The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Rate limiting of application protocols using SSL

Prev Next

The Sensor rate limiting functionality for protocols with SSL connection, depends on whether the Sensor is configured to decrypt the traffic.

SSL keys are present in the Sensor

When the Sensor is configured to have SSL keys to decrypt the traffic, the HTTPS traffic reaching the Sensor will be decrypted, and decrypted application protocol will be HTTP (and not SSL). Several scenarios are possible depending on the traffic and rate limiting rule configured. In all the scenarios, the application protocol HTTP using SSL (HTTPS) is used as the example.

Case 1:

Assume that an SSL rate limiting rule is configured, and HTTPS traffic is processed by the Sensor. In this case, the Sensor will decrypt the HTTPS traffic into HTTP. When the HTTPS traffic rate is beyond the configured SSL rate limiting rule, the Sensor will not rate limit the traffic. This is because the decrypted traffic is HTTP, but the rate limiting rule is configured for SSL. For rate limiting such a traffic, you have to configure a rate limiting rule for HTTP. This is explained in the next case.

Case 2:

Suppose the HTTP rate limiting rule is configured, and HTTPS traffic is processed by the Sensor. In this case, the Sensor will decrypt the HTTPS traffic into HTTP. The Sensor performs rate limiting of the decrypted traffic. This is because the decrypted traffic is HTTP and the rate limiting rule is also configured for HTTP.

SSL keys are not present in the Sensor

When the Sensor is configured such that there are no SSL keys to decrypt the traffic, the HTTPS traffic reaching the Sensor is not decrypted into HTTP. Several scenarios are possible depending on the traffic and rate limiting rule configured. In all the scenarios, the application protocol HTTP using SSL (HTTPS) is used as the example.

Case 1:

Assume that a SSL rate limiting rule is configured, and HTTPS traffic is processed by the Sensor. In this case, the Sensor will not decrypt the HTTPS traffic as it does not have the keys. When the HTTPS traffic rate is beyond the configured SSL rate limiting rule, the Sensor will rate limit the traffic. This is because the HTTPS traffic is not decrypted to HTTP and it is treated as SSL. So the rate limiting rule for SSL holds good and the traffic is rate limited.

Case 2:

Suppose the HTTP rate limiting rule is configured, and HTTPS traffic is processed by the Sensor. In this case, the Sensor will not decrypt the HTTPS traffic as it does not have the keys. The HTTPS traffic is treated as SSL. So the HTTP rate limiting rule does not hold good, and the Sensor does not perform rate limiting. Here you have to configure an SSL rate limiting rule for successful rate limiting of the traffic.