The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Virtual IPS Sensor capacity

Prev Next

The following table describes the supported Virtual IPS Sensor capacity.

Virtual IPS Sensor capacity
Maximum Type IPS-VM600-VSS
Aggregate Performance 1 Gbps
Quarantine rules per Sensor - IPv4 1,000
Quarantine Zones per Sensor 50
Quarantine Zone ACLs per Sensor 1,000
Customized attacks

See the note below on how the number of customized attacks is affected.

100,000
Ignore rules 131,072
Number of attacks with ignore rules 100,000
DoS Profiles 300
SYN cookie rate (64-byte packets per second) 600,000
Effective (Firewall) access rules 2,000
Firewall rule objects member count for Sensors 24,000
Firewall DNS rule objects 750
Firewall rule object groups 200
Application on Custom Port rule objects 250
Firewall user-based rule objects 750
Firewall user groups in access rules 2,000
Number of exclusion list entries permitted for IP Reputation 64
Maximum host entries supported for Connection Limiting policies 128,000
Passive device profile limits 15,000
Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor

See the note below for more information.

32
Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor

See the note below for more information.

1,024

Note for Advanced Malware - Maximum simultaneous file scan

This feature is not the same as the file saving feature that is enabled through the Save File checkbox in the Advanced Malware Policies page of the Manager. It mentions the aspect of file saving that occurs temporarily within the Sensor during analysis. If the analysis result matches the severity configured in the Manager then the file is sent to the Manager to save.

Different outcomes based on your file saving configuration in the Advanced Malware Policies page are below:

  • If you have set the Save File to Disable in the Advanced Malware Policies page, the scanned files are not sent to the Manager.
  • If you have set the Save File to Always, all the scanned files are sent to the Manager to be archived. Before using this option, ensure that you have adequate disk space.
  • If you have set a severity for Save File, the scanned files are saved in the Sensor so that they can be analyzed by internal scanning engines like the PDF- JavaScript Engine. Once the analysis is complete and if the result is same or higher than the severity set, the file is sent to the Manager. When the Manager receives the file, it is saved in the Manager for future analysis by a security administrator.

Note for customized attacks

Customized attacks are not to be confused with custom attacks. A custom attack is a user-defined attack definition either in the Trellix IPS format or the Snort rules language. Whereas a customized attack is an attack definition (as part of the signature set), for which you modified its default settings. For example, if the default severity of an attack is 5 and you change it to 7, it is a customized attack.

The signature set push from the Manager to a Sensor fails if the number of customized attacks on the Sensor exceeds the customized attack limit.

The number of customized attacks can increase due to:

  • Modifications done to attacks on a policy by users.
  • Recommended for blocking (RFB) attacks.
  • User created asymmetric policies.

    Example: How numerous customized attacks are created in asymmetric policies.

    1. Create a policy.
    2. Set the Inbound rule set to "File Server rule set".
    3. Set the Outbound rule set to " Default Testing rule set".

      You see that:

      • The File Server rule set has 166 exploit attacks.
      • The Default Testing rule set has 2204 exploit attacks.

    The total number of customized attacks for this policy is 2204 – 116 = 2038 customized attacks.