The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the TCP Settings on Sensor

Prev Next

This URL updates the TCP settings on the Sensor.

Resource URL

PUT /sensor/<sensor_id>/tcpsettings

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensor_id Sensor id Number Yes

Payload Parameters:

Field Name Description Data Type Mandatory
TCPSettings The TCP settings on the Sensor Object Yes

Details of fields in TCPSettings:

Field Name Description Data Type Mandatory
tcpParameter The parameters of TCP settings Object No

Details of fields in tcpParameter:

Field Name Description Data Type Mandatory
supportedUDPFlows The supported UDP flows Number No
tcbInactivityTimesInMinutes The TCP inactivity timer(minutes) Number No
tcpSegmentTimerInSeconds The TCP segment timer(seconds) Number No
tcp2MSLTimerInSeconds The TCP 2MSL timer (seconds) Number No
coldStartTimeInMinutes The cold start time (minutes) Number No
coldStartAckScan

AlertDiscardIntervalInMinutes

The cold start ack scan alert discard Interval (minutes) Number No
coldStartDropAction The cold start drop action. The value can be:
  • DROP_FLOWS
  • FORWARD_FLOWS
String No
tcpFlowViolation The TCP flow violation. The value can be:
  • PERMIT
  • DENY
  • PERMIT_OUT_OF_ORDER
  • DENY_NO_TCB
  • STATELESS_INSPECTION
String No
unsolicitedUDP

PacketTimeOutInSeconds

The unsolicited UDP packets timeout (seconds) Number No
Normalization The normalization. The value can be:
  • ON
  • OFF
String No
tcpOverlapOption The TCP overlap option. The value can be:
  • OLD_DATA
  • NEW_DATA
String No
synCookie The SYN cookie data Object No
resetUnfinished3Way

HandshakeConnection

The reset unfinished 3 way handshake connection. The value can be:
  • DISABLED
  • SET_FOR_ALL_TRAFFIC
  • SET_FOR_DOS_ATTACK_TRAFFIC_ONLY
String No
dnsSinkholingTimeToLive DNS sinkholing time to live Number No
dnsSinkholingIPAddress DNS sinkholing IP address String No

Details of fields in synCookie:

Field Name Description Data Type Mandatory
synCookieOption The SYN cookie option. The value can be:
  • DISABLED
  • INBOUND_ONLY
  • OUTBOUND_ONLY
  • BOTH_INBOUND_AND_OUTBOUND
String Yes
inboundThresholdValue The inbound threshold value Number No
outboundThresholdValue The outbound threshold value Number No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Set to 1 if the operation was successful Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1002/tcpsettings

Payload

{
	"tcpParameter": {
		"supportedUDPFlows": 100,
		"tcbInactivityTimesInMinutes": 10,
		"tcpSegmentTimerInSeconds": 10,
		"tcp2MSLTimerInSeconds": 10,
		"coldStartTimeInMinutes": 0,
		"coldStartAckScanAlertDiscardIntervalInMinutes": 0,
		"coldStartDropAction": "FORWARD_FLOWS",
		"tcpFlowViolation": "PERMIT_OUT_OF_ORDER",
		"unsolicitedUDPPacketTimeOutInSeconds": 10,
		"normalization": "OFF",
		"tcpOverlapOption": "NEW_DATA",
		"synCookie": {
			"synCookieOption": "INBOUND_ONLY",
			"inboundThresholdValue": 14112,
			"outboundThresholdValue": 10000
		},
  "dnsSinkholingTimeToLive": 720,
  "dnsSinkholingIPAddress": "1.1.1.1"
		"resetUnfinished3WayHandshakeConnection": "SET_FOR_DOS_ATTACK_TRAFFIC_ONLY"
	}
} 

Response

{
"status": 1
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 400 1124 The Sensor is inactive
3 400 5501 Supported UDP flows should be between <value>
4 400 5502 TCB inactivity time should be between 10 and 1200
5 400 5503 TCP segment timer should be between 10 and 120
6 400 5504 TCP 2MSL should be between 3 and 120 and the value should be 3 sec more than the correlation time for signatures. Correlation time is <value>
7 400 5505 Cold start time should be between 0 and 10080
8 400 5506 Cold start ack scan alert discard interval should be between 0 and 1440
9 400 5507 Unsolicited UDP packet timeout should be between 10 and 3600
10 400 5508 Disable SYN cookie first before setting TCP flow violation to stateless inspection
11 400 5509 SYN cookie must be set to DISABLED when TCP flow violation is stateless inspection
12 400 5510 Cannot update SYN cookie when TCP flow violation is set to stateless inspection
13 400 5515 Syncookie threshold value should be between 0 and <value>
14 400 5516 Syncookie threshold value is mandatory