troubleshooting.

  • The modular design of the QoS feature greatly facilitates reusability:

    • You can define the criteria as rule objects and use them for Firewall, Ignore Rules, and QoS.

    • You can define a QoS policy with the component rules and assign it to multiple monitoring ports.