Configure an HTTP proxy server on the appliance to send network event logs to the Evidence Collector.
When you disable the HTTP proxy server, network event logs are sent directly to the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Trellix appliance.
Use the CLI commands in this topic to enable or disable an HTTP proxy server used by the Evidence Collector module to collect logs generated by the Trellix appliance.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix
A configured HTTP proxy server
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable the HTTP proxy server.
hostname (config) # fenet proxy enable
Configure the host IP address and port for the proxy server.
hostname (config) # fenet proxy host<hostname:port>
Configure the user name for the proxy server.
hostname (config) # fenet proxy auth basic user <user_name>
Configure the password for the proxy server.
hostname (config) # fenet proxy auth basic password <password>
Save your changes.
hostname (config) # write memory
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Disables the HTTP proxy server.
hostname (config) # no fenet proxy enable
Resets proxy settings to the default settings.
hostname (config) # no fenet proxy
Resets user name for the proxy server.
hostname (config) # no fenet proxy auth basic user
Resets the password for the proxy server.
hostname (config) # no fenet proxy auth basic password
Save your changes.
hostname (config) # write memory