Before you begin
Disabling CBC protection allows the integration. Cipher block chain (CBC) protection is an operating mode in cryptography. Java uses CBC protection in SSL connections to counter the Beast Exploit against SSL/TLS (BEAST) threat, and a security vulnerability in an SSL socketFactory method. This security fix was introduced in Java version 6u29, which also introduced a bug that prevents SSL connections to SQL Server 2008. As a result, CBC protection interferes in the integration between the Manager and MS SQL database of Vulnerability Manager. Therefore, before you proceed with your configuration of Vulnerability Manager in the Manager, disable this feature by performing the steps below:
- Locate the tms.bat file in %programfiles%\Trellix\IPS Manager\App\bin.
- Open the file in a notepad application.
Text to disable CBC protection in Java 
- Scroll to locate the text displayed in the image as
.
- Once you have located the text, append it with the following entry:
set JAVA_OPTS=%JAVA_OPTS% -Djsse.enableCBCProtection=false
The text must be entered as displayed in the image as
.
- Save and the close the file.
- Reboot the Manager.
Once the Manager is back up you may proceed with the configuration.
The Vulnerability Manager configuration settings allow Manager to connect directly to the Scan engine servers and database.
You can configure the settings in two ways:
Task
- Manually navigating the configuration screens.
-
Using the Vulnerability Manager Configuration Wizard
Manually navigating the configuration screensFollowing steps are essential for manually configuring Vulnerability Manager settings (in the given order):
- Enabling Vulnerability Manager scanning — This is the first step required for successfully using the Vulnerability Manager on-demand scan functionality from Threat Explorer.
- Configuring Vulnerability Manager database settings — This step is essential for Manager to connect to the Vulnerability Manager database server, and import the required information from the database.
- Configuring Vulnerability Manager Server settings — Manager uses information from the Vulnerability Manager server to initiate Vulnerability Manager scans from Threat Explorer.
- Adding Vulnerability Manager scan configurations — If the IP address of the scanned host falls within any of the scan configurations added to Manager, that scan configuration is used for on-demand scan of the host from Threat Explorer. This step completes the configuration settings for Vulnerability Manager in Manager.
Using the Vulnerability Manager Configuration WizardThe Vulnerability Manager Configuration Wizard helps you to navigate the screens in the desired sequence.Select Manager → <Admin Domain Name> → Integration → Vulnerability Assessment → MVM → Vulnerability Scanning → Summary.Or,
Manager → <Child Admin Domain Name> → Integration → Vulnerability Assessment → MVM → Vulnerability Scanning → Summary and click Run Configuration Wizard to start the Vulnerability Manager Configuration Wizard.Vulnerability Manager Summary sub-tab 
Configuring Vulnerability Manager Settings in the Secondary Manager
If you have an MDR setup, before you proceed with your configuration of Vulnerability Manager in the Secondary Manager, perform the steps below:
Note
Ensure that the Secondary Manager is in standby mode.
Task
- Locate the tms.bat file in %programfiles%\Trellix\IPS Manager\App\bin.
-
Open the file in a notepad application.
Text to disable CBC protection in Java 
-
Scroll to locate the text displayed in the image as
.
-
Once you have located the text, append it with the following entry:
set JAVA_OPTS=%JAVA_OPTS% -Djsse.enableCBCProtection=false
The text must be entered as displayed in the image as
.
- Save and close the file.
- Reboot the Secondary Manager.
- Make the Secondary Manager active by clicking Force Switch in the Manager → <Admin Domain Name> → Setup → MDR.
-
Start the FCM agent service. From the Windows
Start button, click
Run and open
Services.
You can find the Found stone Configuration Management (FCM) Agent.
-
Click the
Start button (
) to start the FCM Agent service.
-
In the Manager, select
Manager → <Admin Domain Name> → Integration → Vulnerability Assessment → MVM → Vulnerability Scanning → API Server.
The Retrive MVM Certificate option is enabled.
- Click Retrive MVM Certificate to import the client certificates into the Manager keystore.