The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Threshold-based mode

Prev Next

In the threshold mode, the Sensor monitors the network traffic for packet floods, such as too many IP fragments, transmitting through from a source to a destination as detected within a Sensor interface or subinterface. When configuring the DoS policy or customizing at the interface or subinterface level, you must specify the count and interval rate in seconds, for the threshold attacks you want to detect. The Sensor sends an alert, if configured to do so in the DoS policy, when the traffic exceeds the customized thresholds for an enabled attack. You can also enable a notification for an attack if it warrants special attention. For threshold-based attacks, a Sensor monitors both inbound and outbound traffic.

This method requires that you to fully understand your typical traffic pattern to pick good threshold values; otherwise it can produce false alarms due to traffic fluctuations, such as flash crowds — for example, everyone logging on the network at 9 a.m.— or other legitimate increased traffic.

Note

Although default values are provided for thresholds and intervals, you must configure the actual thresholds and intervals for each DoS threshold mode attack you want to detect. Customization of DoS thresholds works best after researching the current levels to be defended for each DoS threshold. This helps you to determine exactly what counts and intervals are best for protecting your network.

The threshold method involves specifying the count and interval thresholds while configuring a DoS policy in the Manager. When the threshold is crossed, the DoS attack is detected.

Threshold value and interval can be customized in the Manager for threshold attacks, such as:

  • Inbound Link Utilization (Bytes/Sec) Too High

  • Too Many Inbound ICMP Packets

  • Too Many Inbound IP Fragments

  • Too Many Inbound Large ICMP packets

  • Too Many Inbound Large UDP packets

  • Too Many Inbound Rejected TCP Packets

  • Too Many Inbound TCP Connections

  • Too Many Inbound TCP SYNs

  • Too Many Inbound UDP Packets