Connection Limiting policies consist of a set of rules that enable the Sensors to limit the number of connections a host can establish or a connection rate.
The Sensor provides the ability to define threshold values to limit number of connections (three-way handshakes for TCP) a host can establish. The number of connections or the connection rate that is less than or equal to the defined threshold value is allowed, whereas the same exceeding the value is dropped. This helps in minimizing the connection-based DoS attacks on server.
Connection Limiting rules are of two types:
Protocol-based
GTI-based
Only GTI-based rules are applicable for the integration of this technology with IP Reputation. These rules are defined for traffic to/from external hosts based on reputation and geo-location of the external hosts.
When GTI is enabled and Connection Limiting rules are configured, you can block the malicious inbound connections. In this scenario, if Sensor is deployed in front of the Web server, GTI along with Connection Limiting rules limit access to their servers (DOS prevention).
These defined Connection Limiting policies can also be assigned at the interface and sub-interface levels.
Refer Trellix Intrusion Prevention System Product Guide for more information.