The following table describes the supported Virtual IPS Sensor capacity.
| Maximum Type | IPS-VM600-VSS |
|---|---|
| Aggregate Performance | 1 Gbps |
| Quarantine rules per Sensor - IPv4 | 1,000 |
| Quarantine Zones per Sensor | 50 |
| Quarantine Zone ACLs per Sensor | 1,000 |
| Customized attacks
See the note below on how the number of customized attacks is affected. |
100,000 |
| Ignore rules | 131,072 |
| Number of attacks with ignore rules | 100,000 |
| DoS Profiles | 300 |
| SYN cookie rate (64-byte packets per second) | 600,000 |
| Effective (Firewall) access rules | 2,000 |
| Firewall rule objects member count for Sensors | 24,000 |
| Firewall DNS rule objects | 750 |
| Firewall rule object groups | 200 |
| Application on Custom Port rule objects | 250 |
| Firewall user-based rule objects | 750 |
| Firewall user groups in access rules | 2,000 |
| Number of exclusion list entries permitted for IP Reputation | 64 |
| Maximum host entries supported for Connection Limiting policies | 128,000 |
| Passive device profile limits | 15,000 |
| Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor
See the note below for more information. |
32 |
| Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor
See the note below for more information. |
1,024 |
Note for Advanced Malware - Maximum simultaneous file scan
This feature is not the same as the file saving feature that is enabled through the Save File checkbox in the Advanced Malware Policies page of the Manager. It mentions the aspect of file saving that occurs temporarily within the Sensor during analysis. If the analysis result matches the severity configured in the Manager then the file is sent to the Manager to save.
Different outcomes based on your file saving configuration in the Advanced Malware Policies page are below:
- If you have set the Save File to Disable in the Advanced Malware Policies page, the scanned files are not sent to the Manager.
- If you have set the Save File to Always, all the scanned files are sent to the Manager to be archived. Before using this option, ensure that you have adequate disk space.
- If you have set a severity for Save File, the scanned files are saved in the Sensor so that they can be analyzed by internal scanning engines like the PDF- JavaScript Engine. Once the analysis is complete and if the result is same or higher than the severity set, the file is sent to the Manager. When the Manager receives the file, it is saved in the Manager for future analysis by a security administrator.
Note for customized attacks
Customized attacks are not to be confused with custom attacks. A custom attack is a user-defined attack definition either in the Trellix IPS format or the Snort rules language. Whereas a customized attack is an attack definition (as part of the signature set), for which you modified its default settings. For example, if the default severity of an attack is 5 and you change it to 7, it is a customized attack.
The signature set push from the Manager to a Sensor fails if the number of customized attacks on the Sensor exceeds the customized attack limit.
The number of customized attacks can increase due to:
- Modifications done to attacks on a policy by users.
- Recommended for blocking (RFB) attacks.
- User created asymmetric policies.
Example: How numerous customized attacks are created in asymmetric policies.
- Create a policy.
- Set the Inbound rule set to "File Server rule set".
- Set the Outbound rule set to " Default Testing rule set".
You see that:
- The File Server rule set has 166 exploit attacks.
- The Default Testing rule set has 2204 exploit attacks.
The total number of customized attacks for this policy is 2204 – 116 = 2038 customized attacks.