The IPS Configuration Summary report provides a detailed view of the IPS configuration settings made by the user. This includes SNMP Forwarder Information, Alert Syslog Forwarder Information, Firewall Syslog Forwarder Information, Quarantine information, Network Objects, Quarantine Zones, Syslog Forwarding, Remediation Portal, IPS Settings and Quarantine. Information can be displayed for any selected admin domain in either .html, .pdf or .csv file formats.
To generate an IPS Configuration Summary report for an admin domain, do the following:
Task
- Click the Manager tab from the Manager Home page.
- Select <Admin Domain Name> → Reporting → Configuration Reports → IPS Configuration Summary.
-
Select a filter from the
Admin Domain drop-down list.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
- Select the Output Format.
-
Click
Submit.
For the selected Admin Domain, IPS Configuration Summary report gives the following IPS configuration details:IPS Events SNMP Forwarder InformationSNMP Forwarder Information specifies the server to which alert information will be sent from Manager. You can configure more than one SNMP server to where you want to send alert messages. The field details are described in the following table:
Field Name Description IP Address IP address of the target SNMP server which can be IPv4 or IPv6 address. Destination Port Number The target server's SNMP listening port. SNMP Version Version of SNMP running on the target SNMP server. Version options are 1, 2c, Both 1 and 2c, and 3. SNMP Forwarder Information The SNMP server to where you want to send alert messages. Alert SyslogAlert Syslog Forwarder Information enables the forwarding of Trellix IPS alerts to a Syslog Server. The field detail is described in the following table:Field Name Description Syslog Forwarder Enabled Syslog forwarder has been enabled or disabled. Alert Syslog Forwarder InformationAlert Syslog Forwarder Information enables the forwarding of Trellix IPS alerts to a Syslog Server. The Syslog forwarding enables you to view the forwarded alerts from a third-party Syslog application. The field details are described in the following table:Field Name Description Child Domain Notification Enabled Child notification has been enabled. Notification Profile Name Name of the notification profile. Syslog Server (Host Name Or IP Address)/Port Syslog server or port on which it is enabled. Protocol Syslog server using UDP or TCP connection Use SSL Use SSL when syslog server uses TCP Quarantine Enabled Quarantine enabled or disabled. Firewall Notification InformationIt is an optional Firewall feature that will log packets that are dropped or permitted based on your Access Rules. You can configure the Sensor to forward Firewall logs to Manager, where they are formatted and converted to Syslog messages and sent to the configured Syslog server. You can also configure the Sensor to directly send logs to the configured Syslog server. The field details are described in the following table:Field Name Description Syslog Forwarder Enabled Syslog forwarder has been enabled or disabled. Child Domain Notification Enabled Child notification has been enabled. Syslog Server (Host Name Or IP Address) Syslog server is enabled. Port Port on which it is forwarded. QuarantineTo protect your network from security threats, Trellix IPS provides the Quarantine feature which quarantine and remediate the non-compliant network devices (or hosts) connecting to your network.Rule ObjectsRule objects provide a convenient way of grouping together IP addresses, VLAN, CIDR or MAC addresses. The field details are described in the following table:Field Name Description Name Name of the rule object. Type This indicates the four different types of network address types that can be listed together in a network object.
- IP Address
- Network Address ( CIDR )
- MAC Address
- VLAN
Value Enter the Value for the Type selected. Quarantine ZonesQuarantine Zones are a set of ACL rules that define the zone of network access provided to a host subjected to Quarantine.The field details are described in the following table:Field Name Description Name The name of the Quarantine Zone. Description The description of the Quarantine Zone. Syslog ForwardingThe Alert NotificationSyslog action enables the forwarding of Trellix IPS alerts to a Syslog Server. Syslog forwarding enables you to view the forwarded alerts from a third-party Syslog application. For Syslog forwarding, the root domain and parent domains have the option to include alerts from all applicable child domains.Field Name Description Syslog Syslog forwarder has been enabled or disabled. Name Host Name of the Syslog Server where alerts will be sent. Facility Standard Syslog prioritization value. The choices are as follow:
- Security/authorization (code 4)
- Security/authorization (code 10)
- Log audit (note 1)
- Log alert (note 1)
- Clock daemon (note 2)
- Local user 0 (local0)
- Local user 1 (local1)
- Local user 2 (local2)
- Local user 3 (local3)
- Local user 4 (local4)
- Local user 5 (local5)
- Local user 6 (local6)
- Local user 7 (local7)
Priority The severity level of a higher or lesser priority. Remediation PortalTo make the quarantined host clean of malicious traffic and thus compliant to the security policies of the network, Trellix IPS provides remediation by re-directing the HTTP traffic from the host to a Remediation Portal.Field Name Description Remediation Portal State Enable the redirection of HTTP traffic to the Remediation Portal. Remediation Portal IP Address Configure the Remediation Portal, by specifying the Remediation Portal IP Address. Remediation Portal URL Configure the Remediation Portal, by specifying the Remediation Portal URL IPS SettingsThe IPS Settings node in each admin domain facilitates actions related to configuration and management of IPS related policies configuration on the Trellix IPS.QuarantineField Name Description State Whether Quarantine is enabled or not. Quarantine Zone The quarantine zone selected. Release Logic Whether the Sensor is configured to release the endpoint from quarantine automatically after a set timing or whether you have to manually release the endpoint from quarantine. Release After If the Sensor is configured to release the endpoint, what is the time duration after which the endpoint is released. Browser Message How is the browser message enabled. Quarantine ExceptionsYou can exclude certain hosts or network from being quarantined. This can be configured from the Quarantine Exceptions page of the Quarantine Configuration Wizard.Field Name Description Type The IP address, IPv4 Network, or Rule Object. Value Enter the Value for the Type selected. Description The description of the hosts or network. File ReputationThe File Reputation Report provides you details of Global Threat Intelligence (GTI) IP Reputation-related alerts such as Dirtiness Level, Matched fingerprint, Sensor Source IP, Source Port, etc.Fingerprints - GTIField Name Description Maximum file size scanned 4194304 bytes (for signature set 10.8 and higher) - fixed size up to which malware files are detected. Primary DNS Server The main DNS server - configured first. Secondary DNS Server The backup DNS server – configured next and if main DNS server fails to respond. Response Action Detect/Allow (Alert only), block, block and send TCP resets. Sensitivity The severity of malware to block can be controlled. Fingerprints - CustomField Name Description Number of custom fingerprints The number of custom finger prints that are added. Maximum file size scanned 4194304 bytes (for signature set 10.8 and higher)- fixed size up to which malware files are detected. Response Action Detect/Allow (Alert only), block, block and send TCP resets. File types supportedField Name Description GTI The Portable Executable (PE) files. Custom File types based on custom signatures. MVX IntegrationField Name Description Enable VX Appliance Integration VX appliance Integration has been enabled or disabled. VX IP Address IP address of the VX broker integrated with Trellix IPS. Manager to VX Communication Port (TCP) Manager-to-VX Appliance Communication Port number. Trellix Intelligent Sandbox IntegrationField Name Description Enable Trellix Intelligent Sandbox Integration Trellix Intelligent Sandbox Integration has been enabled or disabled. Trellix Intelligent Sandbox IP Address IP address of Trellix Intelligent Sandbox integrated with Trellix IPS. Sensor-to-Intelligent Sandbox Communication Port (TCP) Sensor-to-Intelligent Sandbox Communication Port number. Manager-to-Intelligent Sandbox Communication Port (TCP) Manager-to-Intelligent Sandbox Communication Port number.