The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the TCP Settings on Sensor

Prev Next

This URL updates the TCP settings on the Sensor.

Resource URL

PUT /sensor/<sensor_id>/tcpsettings

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

TCPSettings

The TCP settings on the Sensor

Object

Yes

Details of fields in TCPSettings:

Field Name

Description

Data Type

Mandatory

tcpParameter

The parameters of TCP settings

Object

No

Details of fields in tcpParameter:

Field Name

Description

Data Type

Mandatory

supportedUDPFlows

The supported UDP flows

Number

No

tcbInactivityTimesInMinutes

The TCP inactivity timer(minutes)

Number

No

tcpSegmentTimerInSeconds

The TCP segment timer(seconds)

Number

No

tcp2MSLTimerInSeconds

The TCP 2MSL timer (seconds)

Number

No

coldStartTimeInMinutes

The cold start time (minutes)

Number

No

coldStartAckScan

AlertDiscardIntervalInMinutes

The cold start ack scan alert discard Interval (minutes)

Number

No

coldStartDropAction

The cold start drop action. The value can be:

  • DROP_FLOWS

  • FORWARD_FLOWS

String

No

tcpFlowViolation

The TCP flow violation. The value can be:

  • PERMIT

  • DENY

  • PERMIT_OUT_OF_ORDER

  • DENY_NO_TCB

  • STATELESS_INSPECTION

String

No

unsolicitedUDP

PacketTimeOutInSeconds

The unsolicited UDP packets timeout (seconds)

Number

No

Normalization

The normalization. The value can be:

  • ON

  • OFF

String

No

tcpOverlapOption

The TCP overlap option. The value can be:

  • OLD_DATA

  • NEW_DATA

String

No

synCookie

The SYN cookie data

Object

No

resetUnfinished3Way

HandshakeConnection

The reset unfinished 3 way handshake connection. The value can be:

  • DISABLED

  • SET_FOR_ALL_TRAFFIC

  • SET_FOR_DOS_ATTACK_TRAFFIC_ONLY

String

No

dnsSinkholingTimeToLive

DNS sinkholing time to live

Number

No

dnsSinkholingIPAddress

DNS sinkholing IP address

String

No

http2FlowAllocPrcnt

HTTP2 flow allocation %

Number

Yes

slowPostTimeout

Slow post timeout

Number

No

slowPostThresholdFrameSize

Slow post threshold frame size

Number

No

slowPostMinStreamsCnt

Slow post minimum number of streams

Number

No

slowPostMinTinyFramesCnt

Slow post minimum number of tiny frames

Number

No

slowReadTimeout

Slow read timeout

Number

No

slowReadWindowSize

Slow read window size

Number

No

slowReadMinStreamsCnt

Slow read minimum number of streams

Number

No

http2DecodedPktInAtckPktLogFlag

HTTP2 decoded packets in attack packet log

Number

No

ftpAcceleration

FTP acceleration

String

No

Details of fields in synCookie:

Field Name

Description

Data Type

Mandatory

synCookieOption

The SYN cookie option. The value can be:

  • DISABLED

  • INBOUND_ONLY

  • OUTBOUND_ONLY

  • BOTH_INBOUND_AND_OUTBOUND

String

Yes

inboundThresholdValue

The inbound threshold value

Number

No

outboundThresholdValue

The outbound threshold value

Number

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Set to 1 if the operation was successful

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1002/tcpsettings

Payload

{
"tcpParameter": {
"supportedUDPFlows": 100,
"tcbInactivityTimesInMinutes": 10,
"tcpSegmentTimerInSeconds": 10,
"tcp2MSLTimerInSeconds": 10,
"coldStartTimeInMinutes": 0,
"coldStartAckScanAlertDiscardIntervalInMinutes": 0,
"coldStartDropAction": "FORWARD_FLOWS",
"tcpFlowViolation": "PERMIT_OUT_OF_ORDER",
"unsolicitedUDPPacketTimeOutInSeconds": 10,
"normalization": "OFF",
"tcpOverlapOption": "NEW_DATA",
"synCookie": {
"synCookieOption": "INBOUND_ONLY",
"inboundThresholdValue": 14112,
"outboundThresholdValue": 10000
},
"resetUnfinished3WayHandshakeConnection": "DISABLED",
"dnsSinkholingTimeToLive": 720,
"dnsSinkholingIPAddress": "127.0.0.1",
"http2FlowAllocPrcnt": 5,
"slowPostTimeout": 5,
"slowPostThresholdFrameSize": 10,
"slowPostMinStreamsCnt": 50,
"slowPostMinTinyFramesCnt": 1,
"slowReadTimeout": 60,
"slowReadWindowSize": 10,
"slowReadMinStreamsCnt": 50,
"http2DecodedPktInAtckPktLogFlag": "2",
"ftpAcceleration": "DISABLED"
}
}

Response

{
"status": 1
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

400

1124

The Sensor is inactive

3

400

5501

Supported UDP flows should be between <value>

4

400

5502

TCB inactivity time should be between 10 and 1200

5

400

5503

TCP segment timer should be between 10 and 120

6

400

5504

TCP 2MSL should be between 3 and 120 and the value should be 3 sec more than the correlation time for signatures. Correlation time is <value>

7

400

5505

Cold start time should be between 0 and 10080

8

400

5506

Cold start ack scan alert discard interval should be between 0 and 1440

9

400

5507

Unsolicited UDP packet timeout should be between 10 and 3600

10

400

5508

Disable SYN cookie first before setting TCP flow violation to stateless inspection

11

400

5509

SYN cookie must be set to DISABLED when TCP flow violation is stateless inspection

12

400

5510

Cannot update SYN cookie when TCP flow violation is set to stateless inspection

13

400

5515

Syncookie threshold value should be between 0 and <value>

14

400

5516

Syncookie threshold value is mandatory

15

400

5520

Slow post timeout should be between 5 and 30

16

400

5521

Slow Post threshold framesize should be between 1 and 100

17

400

5522

Slow Post min stream count should be between 50 and 100

18

400

5523

Slow Post Min Tiny Frame count should be between 1 and 10

19

400

5524

Slow Read Timeout should be between 30 and 300

20

400

5525

Slow read window size should be between 1 and 100

21

400

5526

Slow Read min streamcount should be between 50 and 100