Complete the following steps to configure the Trellix Global Threat Intelligence server for URL and IP Reputation:
Select → → → and select Endpoint/URL Reputation.
In the GTI Cloud for Endpoint/URL Reputation Queries, select Public.
In the URL Type, select IPv4 or IPv6 radio button.
Note
Based on the selected URL type, the server name for the Public GTI Endpoint/URL Reputation Queries updates automatically.
Click Save.
The Manager pushes the Trellix Global Threat Intelligence server for URL and IP Reputation configurations to the Sensors connected to the Manager.
Important
You must configure a proxy server in the Manager to get the location and severity of the IP address in the GTI Endpoint/URL reputation.
From 11.1 Minor 6 release, Trellix IPS uses ECDHE ciphers to connect to Public GTI for IP and URL Reputation. During the configuration, the Sensor receives ECDSA based client certificate bundle from the Manager. The ECDSA certificates expire annually. The renewed client certificate bundle are updated in the IPS Update Server. The Manager downloads the certificate bundle to send it to the Sensor whenever the client certificate is expired.
You can monitor the following certificate-related tasks on the User Activities tab of the Manager:
Certificate transfers (from Manager to Sensor): Verify certificate transfers to the Sensor by reviewing the user activities logged in the Manager.
Certificate downloads (From IPS Update Server to Manager): From release 11.1 Update 10 onwards, the Manager also logs when it downloads certificate bundles from the IPS Update Server. You can view these events on the User Activities tab to confirm whether the download was successful or failed.
If there are any issues such as invalid certificates, missing certificates, or DNS configuration issues, you can view the detailed information through several system generated Faults displayed in the Manager. For more information, see Manager critical faults. For any issues, contact Trellix support.