The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Inspection Options Policy

Prev Next

This URL updates the inspection options policy.

Resource URL

PUT /protectionoptionspolicy/<policy_id>

Request Parameters

URL Parameter

Field Name

Description

Data Type

Mandatory

policy_id

Policy id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

policyId

Policy id

Number

policyName

Policy name

String

domainId

Domain id

Number

visibleToChild

Visible to child

Boolean

description

Description

String

protectionOptions

All options tabs

Object

Details of protectionOptions:

Field Name

Description

Data Type

inspectionOptions

Inspection options

Object

advancedBotnetDetectionOptions

Advanced botnet detection options

Object

gtiEndpointReputationAnalysysOptions

GTI endpoint reputation analysis options

Object

webserverHuresticAnalysysOptions

Web server heuristic analysis options

Object

webserverDOSOptions

Web server DoS options

Object

Details of inspectionOptions:

Field Name

Description

Data Type

httpResponseTrafficScanning

HTTP response traffic scanning

String

httpResponseDecompression

HTTP response decompression

String

chunkedHTTPResponseDecoding

Chunked HTTP response decoding

String

htmlEncodedHTTPResponseDecoding

HTML encoded HTTP response decoding

String

base64SMTPDecoding

Base64 SMTP decoding

String

description

Description

String

quotedPrintableSMTPDecoding

Quoted printable SMTP decoding

String

http2TrafficScanning

HTTP2 traffic scanning

String

http2ServerPushScanning

HTTP2 server push scanning

String

msRPCSMBFragmentReassembly

MSRPC SMB fragment reassembly

String

msOfficeDeepFileInspection

Microsoft Office deep file inspection

String

xffHeaderParsing

XFF header parsing

String

layer7DataCollection

Layer 7 data collection

String

passiveDeviceProfiling

Passive device profiling

String

attackBlockingSimulation

Attack blocking simulation

String

Possible values for above attributes should be:

  1. INBOUND_ONLY

  2. OUTBOUND_ONLY

  3. DISABLED

  4. INBOUND_AND_OUTBOUND

Details of advancedBotnetDetectionOptions:

Field Name

Description

Data Type

advancedBotnetDetection

Advanced botnet detection

String

sensitivity

Sensitivity

String

fastFluxDetection

Fast flux detection

String

domainGenerationAlgorithmDetection

Domain generation algorithm detection

String

domainNameAllowlistProcessing

Domain name allow list processing

String

exportTrafficToNTBA

Export traffic to NTBA

Boolean

dnsSinkHooling

DNS sink holing

String

Possible values for above attributes should be:

  1. INBOUND_ONLY

  2. OUTBOUND_ONLY

  3. DISABLED

  4. INBOUND_AND_OUTBOUND

Possible values for sensitivity should be:

  1. LOW

  2. MEDIUM

  3. HIGH

Details of gtiEndpointReputationAnalysysOptions:

Field Name

Description

Data Type

gtiEndpointReputationAnalysys

GTI endpoint reputation analysis

  • INBOUND_ONLY

  • OUTBOUND_ONLY

  • DISABLED

  • INBOUND_AND_OUTBOUND

String

useToInfluenceSmartBlocking

Use to influence SmartBlocking

Boolean

excludeInternalEndpoint

Exclude internal endpoint

Boolean

cidrsExcluded

CIDRs excluded

Stringlist

protocalsExcluded

Protocols excluded

Stringlist

urlReputationAnalysis

URL reputation analysis

String

urlReputationMinimumRisk

URL reputation minium risk:

Valid Values:

  1. HIGH

  2. MEDIUM

String

Details of webserverHuresticAnalysysOptions:

Field Name

Description

Data Type

huresticAnalysys

Heuristic analysis. Direction value as specified above

String

websitePathToProtect

Options: ALL or SPECIFIC

String

blockedTextList

Blocked text list

Stringlist

websitePathToProtectList

Website path to protect list

Stringlist

Details of webserverDOSOptions:

Field Name

Description

Data Type

dosPrevention

DoS prevention: direction mode

String

maxConnectionAllowedToWS

Max connection allowed to WS

Number

slowConnectionAttackPrevention

Slow connection attack prevention

Boolean

maxHTTPRequestPERSecondTOAnyPath

max HTTP request per second to any path

Number

websitePathToProtect

Website path to protect options: ALL or SPECIFIC

String

browserDetectionMethod

Browser detection method

String

websitePathToProtectList

Website path to protect list

Objectlist

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Operation status

Int

Example

Request

PUT https://<NSM_IP>/sdkapi/protectionoptionspolicy/1

{
"policyId": 1,
"policyName": "Default Client and Server Inspection",
"domainId": 0,
"visibleToChild": true,
"description": "Inspect traffic both from internal endpoints and to exposed Web and mail servers",
"isEditable": false,
"lastUpdatedBy": "admin",
"lastUpdated": "Jun 25 18:27",
"protectionOptions": 
{
"inspectionOptions": 
{
"httpResponseTrafficScanning": "INBOUND_AND_OUTBOUND",
"httpResponseDecompression": "INBOUND_AND_OUTBOUND",
"chunkedHTTPResponseDecoding": "INBOUND_AND_OUTBOUND",
"htmlEncodedHTTPResponseDecoding": "INBOUND_AND_OUTBOUND",
"base64SMTPDecoding": "DISABLED",
"quotedPrintableSMTPDecoding": "DISABLED",
"http2TrafficScanning": "INBOUND_AND_OUTBOUND",
"http2ServerPushScanning": "INBOUND_AND_OUTBOUND",
"msRPCSMBFragmentReassembly": "DISABLED",
"msOfficeDeepFileInspection”: “DISABLED",
"xffHeaderParsing": "INBOUND_AND_OUTBOUND",
"layer7DataCollection": "INBOUND_AND_OUTBOUND",
"passiveDeviceProfiling": "INBOUND_AND_OUTBOUND",
"attackBlockingSimulation": true
}
,
"advancedBotnetDetectionOptions": 
{
"advancedBotnetDetection": "DISABLED", 
"exportTrafficToNTBA": false
}
,
"gtiEndpointReputationAnalysysOptions": 
{
"gtiEndpointReputationAnalysys": "DISABLED", 
"useToInfluenceSmartBlocking": false, 
"excludeInternalEndpoint": false,
"urlReputationAnalysis”: “INBOUND_ONLY",
"urlReputationMinimumRisk:”MEDIUM"

}
,
"webserverHuresticAnalysysOptions": 
{
"huresticAnalysys": "INBOUND_ONLY",
"websitePathToProtect": "ALL",
"blockedTextList": [],
"websitePathToProtectList": [],
}
,
"webserverDOSOptions": 
{
"dosPrevention": "INBOUND_ONLY",
"maxConnectionAllowedToWS": 750000,
"slowConnectionAttackPrevention": true,
"maxHTTPRequestPERSecondTOAnyPath": 10000,
"websitePathToProtect": "ALL",
"clientBrowserDetection": true,
"browserDetectionMethod": "HTML_CHALLENGE",
"websitePathToProtectList": [],
}
}
}

Response

  {
       "status":1
   }

Error Information

Following error code is returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

400

4301

Invalid domain id