The integration between Trellix Intelligent Sandbox and Trellix IPS is established only when you enable this integration at the Sensor level. If you enable this integration globally for an admin domain, it is enabled for the corresponding Sensors by default. You can customize these settings at the Sensor level.
Steps:
In the Manager, select the Devices tab.
Select the domain from the Domain drop-down list.
On the left pane, click the Devices tab.
Select →
Enter the configuration details in the corresponding fields.
Enabling the integration for a Sensor
Option definitionsOption
Definition
Inherit Settings?
Select to inherit the integration configuration from the corresponding admin domain. The remaining fields are available only if this is de-selected.
Enable Trellix Intelligent Sandbox Integration?
Select to integrate the Sensor with Trellix Intelligent Sandbox. After you select, you are able to view and configure the details for the integration.
Trellix Intelligent Sandbox IP Address
Enter the static IPv4 address of Trellix Intelligent Sandbox.
Trellix Intelligent Sandbox Listening Port (TCP)
This is the port that Trellix Intelligent Sandbox will listen for connections from Sensors. The default port is 8505. You can modify if required.
Use a Different IP Address for Manager-to-Intelligent Sandbox Communication?
Check if you want Manager to communicate with the Trellix Intelligent Sandbox appliance using a different IP address than the IP address the Sensor is using to communicate with the same Trellix Intelligent Sandbox appliance.
Trellix Intelligent Sandbox IP Address
Enter the IPv4 address of Trellix Intelligent Sandbox.
Trellix Intelligent Sandbox Listening Port (TCP)
This is the port that Trellix Intelligent Sandbox will listen for connections from Manager. The default port is 8505. You can modify if required.
Test Connection
Click to verify if the Manager is able to communicate with Trellix Intelligent Sandbox using the details you configured. For the Sensor, you can ping the IP address of Trellix Intelligent Sandbox appliance from the Sensor CLI.
Trellix Intelligent Sandbox Username
The pre-defined user name, which the Manager uses to log on to Trellix Intelligent Sandbox, is displayed. You cannot enter a different name or change this default name in Trellix Intelligent Sandbox.
Password for 'nsp'
Enter the corresponding password. The default password is admin. As a precaution, change this password in the NSP User user record in Trellix Intelligent Sandbox.
Click Open Trellix Intelligent Sandbox Console to open Trellix Intelligent Sandbox web application.
In Trellix Intelligent Sandbox web application, select →
Select NSP User and click Edit to change the password.
Click Save.
Trellix Intelligent Sandbox User Profile for File Submission
Select from the drop-down your user profile created under Trellix Intelligent Sandbox. A Sensor can have its own analyzer profile as configured by the user.
Save
Saves the Trellix Intelligent Sandbox details in the Manager database
Open Trellix Intelligent Sandbox Console
Click to access the logon page of Trellix Intelligent Sandbox with which the Sensor is currently integrated.