The IPS Configuration Summary report provides a detailed view of the IPS configuration settings made by the user. This includes SNMP Forwarder Information, Alert Syslog Forwarder Information, Firewall Syslog Forwarder Information, Quarantine information, Network Objects, Quarantine Zones, Syslog Forwarding, Remediation Portal, IPS Settings and Quarantine. Information can be displayed for any selected admin domain in either .html, .pdf or .csv file formats.
To generate the report for an admin domain, do the following:
Steps:
Click the Manager tab from the Manager Home page.
Select <Admin Domain Name> → Reporting → Configuration Reports → IPS Configuration Summary.
Select the required domain from the Admin Domain drop-down list.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
Select the Report Format.
Click Run.
For the selected Admin Domain, IPS Configuration Summary report gives the following IPS configuration details:
IPS Events SNMP Forwarder Information
SNMP Forwarder Information specifies the server to which alert information will be sent from Manager. You can configure more than one SNMP server to where you want to send alert messages. The field details are described in the following table:
Field Name
Description
IP Address
IP address of the target SNMP server which can be IPv4 or IPv6 address.
Destination Port Number
The target server's SNMP listening port.
SNMP Version
Version of SNMP running on the target SNMP server. Version options are 1, 2c, Both 1 and 2c, and 3.
SNMP Forwarder Information
The SNMP server to where you want to send alert messages.
Alert Syslog
Alert Syslog Forwarder Information enables the forwarding of Trellix IPS alerts to a Syslog Server. The field detail is described in the following table:
Field Name
Description
Syslog Forwarder Enabled
Syslog forwarder has been enabled or disabled.
Alert Syslog Forwarder Information
Alert Syslog Forwarder Information enables the forwarding of Trellix IPS alerts to a Syslog Server. The Syslog forwarding enables you to view the forwarded alerts from a third-party Syslog application. The field details are described in the following table:
Field Name
Description
Child Domain Notification Enabled
Child notification has been enabled.
Notification Profile Name
Name of the notification profile.
Syslog Server (Host Name Or IP Address)/Port
Syslog server or port on which it is enabled.
Protocol
Syslog server using UDP or TCP connection
Use SSL
Use SSL when syslog server uses TCP
Quarantine Enabled
Quarantine enabled or disabled.
Firewall Notification Information
It is an optional Firewall feature that will log packets that are dropped or permitted based on your Access Rules. You can configure the Sensor to forward Firewall logs to Manager, where they are formatted and converted to Syslog messages and sent to the configured Syslog server. You can also configure the Sensor to directly send logs to the configured Syslog server. The field details are described in the following table:
Field Name
Description
Syslog Forwarder Enabled
Syslog forwarder has been enabled or disabled.
Child Domain Notification Enabled
Child notification has been enabled.
Syslog Server (Host Name Or IP Address)
Syslog server is enabled.
Port
Port on which it is forwarded.
Quarantine
To protect your network from security threats, Trellix IPS provides the Quarantine feature which quarantine and remediate the non-compliant network devices (or hosts) connecting to your network.
Rule Objects
Rule objects provide a convenient way of grouping together IP addresses, VLAN, CIDR or MAC addresses. The field details are described in the following table:
Field Name
Description
Name
Name of the rule object.
Type
This indicates the four different types of network address types that can be listed together in a network object.
IP Address
Network Address ( CIDR )
MAC Address
VLAN
Value
Enter the Value for the Type selected.
Quarantine Zones
Quarantine Zones are a set of ACL rules that define the zone of network access provided to a host subjected to Quarantine.
The field details are described in the following table:
Field Name
Description
Name
The name of the Quarantine Zone.
Description
The description of the Quarantine Zone.
Syslog Forwarding
The Alert Notification Syslog action enables the forwarding of Trellix IPS alerts to a Syslog Server. Syslog forwarding enables you to view the forwarded alerts from a third-party Syslog application. For Syslog forwarding, the root domain and parent domains have the option to include alerts from all applicable child domains.
Field Name
Description
Syslog
Syslog forwarder has been enabled or disabled.
Name
Host Name of the Syslog Server where alerts will be sent.
Facility
Standard Syslog prioritization value. The choices are as follow:
Security/authorization (code 4)
Security/authorization (code 10)
Log audit (note 1)
Log alert (note 1)
Clock daemon (note 2)
Local user 0 (local0)
Local user 1 (local1)
Local user 2 (local2)
Local user 3 (local3)
Local user 4 (local4)
Local user 5 (local5)
Local user 6 (local6)
Local user 7 (local7)
Priority
The severity level of a higher or lesser priority.
Remediation Portal
To make the quarantined host clean of malicious traffic and thus compliant to the security policies of the network, Trellix IPS provides remediation by re-directing the HTTP traffic from the host to a Remediation Portal.
Field Name
Description
Remediation Portal State
Enable the redirection of HTTP traffic to the Remediation Portal.
Remediation Portal IP Address
Configure the Remediation Portal, by specifying the Remediation Portal IP Address.
Remediation Portal URL
Configure the Remediation Portal, by specifying the Remediation Portal URL
IPS Settings
The IPS Settings node in each admin domain facilitates actions related to configuration and management of IPS related policies configuration on the Trellix IPS.
Quarantine
Field Name
Description
State
Whether Quarantine is enabled or not.
Quarantine Zone
The quarantine zone selected.
Release Logic
Whether the Sensor is configured to release the endpoint from quarantine automatically after a set timing or whether you have to manually release the endpoint from quarantine.
Release After
If the Sensor is configured to release the endpoint, what is the time duration after which the endpoint is released.
Browser Message
How is the browser message enabled.
Quarantine Exceptions
You can exclude certain hosts or network from being quarantined. This can be configured from the Quarantine Exceptions page of the Quarantine Configuration Wizard.
Field Name
Description
Type
The IP address, IPv4 Network, or Rule Object.
Value
Enter the Value for the Type selected.
Description
The description of the hosts or network.
File Reputation
The File Reputation Report provides you details of Trellix ePO™ (GTI) IP Reputation-related alerts such as Dirtiness Level, Matched fingerprint, Sensor Source IP, Source Port, etc.
Fingerprints - GTI
Field Name
Description
Maximum file size scanned
4194304 bytes (for signature set 10.8 and higher) - fixed size up to which malware files are detected.
Primary DNS Server
The main DNS server - configured first.
Secondary DNS Server
The backup DNS server – configured next and if main DNS server fails to respond.
Response Action
Detect/Allow (Alert only), block, block and send TCP resets.
Sensitivity
The severity of malware to block can be controlled.
Fingerprints - Custom
Field Name
Description
Number of custom fingerprints
The number of custom finger prints that are added.
Maximum file size scanned
4194304 bytes (for signature set 10.8 and higher)- fixed size up to which malware files are detected.
Response Action
Detect/Allow (Alert only), block, block and send TCP resets.
File types supported
Field Name
Description
GTI
The Portable Executable (PE) files.
Custom
File types based on custom signatures.
IVX Integration - Integration with IVX Appliance
Field Name
Description
Enable IVX Integration
IVX appliance Integration has been enabled or disabled.
Enabled Integration with
Integration has been enabled with IVX.
IP Address
IP address of the IVX broker(s) integrated with Trellix IPS.
Manager to IVX Communication Port (TCP)
Manager-to-IVX Appliance Communication Port number.
IVX Integration - Integration with IVX Cloud
Field Name
Description
Enable IVX Cloud Integration
IVX Cloud Integration has been enabled or disabled.
Enabled Integration with
Integration has been enabled with IVX Cloud.
Host Name
Host name for the IVX Cloud service. The default host name is
feapi.marketplace.apps.fireeye.com.Manager to IVX Cloud Communication Port
Manager-to-IVX Cloud Communication Port number.
Trellix Intelligent Sandbox Integration
Field Name
Description
Enable Trellix Intelligent Sandbox Integration
Trellix Intelligent Sandbox Integration has been enabled or disabled.
Trellix Intelligent Sandbox IP Address
IP address of Trellix Intelligent Sandbox integrated with Trellix IPS.
Sensor-to-Intelligent Sandbox Communication Port (TCP)
Sensor-to-Intelligent Sandbox Communication Port number.
Manager-to-Intelligent Sandbox Communication Port (TCP)
Manager-to-Intelligent Sandbox Communication Port number.