Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

What is a Zoneless Trigger?

    • Updated:
    • 1 Aug 2017
    • Product/Version:
    • TippingPoint IPS N-series All
    • TippingPoint IPS NX-series All
    • TippingPoint IPS S-series All
    • Platform:
Summary
This article discusses what is a "Zoneless" trigger and how it is processed by TippingPoint IPS devices.
Details
Public

A zoneless trigger is a condition that occurs when an IPS device registers a filter trigger match on a segment even though the filter that is causing the trigger is not enabled in that particular segment.

This condition occurs because the triggering mechanism is enabled in a global context. When you enable a filter (irrespective of segment), the trigger is installed into Tier 1 (which is where trigger matching occurs). This trigger will then match against traffic from all segments. If the filter is only enabled on segment 1 but it triggers against traffic on segment 2, then the trigger match will be reported as Zoneless.

Example: A profile named "Internet" has filter 0164 (ICMP Echo request) enabled for block + notify and this profile is only applied to segment 1. Segments 2, 3 and 4, do not have filter 0164 enabled, but because the profile “Internet” on segment 1 has filter 0164 enabled, all "pings" detected through all segments will be sent for deep inspection but will only be blocked on segment 1 as that is the only segment that has the filter enabled.

View zoneless statistics: In order to view the zoneless statistics issue the CLI command “show np rule-stats”. This command will display the zoneless hits recorded by the IPS/TPS device since the last reboot or the last clear np rule-stats.

# show np rule-stats
Filter         Flows    Success    % Total    % Success    Zoneless    % Zoneless
23393         589705          0         38         0.00           0             0
30131         213508          0         14         0.00           0             0
23090         184458          0         12         0.00           0             0
30105         109000          0         7          0.00           0             0
20869          77165          0         5          0.00           0             0
20871          77164          0         5          0.00           0             0
22116          73922          0         4          0.00           0             0
22970          60454          0         3          0.00           0             0
22978          60443          0         3          0.00           0             0
23131          32757          0         2          0.00           0             0
23623          32568          0         2          0.00           0             0
23110           5456          0         0          0.00           0             0
30151           4005          0         0          0.00           0             0
Total of 1520605 flows


Note: Watch out for filters with lots of zoneless triggers, if you are experiencing performance problems, you may need to disable that filter across all segments, including the ANY-ANY segment.

Premium
Internal
Rating:
Category:
Configure; Troubleshoot; Deploy
Solution Id:
TP000085751
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.