The following table describes the supported Virtual IPS Sensor capacity on VMware ESXi:
Maximum Type | IPS-VM600 | IPS-VM5000 |
|---|---|---|
Aggregate Performance | 1 Gbps | 5 Gbps |
Maximum throughput with test equipment sending UDP packet size of 1518 bytes | 5 Gbps | 9 Gbps |
Concurrent connections | 426,000 | 2,500,000 |
Connections established per second | 97,000 | 149,000 |
Latency (Average UDP per packet Latency) | < 100 us | < 100 us |
SSL Flow count | 30,000 | 120,000 |
Number of SSL certificates that can be imported into the Sensor | 256 | 256 |
Throughput with SSL Decryption (based on 10% SSL traffic) | 900 Mbps | 4 Gbps |
Quarantine rules per Sensor - IPv4 | 8,000 | 8,000 |
Quarantine rules per Sensor - IPv6 | 500 | 500 |
Quarantine Zones per Sensor | 50 | 50 |
Quarantine Zone ACLs per Sensor | 1,000 | 1,000 |
Virtual Interfaces (VIDS) per Sensor | 100 | 100 |
VLAN / CIDR Blocks per Sensor | 300 | 300 |
VLAN / CIDR Blocks per Interface | 254 | 254 |
Customized attacks See the note below on how the number of customized attacks is affected. | 100,000 | 100,000 |
Ignore rules | 131,072 | 131,072 |
Number of attacks with ignore rules | 100,000 | 100,000 |
DoS Profiles | 300 | 300 |
SYN cookie rate (64-byte packets per second) | 600,000 | 600,000 |
Effective (Firewall) access rules | 2,000 | 2,000 |
Firewall rule objects | 14,000 | 24,000 |
Firewall DNS rule objects | 750 | 750 |
Firewall rule object groups | 200 | 200 |
Application on Custom Port rule objects | 250 | 250 |
Firewall user-based rule objects | 750 | 750 |
Firewall user groups in access rules | 2,000 | 2,000 |
Number of exclusion list entries permitted for IP Reputation | 64 | 128 |
Maximum host entries supported for Connection Limiting policies | 128,000 | 128,000 |
Passive device profile limits | 15,000 | 15,000 |
Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor See the note below for more information. | 32 | 32 |
Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor See the note below for more information. | 1,024 | 1,024 |
New HTTP connections per second (using 1 GET with 5000 HTTP response) | 59,000 | 78,000 |
The following table describes the supported Virtual IPS Sensor capacity on Kernel-based Virtual Machine (KVM).
Maximum Type | IPS-VM600 | IPS-VM5000 |
|---|---|---|
Aggregate Performance | 1 Gbps | 5 Gbps |
Maximum throughput with test equipment sending UDP packet size of 1518 bytes | 5 Gbps | 9 Gbps |
Concurrent connections | 426,000 | 2,500,000 |
Connections established per second | 80,000 | 125,000 |
Latency (Average UDP per packet Latency) | < 100 us | < 100 us |
SSL Flow count | 30,000 | 120,000 |
Number of SSL certificates that can be imported into the Sensor | 256 | 256 |
Throughput with SSL Decryption (based on 10% SSL traffic) | 900 Mbps | 4 Gbps |
Quarantine rules per Sensor - IPv4 | 8,000 | 8,000 |
Quarantine rules per Sensor - IPv6 | 500 | 500 |
Quarantine Zones per Sensor | 50 | 50 |
Quarantine Zone ACLs per Sensor | 1,000 | 1,000 |
Virtual Interfaces (VIDS) per Sensor | 100 | 100 |
VLAN / CIDR Blocks per Sensor | 300 | 300 |
VLAN / CIDR Blocks per Interface | 254 | 254 |
Customized attacks See the note below on how the number of customized attacks is affected. | 100,000 | 100,000 |
Ignore rules | 131,072 | 131,072 |
Number of attacks with ignore rules | 100,000 | 100,000 |
DoS Profiles | 300 | 300 |
SYN cookie rate (64-byte packets per second) | 600,000 | 600,000 |
Effective (Firewall) access rules | 2,000 | 2,000 |
Firewall rule objects | 14,000 | 24,000 |
Firewall DNS rule objects | 750 | 750 |
Firewall rule object groups | 200 | 200 |
Application on Custom Port rule objects | 250 | 250 |
Firewall user-based rule objects | 750 | 750 |
Firewall user groups in access rules | 2,000 | 2,000 |
Number of exclusion list entries permitted for IP Reputation | 64 | 128 |
Maximum host entries supported for Connection Limiting policies | 128,000 | 128,000 |
Passive device profile limits | 15,000 | 15,000 |
Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor See the note below for more information. | 32 | 32 |
Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor See the note below for more information. | 1,024 | 1,024 |
New HTTP connections per second (using 1 GET with 5000 HTTP response) | 47,000 | 83,000 |
Note for Advanced Malware - Maximum simultaneous file scan
The Advanced Malware - Maximum simultaneous file scan capacity with file save applies to all engines that require complete file for performing the malware analysis, such as Intelligent Sandbox, Gateway Anti-Malware, or Trellix IPS Analysis engines. It mentions the aspect of file saving that occurs temporarily within the Sensor during analysis. This feature is not the same as the file saving feature that is enabled through the Save File checkbox in the Advanced Malware Policies page of the Manager.
Different outcomes based on your file saving configuration using Save File checkbox in the Advanced Malware Policies page are below:
If you have set the Save File to Disable in the Advanced Malware Policies page, the scanned files are not sent to the Manager.
If you have set the Save File to Always, all scanned files are sent to the Manager to be archived. Before using this option, make sure that you have adequate disk space.
If you have set a severity for Save File, the scanned files are temporarily saved in the Sensor for malware analysis by engines such as AIntelligent Sandbox, Gateway Anti-Malware, or Trellix IPS Analysis. If the result is same or higher than the severity configured, the file is sent to the Manager. When the Manager receives the file, it is saved in the Manager for future analysis by a security administrator.
Note for customized attacks
Customized attacks are not to be confused with custom attacks. A custom attack is a user-defined attack definition either in the Trellix IPS format or the Snort rules language. Whereas a customized attack is an attack definition (as part of the signature set), for which you modified its default settings. For example, if the default severity of an attack is 5 and you change it to 7, it is a customized attack.
The signature set push from the Manager to a Sensor fails if the number of customized attacks on the Sensor exceeds the customized attack limit.
The number of customized attacks can increase due to:
Modifications done to attacks on a policy by users.
Recommended for blocking (RFB) attacks.
User created asymmetric policies.
Example: How numerous customized attacks are created in asymmetric policies.
Create a policy.
Set the Inbound rule set to "File Server rule set".
Set the Outbound rule set to " Default Testing rule set".
You see that:
The File Server rule set has 166 exploit attacks.
The Default Testing rule set has 2204 exploit attacks.
The total number of customized attacks for this policy is 2204 – 116 = 2038 customized attacks.