You can configure the details for the integration at an admin domain so that the corresponding Sensors and child domains can inherit these settings. However, you must enable the integration at the Sensor level for the Sensor and the Manager to be able to communicate with Intelligent Virtual Execution (IVX) engine.
In the Manager, select the Devices tab.
Select the domain from the Domain drop-down list.
On the left pane, click the Devices tab.
Select → .
Check Inherit Settings? if you want to inherit the integration configuration from the corresponding admin domain. The remaining fields are available only if this option is de-selected.
If you plan to have a customized configuration at Sensor level, deselect Inherit Settings? checkbox and select Enable IVX Integrationcheckbox. For steps on how to integration these solutions separately, refer to the sections Enable and Configure integration with IVX Appliance and Enable and Configure integration with IVX Cloud within this topic.
Enabling IVX Integration for a Sensor
.png)
Option definitions
Option
Definition
Inherit Settings?
Select this option to inherit the integration configuration from the corresponding admin domain. The remaining fields are available only if this is deselected.
Note
If you are inheriting admin domain configuration, make sure that both the Manager and the Sensor are running on software version 11.1 Update 4 or later. In case of heterogeneous scenarios where you are on a 11.1 Update 4 Manager and an older Sensor that supports only one broker node on IPv4, make sure you have added only one IPv4 broker address at Global level. If you have added an IPv6 address and the settings get inherited to the older Sensor, the file detection will not happen.
Note
Hence, it is highly recommended that you upgrade both the Manager and Sensor to 11.1 Update 4 or later releases to utilize multiple brokers which are connected over IPv4 and IPv6 addresses.
Enable IVX Integration
Select this option to integrate the Sensor with the IVX appliance or IVX Cloud.
Enable IVX: Enables IVX appliance integration
Enable IVX Cloud: Enables IVX Cloud integration
After you select, you will be able to view and configure the details for the integration.
Note
At any instance, you can choose to integrate either IVX or IVX Cloud with Trellix IPS, but not both of them together.
Save
Click Save when you enable or disable IVX Integration.
Enable and Configure integration with IVX Appliance
To enable and configure an IVX appliance integration, select the Enable IVX option.
Enabling IVX Appliance Integration for a Sensor
.png)
Option definitions
Option
Definition
IVX Appliance Configuration
Cluster Status
Displays the status of the cluster that an IVX broker node belongs to.
Ready: Cluster is ready and all the broker nodes are active.
: Any state other than Ready when one or more brokers are affected.---: Not available.
Note
The file submission to the cluster happens if the status is either
or
. However, in the
state, a few broker nodes might be down/not reachable but the file submission continues to happen to the active broker nodes.Broker Nodes Configured
Lists the IP address of the broker nodes configured for communication.
Listening Port
Displays the port that IVX appliance will listen for connections from Sensor and Manager. The default port is 443 and users cannot change it.
Enable Certificate Validation
Displays the status of the certificate validation as Enabled or Disabled.
Enable Proxy for IVX Communication
Displays the status of the proxy communication as Enabled or Disabled.
Add IVX Cluster
Allows you to add a cluster consisting of IVX broker nodes.
Remove IVX Cluster
Use this option if you plan to remove an existing cluster.
Save
Saves the integration details in the Manager database and applies them to the Sensor.
Note
The Add IVX Cluster, Remove IVX Cluster, and Save options will be hidden if:
You are viewing this page as a user with read-only access (or)
Manager is in Standby mode (or)
The device is disconnected
The Add IVX Cluster option allows you to add a cluster and its associated broker nodes. Click Add IVX Clusterdisplayed in the image Enabling IVX Integration for an admin domain.
A new page opens where you can configure the cluster and its associated broker nodes.
Adding broker nodes to a cluster
.png)
Option definitions
Option
Definition
Cluster Details
Note
Configuration done in this section will be applicable to all the broker nodes that you add.
Enable Certificate Validation
Select this option if you have configured CA signed certificate on the IVX appliance.
If the certificate is configured on the appliance, it is recommended to enable this option to ensure secure communication.
Enable Proxy for IVX communication
Select this option if you deployed proxy server between the Sensor and the IVX appliance.
You need to configure proxy server at device level page and enable proxy option under the IVX Appliance Configuration section.
Listening Port (TCP)
This is the port that IVX will listen for connections from Sensor and Manager. The default port is 443 and users cannot change it.
Cluster Status
Displays the status of the cluster that an IVX broker node belongs to.
Ready: Cluster is ready and all the broker nodes are active.
: Any state other than Ready when one or more brokers are affected.---: Not available.
Broker Nodes
Server Address
Enter the IP address (IPv4/IPv6) or Host Name of the IVX broker for communicating with the Manager and Sensor.
Note
In case you are on a Sensor software version prior to 11.1 Update 4, you can add only IPv4 address of the broker node.
Username
Username of the IVX broker node.
Manager to IVX Authentication Status
Displays the authentication status of the Manager with the IVX appliance.
Successful: Manager to IVX authentication is successful.
Unsuccessful: Manager to IVX authentication failed. User needs to recheck the credentials entered.---: Yet to be configured.
Manager to IVX Authentication Failure Reason
In case of Manager to IVX authentication failure, this column displays the reason for failure which helps users to take corrective actions and attain successful authentication.
In case of a successful connection, the column displays the status as ---.
Sensor to IVX Authentication Status
Displays the authentication status of the Sensor with the Trellix VX appliance.
Successful: Sensor to Trellix VX authentication is successful. User needs to recheck the credentials entered.
Unsuccessful: Sensor to Trellix VX authentication failed and the failure reason is displayed.---: Yet to be configured.
: Warning message description.
Test connection
Click to verify if the Manager and Sensor are able to communicate with the broker node(s) using the details you configured.
A Result pop-up appears displaying the status of the connection for all the configured broker nodes. Click OK to close the pop-up.
Note
When you click Test connection, the action is performed over all the newly added and existing broker nodes and the result is displayed.
.jpg)
Click this button to add a broker node.
Note
You can add a maximum of 5 broker nodes within a cluster.
Note
In case you are on a Sensor software version prior to 11.1 Update 4, you can add only 1 broker node.
Note
Users should ensure that the broker nodes added in this section belong to the same IVX cluster.
.jpg)
Click this button to remove newly added or existing broker nodes.
You can delete only one node at a time.
Next
Click this option upon modifying the broker node(s).
Cancel
Click this option to cancel the add/delete operation performed on the broker nodes.
Note
Cluster Status, Manager to IVX Authentication Status, Manager to IVX Authentication Failure Reason, and Manager to IVX Authentication Status are updated only when you save the configuration changes.
Upon clicking
, Add Broker Node panel appears in the right pane.Adding broker node details
.png)
Option definitions
Option
Definition
Server Address
Enter the IP address (IPv4/IPv6) or Host Name of the IVX broker for communicating with the Manager and Sensor.
Note
In case you are on a Sensor software version prior to 11.1 Update 4, you can add only one broker node which is on an IPv4 address.
Username
Enter the username of the IVX broker node.
Password
Enter the password of the IVX broker node.
Add
Click Add upon entering broker node details.
Note
The Add button remains grayed out if you enter invalid IP address.
Update
Double-click an existing broker node if you plan to make any modifications in it. Upon updating the fields with valid inputs, click Update.
Upon configuring the cluster and the broker nodes, click Next. You will be redirected to the IVX Integration home page., click Save.
Once the changes are saved, the IVX Appliance Configuration section appears as shown below:
IVX Appliance Configured
.png)
Note
If you plan to modify an existing cluster, double-click the cluster to go to the next page where you can update the Cluster Details and the Broker Nodes. Follow the above steps to make the modifications.
Enable and Configure integration with IVX Cloud
To enable and configure IVX cloud integration, select the Enable IVX Cloud option.
Enabling IVX Integration for a Sensor
.jpg)
Option definitions
Option
Definition
IVX Cloud Integration
Host Name
Enter the host name for the IVX Cloud service (that is, the domain name on which IVX Cloud service is hosted).
Note
You need to add a firewall exception to the domain (that you enter as Host Name) to ensure uninterrupted communication. For more information, see Set the desktop firewall.
API Key
Enter the API key created in the IVX Cloud portal. This key is used for authentication and it retrieves the IVX Cloud service status.
Note
The maximum character length supported is 6000.
Service Status
Displays the status of IVX Cloud service.
RUNNING: The IVX Cloud service is running and is available for malware file polling and retrieving the analysis reports.
Failed: User needs to recheck the configuration settings and the status of the IVX Cloud service. The failure reason is displayed which can be useful in troubleshooting the issue.---: Not applicable.
Listening Port
This is the port that IVX will listen for connections from Sensor and Manager. The default port is 443 and users cannot change it.
Enable Proxy for IVX Cloud Communication
Select this option if you deployed proxy server between the Sensor and IVX Cloud.
You need to configure proxy server at device level page and enable proxy option under the IVX Cloud Integration section.
Sensor to IVX Cloud Authentication Status
Displays the authentication status of the Sensor with IVX Cloud.
RUNNING: Sensor to IVX Cloud authentication is successful.
Failed: Sensor to IVX Cloud authentication is unsuccessful.
Pending: The authentication process stopped in the middle or did not take place until the status is returned.---: Yet to be configured.
Test connection
Click to verify if the Manager is able to communicate with IVX Cloud using the details you configured. If the details entered are correct and the IVX Cloud service is running, a Successful dialog-box appears. This ensures that the Sensors submit suspicious files for analysis, and the Manager retrieves the analysis result and display it in the user interface.
If there is an issue, an Error dialog-box appears displaying the failure reason which can be useful in troubleshooting.
Note
When you click Test connection, the action is performed over the currently selected configuration.
Save
Saves the integration details in the Manager database and applies them to the Sensor.
Note
The Service Status and Sensor to IVX Cloud Authentication Status are updated only when you save the configuration changes.
Upon saving the integration details, the IVX Cloud Integration section appears as shown below:
IVX Cloud integrated at device level
|
.jpg)