Trellix IPS validates standard ports used across various protocols using the signature set.
You can add more than one non-standard port per protocol; however, you can only add one port at a time. If multiple ports have been added for a single protocol, all entered non-standard ports appear in one entry. Consider you added two non-standard ports, 1121 and 1281 for FTP traffic (standard FTP port is 21). Each non-standard port was added separately, yet both appear in the same entry.
To define non-standard ports for an admin domain:
Click the Devices tab.
From the Domain drop-down list, select the domain you want to work in.
On the left pane, click the Global tab.
Select IPS Device Settings → Non-Standard Ports.
To define non-standard ports for a Sensor:
Click the Devices tab.
Select the domain from the Domain drop-down list.
On the left pane, click the Devices tab.
Select the device from the Device drop-down list.
Select Setup → Advanced → Non-Standard Ports.
Click
and specify the options in the corresponding fields..png)
Option
Definition
Protocol
Lists the protocols for which you can specify the non-standard ports.
Enable SSL
To specify the non-standard port for HTTPS, select HTTP as the Protocol and select Enable SSL.
Transport
The Transport protocol is automatically selected based on the protocol selected. If applicable, you can toggle between TCP and UDP.
Standard Port Number
Automatically displays the standard port number for the selected protocol.
Non-Standard Port Number
Type a port number between 1 and 65535. You cannot enter a standard port number in this field.
Save
Saves the non-standard ports for the corresponding protocol.
Cancel
Ends adding the non-standard ports.
The Manager does not allow you to configure a standard port number for a protocol as the non-standard port. In such an event, the Manager displays the error "The non-standard port number cannot be same as the standard port number."
If the assigned non-standard port is a standard port for another protocol, the Manager displays the error "The input non-standard port number is the standard port number for <protocol name>.The update configuration to Sensor fails on set of this non-standard port number. Please try again with different settings."
If you upgrade from an older version of the Manager, and if there is a conflict between the non-standard port assigned and the standard port in the signature set, the signature set update fails. In this scenario, manually update the conflicting port number.
Click Save.
Perform a configuration update for the Sensor from Devices → <Admin Domain Name> → Global → Device Manager. Select the Sensors tab. Select the Sensor and click Deploy. Select the required configurations from Sync: <Device Name> window and click Deploy. For more information, see Deploy pending changes to a device.
Note
You can also perform configuration update from Devices → <Admin Domain Name> → Devices → <Device Name> → Deploy Pending Changes. Select the required configurations and click Deploy.