The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the SSL Configuration at the Domain Level

Prev Next

This URL updates the SSL configuration at the domain level.

Resource URL

PUT /domain/<domainId>/sslconfiguration

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domainID

Domain id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

inheritSettings

Inherit settings from parent domain.

Boolean

Yes

decryptionState

SSL state.

Values can be:

  • DISABLED

  • INBOUND

  • OUTBOUND

  • PROXY_INBOUND (For Inbound Proxy)

  • PROXY_INBOUND_OUTBOUND (For Inbound and Outbound Proxy)

String

Yes

anticipatedSSLTrafficUsage

Anticipated inbound SSL traffic usage.

Values can be:

  • VERY_LIGHT

  • LIGHT

  • MEDIUM

  • HEAVY

  • VERY_HEAVY

String

Yes

sslInactivityTimeoutInMinutes

The maximum amount of time a Sensor will keep an outbound SSL flow open when no data is seen on the Sensor.

Number

Yes

includeDecryptedPCAPS

Include decrypted packets while packet capture.

Boolean

Yes

enableDhSupport

DH support

Boolean

maxConcurrent

Maximum concurrent connections allowed between a Trellix Agent and a Sensor. The value can range from 1 to 1024.

Number

Yes

permittedIPv4CIDRBlocks

IPv4 CIDR blocks

Object

Yes

permittedIPv6CIDRBlocks

IPv6 CIDR blocks

Object

Yes

failureHandling

Failure handling

Object

Yes

Details of permittedIPv4CIDRBlocks and permittedIPv6CIDRBlocks.

Field Name

Description

Data Type

Mandatory

action

Action for the CIDR. The values can be "delete" for deletion.

Number

No

cidr

CIDR block

String

Yes

Details of failureHandling.

Field Name

Description

Data Type

Mandatory

untrustedOrExpiredServerCertificate

Action to take if the target web server's certificate is not on the Sensor's trusted CA list. Used only in case of outbound SSL. The values can be:

  • Block flow

  • Decrypt

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Set to 1 if the operation was successful

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/0/sslconfiguration

Payload

{
"inheritSettings": false,
  "decryptionState": "INBOUND",
  "anticipatedSSLTrafficUsage": "HEAVY",
  "sslInactivityTimeoutInMinutes": 1,
  "enableDhSupport": true,
  "maxConcurrent": 210,
   "permittedIPv4CIDRBlocks": [{"cidr":"10.1.1.0/23"}],
   "permittedIPv6CIDRBlocks": [{"cidr":"2001:DB9::1/122"}],
  "decryptedFlow": 20,
  "includeDecryptedPCAPS": false
}

Response

    {
"status": 1
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1105

Invalid domain

2

500

1001

Internal error