The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Passive Device Profiling Setting at Sensor Level

Prev Next

This URL updates passive device profiling setting at the Sensor level.

Resource URL

PUT /sensor/<sensor_id>/passivedeviceprofiling

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensor_id Domain id Number Yes

Payload Parameters:

Field Name Description Data Type Mandatory
inheritSettingsfromParentNode Inherit settings from parent node Boolean Yes
passiveDeviceProfilingSetting Object that contains passive device profiling setting Object Yes
bindIPForCopiedDHCPTraffic Bind monitoring port of a Sensor to receive a DHCP traffic with a relay agent Boolean Yes
bindIPAddressDetails Object that contains monitoring port details for receiving DHCP traffic Object Yes
PassiveDeviceProfilingStateForSensor Passive device profiling state on Sensor String Yes
interfaceStatusList List of interfaces with enable status of passive device profiling setting in inbound/outbound direction Object Yes

Details of fields in passiveDeviceProfilingSetting:

Field Name Description Data Type Mandatory
profilingTechniques Profiling technique to use for device profiling Object Yes
profileExpiration Profile expiration duration for re-profiling of a device Object Yes
hostInactivityTimerInHrs Specifies the duration after which information for a device is considered invalid Number Yes

Details of fields in profilingTechniques:

Field Name Description Data Type Mandatory
DHCPEnableStatus Enable DHCP for device profiling Boolean Yes
TCPEnableStatus Enable TCP for device profiling Boolean Yes
HTTPEnableStatus Enable HTTP for device profiling Boolean Yes

Details of fields in profileExpiration:

Field Name Description Data Type Mandatory
duration Profile expiration duration Number Yes
unit Profile expiration duration unit, can be "MINUTES" / "HOURS" String Yes

Details of fields in bindIPAddressDetails:

Field Name Description Data Type Mandatory
designatedPort Monitoring port of a Sensor to receive a DHCP traffic with a relay agent String Yes
portIPAddress IP address of the monitoring port String Yes
networkMask Network mask String Yes
defaultGateway Default gateway String Yes
vlanID VLAN id String Yes

Details of object in interfaceStatusList:

Field Name Description Data Type Mandatory
interfaceId Interface id Number Yes
interfaceName Interface name String Yes
enableInbound Enable status in inbound direction Boolean Yes
enableOutbound Enable status in outbound direction Boolean Yes
subinterfaceStatusList List of sub-interfaces in a particular interface with enable status of passive device profiling in inbound/outbound direction Object Yes

Details of fields in subinterfaceStatusList:

Field Name Description Data Type Mandatory
interfaceId Interface id Number Yes
interfaceName Interface name String Yes
enableInbound Enable status in inbound direction Boolean Yes
enableOutbound Enable status in outbound direction Boolean Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Status returned by update Number

Example

Request

PUT https://%3CNSM_IP%3E/sdkapi/sensor/1001/passivedeviceprofiling

Payload

{
       		"inheritSettingsfromIPSSettingsNode": true,
       		"passiveDeviceProfilingSetting":
       		{
           		"profilingTechniques":
           		{
               			"DHCPEnableStatus": false,
               			"TCPEnableStatus": false,
               			"HTTPEnableStatus": true
           		},
           		"profileExpiration":
           		{
               			"duration": 10,
               			"unit": "HOURS"
           		},
           		"hostInactivityTimerInHrs": 11
       		},
       		"bindIPForCopiedDHCPTraffic": true,
       		"bindIPAddressDetails":
       		{
           		"designatedPort": "4A",
           		"portIPAddress": "100.100.100.10",
           		"networkMask": "255.255.0.0",
           		"defaultGateway": "100.100.100.1",
           		"vlanID": "10"
       		},
"PassiveDeviceProfilingStateForSensor": "ENABLE_DEVICEPROFILING_FOR_ENTIRE_DEVICE",
       		"interfaceStatusList":
       		[
           		{
               			"interfaceId": 117,
               			"interfaceName": "3B",
               			"enableInbound": true,
               			"enableOutbound": true
           		},
           		{
               			"interfaceId": 105,
               			"interfaceName": "1A-1B",
               			"enableInbound": true,
               			"enableOutbound": true,
               			"subinterfaceStatusList":
               			[
                   				{
                       				"subInterfaceId": 118,
                       				"subInterfaceName": "TestVLAN1",
                       				"enableInbound": true,
                       				"enableOutbound": true
                   				}
               			]
           		},
           		{
               			"interfaceId": 104,
               			"interfaceName": "2A-2B",
               			"enableInbound": true,
               			"enableOutbound": true
           		},
           		{
               			"interfaceId": 103,
               			"interfaceName": "3A",
               			"enableInbound": true,
               			"enableOutbound": true
           		},
           		{
               			"interfaceId": 102,
               			"interfaceName": "4A-4B",
               			"enableInbound": true,
              			 "enableOutbound": true
           		}
       		]
    	} 

Response

{
"status": 1
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 400 3301 Profile expiration value must be between 5 and 59 minutes
3 400 3302 Profile expiration value must be between 1 and 12 hours
4 400 3303 Profile expiration value cannot be greater than host inactivity timer
5 400 3304 Please enable at least one profiling technique
6 400 3305 Inter connecting port cannot be specified as monitoring port
7 400 3306 Invalid monitoring port
8 400 3307 Invalid port IP address
9 400 3308 Invalid network mask
10 400 3309 Invalid default gateway
11 400 3310 VLAN id should be between 0 and 65535