The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

View the applied DoS policies of a subinterface

Prev Next

The DoS Profile page of a subinterface provides operational details on the custom DoS policies applied to a subinterface. DoS policy was inherited from the interface upon subinterface creation, but might have changed due to one of the following conditions:

  • Application of a different policy for the subinterface.

  • Creation of one or more custom DoS policies for a subinterface. This was achieved by performing the Manage Custom action for an entire subinterface, for individual VLAN/CIDR IDs within a subinterface, or for a CIDR addresses within a VLAN or CIDR ID.

In DoS learning mode, a profile is built over a 48-hour period to determine the normal traffic pattern. Once the initial learning is complete, the Sensor detects traffic that is outside of the normal parameters while continuing to take measurements of network traffic and adjusting the profile accordingly. Activity outside of the normal parameters raises an alert. To view the DoS profiles at a subinterface level, do the following:

  • For individual Sensors, navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Denial of Service → Profiles.

  • For Sensors in HA pair, navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <HA Pair Node> → Troubleshooting → Denial of Service → Profiles.

  • (Applicable to NS9600 and NS9500 only) For Sensors in a stack and a HA pair of stack Sensors, navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Denial of Service → Profiles.

Option definitions

Option

Definition

Profile

The subinterface where DoS policy was applied. Default NI refers to all traffic that is not a part of a subinterface subdivision, that is, DoS ID for a VLAN tag or CIDR address within a subinterface.

Status

lists whether the profile is currently learning or detecting. Learning means the initial learning profile is being created to determine the normal traffic baseline. This learning period requires 48 hours. Detection means the profile has finished the initial learning period and traffic checking for abnormal levels is in progress.

Transition Time

The exact time when the learning profile started analysis or when the detection for the learning profile began. The Status field indicates which process is currently operating.



Optionally, select a DoS ID and click View to display rate data for the measures in the DoS profile applied to the selected DoS ID.

You can change the measure by toggling the direction and measure drop-down list. To return to the DoS Profiles page, click Close.