The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show dospreventionprofile

Prev Next

This command displays the specified denial of service profile information for the Sensor, defined in two arguments — a DoS measure name, and a traffic direction. It also displays the DOS prevention profile information for different measures.

Syntax:

show dospreventionprofile <dos-measure-name> <inbound | outbound>

show dospreventionprofile intfport (g0/1 | g0/2 | g1/1 | g1/2 | g1/3 | g1/4 | g1/5 | g1/6 | g1/7 | g1/8 | g1/9 | g1/10 | g1/11 | g1/12 | g2/1 | g2/2 | g2/3 | g2/4 | g2/5 | g2/6 | g2/7 | g2/8 | g2/9 | g2/10 | g2/11 | g2/12 | g3/1 | g3/2 | g3/3 | g3/4 | g3/5 | g3/6 | g3/7 | g3/8 | g4/1 | g4/2 | g5/1 | g5/2 | g5/3 | g5/4 | g5/5 | g5/6 | g5/7 | g5/8 | g5/9 | g5/10 | g5/11 | g5/12 | g6/1 | g6/2 | g6/3 | g6/4 | g6/5 | g6/6 | g6/7 | g6/8 | g6/9 | g6/10 | g6/11 | g6/12 | g7/1 | g7/2 | g7/3 | g7/4 | g7/5 | g7/6 | g7/7 | g7/8) (tcp-syn|tcp-syn-ack|tcp-fin|tcp-rst|udp|icmp-echo|icmp-echo-reply|icmp-non-echo-echoreply|ip-fragment|non-tcp-udp-icmp) (inbound | outbound)

Parameter

Description

<intfport>

Indicates the interface port

<dos-measure-name>

Indicates the DoS measure name: one of 'tcp-syn', 'tcp-syn-ack', 'tcp-fin', 'tcp-rst', 'udp', 'icmp-echo', 'icmp-echo-reply', 'icmp-non-echo-reply', 'ip-fragment', 'non-tcp-udp-icmp'

<direction>

Indicates the direction. It can be 'inbound' or 'outbound'.

Example:

show dospreventionprofile tcp-syn inbound

Information displayed by the show dospreventionprofile command includes the following:

  • The Sensor's DoS profile

  • The traffic direction protected by the profile

Example 1:

intruShell@Sensor-9500> show dosPreventionProfile tcp-syn inbound

where:

  • packet type: TCP-SYN IN (0), profile stage: still learning (0)

  • long-term average rate=0.000(pkts/s), last_rate=0.000(pkts/s) no attack in progress

  • each line: bin_index, IP_prefix/prefix_len, AS, LT, ST, ltR(ate), stR(ate)

  • AS(%) -- percentage of the IP address space this bin occupies

  • LT(%) -- percentage of long-term traffic that falls into this bin

  • ST(%) -- percentage of short-term traffic that falls into this bin

  • ltRate -- long-term average traffic rate (in pkts/s) for this bin

  • stRate -- short-term traffic rate (in pkts/s) for this bin

  • 0: 0.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000

  • 1: 128.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000

  • 2: 64.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000

Example 2:

show dospreventionprofile intfport g2/3 tcp-syn inbound

Applicable to:

NS-series Sensors

Note

show dospreventionprofile intfport command is applicable only for NS9300 Sensors.