Connectivity with FireEye's Dynamic Threat Intelligence (DTI) network (one-way or two-way sharing) is required.
Endpoint Security (HX) appliances can download software updates (security content and system images) from the FireEye Dynamic Threat Intelligence (DTI) network. With a two-way content license, the appliance can also upload threat intelligence information to the DTI network. By default, CM-managed appliances receive software updates from the DTI network through the Central Management System appliance.
Standalone Endpoint Security (HX) appliances that receive DTI updates
The Central Management System appliance and standalone (not managed by Central Management System) appliances use the ether1 port to communicate directly with the DTI network. In the default configuration, where you receive updates from the DTI network (cloud.fireeye.com), allow outbound access to all IP addresses on the following ports:
DNS (UDP/53)
HTTPS (TCP/443)
Management interface ether1 requires a static IP address or reserved DHCP address and subnet mask.
Domain-based proxy ACL rules
If your configuration includes domain-based proxy ACL rules, allow access to *.fireeye.com.
Trellix Endpoint Security (HX) malware definitions
The malware protection provided with HX Series 4.0 and Trellix xAgent 26.21 (and later versions) use malware definitions to detect and identify files infected by malware. These malware definitions are downloaded by Trellix's Dynamic Threat Intelligence (DTI) cloud and the Endpoint Security (HX) server from avupdate.fireeye.com. However, if your security policy makes use of a firewall to restrict access to certain IP and web addresses, you need to configure your firewall rules to allow access to avupdate.fireeye.com. The IP addresses associated with avupdate.fireeye.com vary based on your environment. The following are some possible solutions.
Use DNS names instead of IP addresses in the firewall rules. The firewall rules will be automatically applied to the correct IP addresses as appropriate for
avupdate.fireeye.com.Do a DNS reverse lookup to identify the IP addresses used by
avupdate.fireeye.comin your environment and then use those IP addresses in the firewall rules.Use a caching proxy server to obtain the malware definition updates from
avupdate.fireeye.com. Be sure your firewall rules allow access to*.fireeye.com.