Prerequisites:
To integrate the Public GTI Cloud for File Reputation with Trellix IPS you need to have the following:
Communication between the Manager and the Trellix IPS Update Server.
Name resolution configuration that allows the Sensor to resolve the hostname of the server that hosts the URL database.
Complete the following steps to configure the Trellix Global Threat Intelligence server for File Reputation:
Select → → → and select File Reputation.
In the GTI Cloud for File Reputation Queries, select Public.
In the URL Type, select IPv4 or IPv6 radio button.
Note
Based on the selected URL type, the server name for the Public GTI File Reputation Server Name updates automatically.
Click Save.
The Manager pushes the Trellix Global Threat Intelligence server configurations to the Sensors connected to the Manager.
Note
The GTI configurations from the Manager are sent to the Sensors in the following scenarios:
Trust establishment between the Manager and Sensor
Configuration change from private GTI to public GTI
When public GTI credentials are changed