The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Network requirements

Prev Next

Connectivity with FireEye's Dynamic Threat Intelligence (DTI) network (one-way or two-way sharing) is required.

Endpoint Security (HX) appliances can download software updates (security content and system images) from the FireEye Dynamic Threat Intelligence (DTI) network. With a two-way content license, the appliance can also upload threat intelligence information to the DTI network. By default, CM-managed appliances receive software updates from the DTI network through the Central Management System appliance.

Standalone Endpoint Security (HX) appliances that receive DTI updates

The Central Management System appliance and standalone (not managed by Central Management System) appliances use the ether1 port to communicate directly with the DTI network. In the default configuration, where you receive updates from the DTI network (cloud.fireeye.com), allow outbound access to all IP addresses on the following ports:

  • DNS (UDP/53)

  • HTTPS (TCP/443)

Management interface ether1 requires a static IP address or reserved DHCP address and subnet mask.

Domain-based proxy ACL rules

If your configuration includes domain-based proxy ACL rules, allow access to *.fireeye.com.

Trellix Endpoint Security (HX) malware definitions

The malware protection provided with HX Series 4.0 and Trellix xAgent 26.21 (and later versions) use malware definitions to detect and identify files infected by malware. These malware definitions are downloaded by Trellix's Dynamic Threat Intelligence (DTI) cloud and the Endpoint Security (HX) server from avupdate.fireeye.com. However, if your security policy makes use of a firewall to restrict access to certain IP and web addresses, you need to configure your firewall rules to allow access to avupdate.fireeye.com. The IP addresses associated with avupdate.fireeye.com vary based on your environment. The following are some possible solutions.

  • Use DNS names instead of IP addresses in the firewall rules. The firewall rules will be automatically applied to the correct IP addresses as appropriate for avupdate.fireeye.com.

  • Do a DNS reverse lookup to identify the IP addresses used by avupdate.fireeye.com in your environment and then use those IP addresses in the firewall rules.

  • Use a caching proxy server to obtain the malware definition updates from avupdate.fireeye.com. Be sure your firewall rules allow access to *.fireeye.com.