The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Troubleshooting Connection Limiting issues

Prev Next

After Connection Limiting policies are configured, you might come across issues like the following:

  • No alerts are raised in the Manager.

  • Excess packets are not dropped or denied.

  • Hosts are not quarantined.

Connection Limiting rules can be configured with protocol types Alert only, Alert & Drop Excess Connections, Alert & Deny Excess Connections, and Alert & Quarantine.

Perform these steps to troubleshoot issues such as alerts not raised in the Manager, excess packets not dropped or denied, or hosts not quarantined after reaching the threshold value.

  1. Make sure that the Connection Limiting policy rules are configured and applied to the Sensor interface.

  2. From the Sensor CLI, run the show inlinepktdropstat all command and check if the Conn Limiting Pkt Drop Count is 0. This means that the configured threshold value is not reached. Only when the count reaches a threshold value, alerts are triggered in the Manager.

  3. Check whether the incoming traffic rate to the Sensor meets the Connection Limiting rule's threshold value. If it does not meet the threshold value, send the corresponding traffic rate.

  4. Set a lower threshold value and check the active connections or connections per second.

  5. Check if there is any firewall ignore rule for the source IP address configured in the Connection Limiting rule.

    1. Go to Policy → Intrusion Prevension → Policy Types → Firewall Policies → <Firewall Policy> → Access Rules.

    2. Select a policy and click Edit to view the rules of that policy or double-click on the row of the policy.

    3. On the Access Rules tab, check if a source IP address's Response is set as Stateless Ignore or Ignore.

  6. Check if the source IP address configured in the Connection Limiting rule is part of the Quarantine Exceptions list. Go to Devices → Global → IPS Device Settings → Quarantine → Default Port Settings to if source IP address is quarantined.

Considerations for GTI connection limiting and XFF feature

When you configure GTI and XFF for a connection limiting rule:

  • The Sensor cannot perform GTI lookup on the XFF IP address. The GTI-based connection limiting does not work when the XFF feature is enabled.

  • When the XFF feature is enabled, the Sensor expects that all HTTP flows should have XFF data in the HTTP header.

  • The Sensor supports connection limiting on XFF based on protocol-based connection limiting.

Alert Detection Matrix

The table briefs how alerts are detected based on the connection limiting type and XFF feature configuration.

Connection limiting type

XFF configuration

XFF or Non XFF tag traffic sent to Sensor

Proxy IP reputation

XFF IP

Alert detection

Protocol

Disabled

Without XFF

-

Yes

Protocol

Enabled

With XFF

-

Yes

Protocol

Enabled

Without XFF

-

No

GTI

Disabled

Without XFF

-

Yes

GTI

Enabled

With XFF

Low risk

High risk

No

GTI

Enabled

With XFF

High risk

Low risk

No

GTI

Enabled

Without XFF

-

-

No