The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Virtual IPS Sensor capacity by model number

Prev Next

The following table describes the supported Virtual IPS Sensor capacity on VMware ESXi:

Maximum Type

IPS-VM600

IPS-VM5000

Aggregate Performance

1 Gbps

5 Gbps

Maximum throughput with test equipment sending UDP packet size of 1518 bytes

5 Gbps

9 Gbps

Concurrent connections

426,000

2,500,000

Connections established per second

97,000

149,000

Latency

(Average UDP per packet Latency)

< 100 us

< 100 us

SSL Flow count

30,000

120,000

Number of SSL certificates that can be imported into the Sensor

256

256

Throughput with SSL Decryption (based on 10% SSL traffic)

900 Mbps

4 Gbps

Quarantine rules per Sensor - IPv4

8,000

8,000

Quarantine rules per Sensor - IPv6

500

500

Quarantine Zones per Sensor

50

50

Quarantine Zone ACLs per Sensor

1,000

1,000

Virtual Interfaces (VIDS) per Sensor

100

100

VLAN / CIDR Blocks per Sensor

300

300

VLAN / CIDR Blocks per Interface

254

254

Customized attacks

See the note below on how the number of customized attacks is affected.

100,000

100,000

Ignore rules

131,072

131,072

Number of attacks with ignore rules

100,000

100,000

DoS Profiles

300

300

SYN cookie rate (64-byte packets per second)

600,000

600,000

Effective (Firewall) access rules

2,000

2,000

Firewall rule objects

14,000

24,000

Firewall DNS rule objects

750

750

Firewall rule object groups

200

200

Application on Custom Port rule objects

250

250

Firewall user-based rule objects

750

750

Firewall user groups in access rules

2,000

2,000

Number of exclusion list entries permitted for IP Reputation

64

128

Maximum host entries supported for Connection Limiting policies

128,000

128,000

Passive device profile limits

15,000

15,000

Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor

See the note below for more information.

32

32

Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor

See the note below for more information.

1,024

1,024

New HTTP connections per second (using 1 GET with 5000 HTTP response)

59,000

78,000

The following table describes the supported Virtual IPS Sensor capacity on Kernel-based Virtual Machine (KVM).

Maximum Type

IPS-VM600

IPS-VM5000

Aggregate Performance

1 Gbps

5 Gbps

Maximum throughput with test equipment sending UDP packet size of 1518 bytes

5 Gbps

9 Gbps

Concurrent connections

426,000

2,500,000

Connections established per second

80,000

125,000

Latency

(Average UDP per packet Latency)

< 100 us

< 100 us

SSL Flow count

30,000

120,000

Number of SSL certificates that can be imported into the Sensor

256

256

Throughput with SSL Decryption (based on 10% SSL traffic)

900 Mbps

4 Gbps

Quarantine rules per Sensor - IPv4

8,000

8,000

Quarantine rules per Sensor - IPv6

500

500

Quarantine Zones per Sensor

50

50

Quarantine Zone ACLs per Sensor

1,000

1,000

Virtual Interfaces (VIDS) per Sensor

100

100

VLAN / CIDR Blocks per Sensor

300

300

VLAN / CIDR Blocks per Interface

254

254

Customized attacks

See the note below on how the number of customized attacks is affected.

100,000

100,000

Ignore rules

131,072

131,072

Number of attacks with ignore rules

100,000

100,000

DoS Profiles

300

300

SYN cookie rate (64-byte packets per second)

600,000

600,000

Effective (Firewall) access rules

2,000

2,000

Firewall rule objects

14,000

24,000

Firewall DNS rule objects

750

750

Firewall rule object groups

200

200

Application on Custom Port rule objects

250

250

Firewall user-based rule objects

750

750

Firewall user groups in access rules

2,000

2,000

Number of exclusion list entries permitted for IP Reputation

64

128

Maximum host entries supported for Connection Limiting policies

128,000

128,000

Passive device profile limits

15,000

15,000

Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor

See the note below for more information.

32

32

Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor

See the note below for more information.

1,024

1,024

New HTTP connections per second (using 1 GET with 5000 HTTP response)

47,000

83,000

Note for Advanced Malware - Maximum simultaneous file scan

The Advanced Malware - Maximum simultaneous file scan capacity with file save applies to all engines that require complete file for performing the malware analysis, such as Intelligent Sandbox, Gateway Anti-Malware, or Trellix IPS Analysis engines. It mentions the aspect of file saving that occurs temporarily within the Sensor during analysis. This feature is not the same as the file saving feature that is enabled through the Save File checkbox in the Advanced Malware Policies page of the Manager.

Different outcomes based on your file saving configuration using Save File checkbox in the Advanced Malware Policies page are below:

  • If you have set the Save File to Disable in the Advanced Malware Policies page, the scanned files are not sent to the Manager.

  • If you have set the Save File to Always, all scanned files are sent to the Manager to be archived. Before using this option, make sure that you have adequate disk space.

  • If you have set a severity for Save File, the scanned files are temporarily saved in the Sensor for malware analysis by engines such as AIntelligent Sandbox, Gateway Anti-Malware, or Trellix IPS Analysis. If the result is same or higher than the severity configured, the file is sent to the Manager. When the Manager receives the file, it is saved in the Manager for future analysis by a security administrator.

Note for customized attacks

Customized attacks are not to be confused with custom attacks. A custom attack is a user-defined attack definition either in the Trellix IPS format or the Snort rules language. Whereas a customized attack is an attack definition (as part of the signature set), for which you modified its default settings. For example, if the default severity of an attack is 5 and you change it to 7, it is a customized attack.

The signature set push from the Manager to a Sensor fails if the number of customized attacks on the Sensor exceeds the customized attack limit.

The number of customized attacks can increase due to:

  • Modifications done to attacks on a policy by users.

  • Recommended for blocking (RFB) attacks.

  • User created asymmetric policies.

    Example: How numerous customized attacks are created in asymmetric policies.

    1. Create a policy.

    2. Set the Inbound rule set to "File Server rule set".

    3. Set the Outbound rule set to " Default Testing rule set".

      You see that:

      • The File Server rule set has 166 exploit attacks.

      • The Default Testing rule set has 2204 exploit attacks.

    The total number of customized attacks for this policy is 2204 – 116 = 2038 customized attacks.