Use this file to discover all available pages before exploring further.
The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.
It is recommended that you configure your Manager server to fix the following vulnerability issues:
Vulnerability message
Port
Configuration Changes
X.509 Certificate Subject CN Does Not Match the Entity
Name (certificate-common-name-mismatch)
NA
Replace self-signed SSL certificate with a CA-signed SSL certificate. For more information, see the
KB59373 article.
SMB signing disabled (cifs-smb-signing-disabled)
SMB signing not required (cifs-smb-signing-not-required)
NA
Configure SMB signing for Windows. SMB signing is enabled on the server side if the following conditions are true:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Lanmanserver\Parameters\Enablesecuritysignature registry value is set to 1,or if the corresponding Group Policy setting is enabled.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Lanmanserver\Parameters\Requiresecuritysignature registry value is set to 0,or if the corresponding Group Policy setting is disabled.
TLS/SSL Birthday attacks on 64-bit block ciphers (SWEET32)
(ssl-cve-2016-2183-sweet32)
NA
Remove the TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher as it is insecure.
Disable support for TLSv1.0 & TLSv1.1
TLS/SSL Server Supports RC4 Cipher Algorithms
(CVE-2013-2566) (rc4-cve-2013-2566)
NA
Remove the TLS_RSA_WITH_RC4_128_MD5 and the TLS_RSA_WITH_RC4_128_SHA ciphers as they are insecure.
Disable support for TLSv1.0 & TLSv1.1
TLS/SSL Server Supports The Use of Static Key Ciphers (ssl-static-key-ciphers)
NA
Remove the following insecure ciphers as they are insecure.
TLS 1.0 ciphers:
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_RC4_128_MD5
TLS_RSA_WITH_RC4_128_SHA
TLS 1.1 ciphers:
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_RC4_128_MD5
TLS_RSA_WITH_RC4_128_SHA
TLS 1.2 ciphers:
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_RSA_WITH_RC4_128_MD5
TLS_RSA_WITH_RC4_128_SHA
Disable support for TLSv1.0 & TLSv1.1
TLS Server Supports TLS version 1.1 (tlsv1_1-enabled)
NA
Disable support for TLSv1.0 & TLSv1.1
Diffie-Hellman group smaller than 2048 bits (tls-dh-prime-under-2048-bits)
Na
Remove the following insecure ciphers as they are insecure.
TLS 1.0 ciphers:
TLS_DHE_RSA_WITH_AES_256_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits
TLS_DHE_RSA_WITH_AES_128_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits
TLS 1.1 ciphers:
TLS_DHE_RSA_WITH_AES_256_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits
TLS_DHE_RSA_WITH_AES_128_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits
Disable support for TLSv1.0 & TLSv1.1
TLS/SSL Server Is Using Commonly Used Prime Numbers (tls-dh-primes)
NA
Disable support for TLSv1.0 & TLSv1.1
ICMP timestamp response (generic-icmp-timestamp)
443
8501
8502
8503
8506
8507
8508
Enable Windows firewall and disable the ICMP timestamp response. To do this, perform the following steps:
Enable the windows firewall by selecting the
on (recommended) option.
Open a command prompt and enter
netsh firewall set icmpsetting 13 disable
Allow inbound and outbound communication on port 443 and all the ports used by the Manager to communicate with outside devices like Sensors, ePO, MVM, and so on. For communicating with the Sensor, the Manager uses ports 8501-8503 and 8506-8508.
Caution
If you do not create firewall rules with proper port information, applying this solution might break your existing communication.
TLS/SSL Server Supports 3DES Cipher Suite (ssl-3des-ciphers)
NA
Remove the following insecure ciphers as they are insecure.
TLS 1.0 ciphers:
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS 1.1 ciphers:
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS 1.2 ciphers:
TLS_RSA_WITH_3DES_EDE_CBC_SHA
Disable support for TLSv1.0 & TLSv1.1
SSL Certificate Signed Using Weak Hashing Algorithm
3389
Contact the Certificate Authority to issue a certificate signed with strong hashing algorithm.
Note
The exact vulnerability message might differ based on the Vulnerability Scanner you use.
Most of the configuration changes require changes to the Windows registry and you should be careful when changing the registry values. For general information on changing the Windows registry values, see the Microsoft Knowledge Base article
310516.