The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Virtual IPS Sensor capacity by model number

Prev Next

The following table describes the supported Virtual IPS Sensor capacity.

Maximum Type IPS-VM600
Aggregate Performance 1 Gbps
Maximum throughput with test equipment sending UDP packet size of 1518 bytes Up to 1 Gbps
Concurrent connections 600,000
Connections established per second 20,000
Latency

(Average UDP per packet Latency)

< 100 us
SSL Flow count 30,000
Number of SSL certificates that can be imported into the Sensor 256
Throughput with SSL Decryption (based on 10% SSL traffic) 900 Mbps
Quarantine rules per Sensor - IPv4 1,000
Quarantine rules per Sensor - IPv6 500
Quarantine Zones per Sensor 50
Quarantine Zone ACLs per Sensor 1,000
Virtual Interfaces (VIDS) per Sensor 100
VLAN / CIDR Blocks per Sensor 300
VLAN / CIDR Blocks per Interface 254
Customized attacks

See the note below on how the number of customized attacks is affected.

100,000
Ignore rules 131,072
Number of attacks with ignore rules 100,000
DoS Profiles 300
SYN cookie rate (64-byte packets per second) 600,000
Effective (Firewall) access rules 2,000
Firewall rule objects 14,000
Firewall DNS rule objects 750
Firewall rule object groups 200
Application on Custom Port rule objects 250
Firewall user-based rule objects 750
Firewall user groups in access rules 2,000
Number of exclusion list entries permitted for IP Reputation 64
Maximum host entries supported for Connection Limiting policies 128,000
Passive device profile limits 15,000
Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor

See the note below for more information.

32
Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor

See the note below for more information.

1,024

Note for Advanced Malware - Maximum simultaneous file scan

The Advanced Malware - Maximum simultaneous file scan capacity with file save applies to all engines that require complete file for performing the malware analysis, such as Intelligent Sandbox, Gateway Anti-Malware, or Trellix IPS Analysis engines. It mentions the aspect of file saving that occurs temporarily within the Sensor during analysis. This feature is not the same as the file saving feature that is enabled through the Save File checkbox in the Advanced Malware Policies page of the Manager.

Different outcomes based on your file saving configuration using Save File checkbox in the Advanced Malware Policies page are below:

  • If you have set the Save File to Disable in the Advanced Malware Policies page, the scanned files are not sent to the Manager.
  • If you have set the Save File to Always, all scanned files are sent to the Manager to be archived. Before using this option, make sure that you have adequate disk space.
  • If you have set a severity for Save File, the scanned files are temporarily saved in the Sensor for malware analysis by engines such as AIntelligent Sandbox, Gateway Anti-Malware, or Trellix IPS Analysis. If the result is same or higher than the severity configured, the file is sent to the Manager. When the Manager receives the file, it is saved in the Manager for future analysis by a security administrator.

Note for customized attacks

Customized attacks are not to be confused with custom attacks. A custom attack is a user-defined attack definition either in the Trellix IPS format or the Snort rules language. Whereas a customized attack is an attack definition (as part of the signature set), for which you modified its default settings. For example, if the default severity of an attack is 5 and you change it to 7, it is a customized attack.

The signature set push from the Manager to a Sensor fails if the number of customized attacks on the Sensor exceeds the customized attack limit.

The number of customized attacks can increase due to:

  • Modifications done to attacks on a policy by users.
  • Recommended for blocking (RFB) attacks.
  • User created asymmetric policies.

    Example: How numerous customized attacks are created in asymmetric policies.

    1. Create a policy.
    2. Set the Inbound rule set to "File Server rule set".
    3. Set the Outbound rule set to " Default Testing rule set".

      You see that:

      • The File Server rule set has 166 exploit attacks.
      • The Default Testing rule set has 2204 exploit attacks.

    The total number of customized attacks for this policy is 2204 – 116 = 2038 customized attacks.