The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Task list for finding the source of asymmetric Flows

Prev Next

If you suspect that the traffic monitored by your appliance contains asymmetric flows, follow these guidelines to locate the source of the asymmetric traffic.

Important

To avoid depleting system resources and degrading appliance performance, enable this feature only while you are collecting and viewing the statistics needed to investigate asymmetric flows in the network.

  1. Check the ratio of asymmetric traffic to non-asymmetric traffic.

    See Viewing the number of asymmetric flows using the CLI.

    Note

    On SmartVision Mode sensors, the suspicious objects that Trellix Unified Multiflow Engine (FUME) sends to the virtual machine (VM) to detect multiflow attacks are limited .exe and .dll files over SMB and SMB 2.

  2. If the ratio is high, begin caching statistics about the asymmetric traffic flows.

    See Enabling asymmetric flow statistics collection using the CLI.

  3. Analyze the cached traffic flow statistics. Statistics for SYN‑only flows and non-SYN‑only asymmetric flows are listed separately. Within each list, statistics for the most frequently occurring flow profiles are listed first.

    See Viewing the asymmetric flow statistics using the CLI.

  4. (Optional) If a list is at or near its capacity of 100 unique flow profiles, you can refresh the cache, enabling the appliance to collect statistics for the latest traffic.

    See Refreshing the asymmetric flow statistics cache using the CLI.

  5. IMPORTANT! When you are no longer actively investigating asymmetric flows, stop caching asymmetric traffic flow statistics.

    See Disabling asymmetric flow statistics collection using the CLI.