The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a Client Profile on the NI CLI

Prev Next

Prerequisites:

  • Make sure that you have set up an NI appliance and it is up and running. For more information on how to set up and perform initial configuration of the NI appliance, refer to Network Investigator System Administration Guide. If you wish to deploy a virtual instance of the NI appliance, refer to Network Investigator Deployment Guide.

  • Ensure that you have added an Inspection Options policy with Layer 7 Data Collection enabled at the required domain and have assigned it to the required interfaces and sub-interfaces. This enables the Sensor(s) to export L7 metadata to the NI as per the configuration of the Client Profile. Refer to the chapter Working with Inspection options policies for more detailed information.

Perform the following steps to create a Client Profile on the NI CLI:

  1. Log into the NI CLI using a terminal window or SSH client:

    • Using the SSH protocol, log into the appliance with management interface's IP address or hostname.

      $ ssh npadmin@<NI IP address>

    • Enter the password when prompted. The hostname > prompt is displayed after you have logged in.

  2. Enter privileged mode on the NI CLI

    npadmin@hostname> enable

  3. Enter the npadmin password, when prompted. The password can be 5 to 24 characters long.

    [sudo] password for npadmin: <password>

  4. Enter configuration mode

    npadmin@hostname# configure system

    The prompt changes to npadmin@hostname(config)# on the terminal indicating that configuration mode is enabled. You can now proceed with the Client Profile configuration task.

  5. Type client-profile at the terminal and press Enter.

    Client Profile configuration options are displayed on the terminal.

    Note

    If you already have one or more Client Profiles configured on the NI appliance, the prompt will display the names of the Client Profiles under the Profile(s) page in ascending numerical order starting with value 0.

    Note

    You can configure up to 20 Client Profiles on an NI appliance using its CLI.

    Profile(s)            
    ----------------------------------------
    
     0) IPS_Profile_SanJose
     1) IPS_Profile_SantaClara
     
    ----------------------------------------
    
    A) Add Profile
    #) Edit/Delete Profile
    Q) Exit
    
    ----------------------------------------
    
    Enter your choice:
    
  6. To add a new Client Profile, type A in the Enter your choice field and press Enter.

    Add new profile page is displayed with the configuration options on the terminal.

    Add new profile.
    ----------------------------------------
    
    1. Name            :
    2. L7 Metadata     : ['enabled':False,'event-types':0(count)]
    3. Alerts          : ['enabled':False,'severity-threshold':Low]
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select profile field
    
    ----------------------------------------
    
    Enter your choice:
    
  7. Type 1 and press Enter to create a name for the Client Profile being configured. Enter the name of the profile in the Enter profile name field and press Enter. The name given will now reflect in the Name section.

    Note

    If you wish to edit the Client Profile name, type 1 again in the Enter your choice field, and press Enter. Provide the new name and press Enter.

  8. Type 2 and press Enter to setup filters related to L7 metadata that you want to be exported to the NI by the Sensors when the NI integration is enabled in the Manager.

    Configure l7 metadata page is displayed on the terminal with the following configuration options.

    Configure l7 metadata.
    ----------------------------------------
    
    1. Enabled         : False
    2. Event types     : 0(count)
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select field to configure
    
    ----------------------------------------
    
    Enter your choice:
    • L7 metadata configuration is disabled by default. Type 1 and Press Enter to enable it. The Enabled field turns to True when it is enabled.

    • To enable or disable specific protocols, type 2 and press Enter.

      Enable/Disable event types configuration is displayed in 4 pages. All the protocols are disabled by default and shows N to reflect the disabled status. Type N and press Enter to go to the next page and P to go back to the previous page. The configuration options in all the 4 pages appear as the following on the NI CLI terminal:

      Enable/Disable event types     Page 1/4
      -------------------------------------------
       0. DCERPC          N
       1. DHCP            N
       2. DNS             N
       3. DNP3            N
       4. FILEINFO        N
       5. FLOW            N
       6. FTP             Y
       7. HTTP            Y
       8. HTTPS           Y
       9. IMAP            N
      
      
      -------------------------------------------
      N. Next Page
      E. Enable all on page
      C. Cancel and Return
      X. Save and Return
      # Toggle event type status
      
      -------------------------------------------
      
      Enter your choice:
      Enable/Disable event types     Page 2/4
      -------------------------------------------
       0. IRC             N
       1. KRB5            N
       2. MODBUS          N
       3. MQTT            N
       4. MYSQL           N
       5. NFS             N
       6. POP3            N
       7. RADIUS          N
       8. RDP             N
       9. RFB             N
      
      
      -------------------------------------------
      N. Next Page
      P. Previous Page
      E. Enable all on page
      C. Cancel and Return
      X. Save and Return
      # Toggle event type status
      
      -------------------------------------------
      
      Enter your choice:
      Enable/Disable event types     Page 3/4
      -------------------------------------------
       0. RTSP            N
       1. SIP             N
       2. SMB             N
       3. SMTP            Y
       4. SNMP            N
       5. SOCKS           N
       6. SSH             N
       7. TACPLUS         N
       8. TFTP            N
       9. TLS             N
      
      
      -------------------------------------------
      P. Previous Page
      E. Enable all on page
      C. Cancel and Return
      X. Save and Return
      # Toggle event type status
      
      -------------------------------------------
      
      Enter your choice:
      Enable/Disable event types     Page 4/4
      -------------------------------------------
       0. WEBSOCKET       N
      
      
      -------------------------------------------
      N. Next Page
      E. Enable all on page
      C. Cancel and Return
      X. Save and Return
      # Toggle event type status
      
      -------------------------------------------
      
      Enter your choice:
    • To enable a specific protocol, type the numeric value assigned to that protocol and press Enter. The status of the protocol changes to Y to reflect the enabled mode. For example, in the configuration options presented above, you need to type 7 and Press Enter to enable HTTP protocol on page 1. Repeat the same procedure for all the protocols you wish to enable as per your network requirement.

      Note

      Entering the numeric value associated with any protocol already enabled disables it, and changes the status to N to reflect the disabled mode.

      Note

      Currently, IPS Sensors export L7 metadata related to HTTP, HTTPS, HTTP2, SMTP, FTP, DNS, SMB, and DCERPC protocols to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later, and integrated with Trellix NI, send only SmartVision attack-related L7 metadata to NI. For more information on SmartVision attacks, see Harnessing SmartVision attacks for effective threat detection and response.

      Type E and press Enter if you wish to enable all the protocols in a page. To save and return to the Configure l7 metadata page, type X and Press Enter. Or, type C and press Enter to abort the changes made and return to the Configure l7 metadata page. As per the configuration options enabled, the Configure l7 metadata page would show the Enabled status and Event types count.

      Configure l7 metadata.
      ----------------------------------------
      
      1. Enabled         : True
      2. Event types     : 30(count)
      
      ----------------------------------------
      
      X. Save and Return
      C. Cancel and Return
      #. Select field to configure
      
      ----------------------------------------
      
      Enter your choice:

      To save and return to the Add new profile page, type X and press Enter.

  9. On Add new profile page, type 3 and press Enter to enable alerts based on alert severity thresholds.

    Configure alerts page is displayed on the terminal.

    Configure alerts.
    ----------------------------------------
    
    1. Enabled                   : False
    2. Severity Threshold        : Low
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select field to configure
    
    ----------------------------------------
    
    Enter your choice:
    • Filters specific to alert severity threshold is disabled by default. Type 1 and press Enter to enable the alert severity threshold configuration option. As a result, the Enabled status under the Configure alerts page changes to True.

    • You can now enable alerts as per the alert severity thresholds (Low, Medium, and High). When an alert severity threshold is set, it denotes that alerts of that level and above would be exported by the IPS Manager to NI after the successful integration between Trellix IPS and NI. The table below describes the alert severity thresholds and what they indicate:

      Alert Severity Thresholds

      Description

      Low

      Includes Low, Medium, and High severity alerts

      Medium

      Includes both Medium and High severity alerts

      High

      Includes only High severity alerts

    • The alert Severity Threshold is set to Low by default. If you wish to change it, type 2 and press Enter. Configure alert severity threshhold page is displayed on the terminal:

      Configure alert severity threshhold.
      ----------------------------------------
      
       1. Low
       2. Medium
       3. High
      
      ----------------------------------------
      
      
      C: Back to Prev Menu.
      
      Enter your choice:

      To enable an alert severity threshold level, type the corresponding numeric value assigned to the specific severity threshold, and press Enter. For example, if you wish to view only high severity alerts on the NI after its integration, type 3 and press Enter.

    • Once the alert severity threshold level is configured, you are redirected back to the Configure alerts page which shows the Enabled status and the Severity Threshold as configured:

      Configure alerts.
      ----------------------------------------
      
      1. Enabled                   : True
      2. Severity Threshold        : High
      
      ----------------------------------------
      
      X. Save and Return
      C. Cancel and Return
      #. Select field to configure
      
      ----------------------------------------
      
      Enter your choice:

      Press X and press Enter to save the changes and return to the Add new profile page in the Client Profile configuration task.

  10. Add new profile page is displayed, which shows the name of the Client Profile, L7 metadata configuration status and protocol count, and alert configuration status and severity threshold as configured, The example below shows the Client Profile Name as IPS_Profile, L7 metadata configuration status enabled for 30 protocols, and alerts enabled for High severity threshold.

    Add new profile.
    ----------------------------------------
    
    1. Name            : IPS_Profile
    2. L7 Metadata     : ['enabled':True,'event-types':30(count)]
    3. Alerts          : ['enabled':True,'severity-threshold':High]
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select profile field
    
    ----------------------------------------
    
    Enter your choice:
  11. Type X and press Enter to save the changes and finish the Client Profile configuration task. If you do not wish to proceed with the Client Profile configuration changes, type C and press Enter which will cancel all the configurations made and redirect you back to the Profile(s) page.

    Profile(s)            
    ----------------------------------------
    
     0) IPS_Profile_SanJose
     1) IPS_Profile_SantaClara
     2) IPS_Profile
    
    ----------------------------------------
    
    A) Add Profile
    #) Edit/Delete Profile
    Q) Exit
    
    ----------------------------------------
    
    Enter your choice: