Review this section before your proceed with the integration between Trellix IPS and Trellix NI.
You need a Manager and Sensor(s) running on 11.1 Update 2 or later.
Note
Trellix NI integration supports all NS-Series as well as Virtual IPS Sensor models (i.e, VM600, VM5000, and VM600-VSS).
You need one or more NI appliances or NI cluster (physical, virtual and/or on Cloud) running software version 2.2.0 or later. Make sure that the NI appliance is up and running.
Note
For more information on how to set up and perform initial configuration of the NI appliance, refer to Network Investigator System Administration Guide. If you wish to deploy a virtual instance of the NI appliance, refer to Network Investigator Deployment Guide.
You can integrate multiple NI appliances with the Manager.
Ensure that you have added an Inspection Options policy with Layer 7 Data Collection enabled at the required domain and have assigned it to the required interfaces and sub-interfaces. This enables the Sensor(s) to export L7 metadata to the NI as per the Client Profile configuration.
Currently, IPS Sensors export L7 metadata related to HTTP, HTTPS, HTTP2, SMTP, FTP, DNS, SMB, and DCERPC protocols to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later, and integrated with Trellix NI, send only SmartVision attack-related L7 metadata to NI.
Important
Refer to the chapter Working with Inspection options policies for detailed information on how to add and assign an Inspections Options policy in the Manager.
See Enable Layer 7 Data Collection for an interface or subinterface for detailed information on how to view and customize protocol-specific L7 fields using the Manager.
See Harnessing SmartVision attacks for effective threat detection and response for more information on SmartVision attacks and how to work with them.