Before using the Network Security appliance, do the following:
Read the Network Security Release Notes for the current release.
Familiarize yourself with the Network Security appliance.
Note
Some screenshots and examples of CLI command output in this guide may differ slightly from the current Web UI and CLI.
About the HelixConnect client
The HelixConnect client connects your on-premisesTrellix Network Security appliances directly to the Helix Enterprise cloud using a secure VPN connection. This allows Helix Enterprise to collect alerts and artifacts from the appliances. It also allows you to do the following from the Helix Enterprise Web UI:
Configure policy and other settings in Appliance Settings pages.
Update Network Security appliances to the latest system image, guest images, and security content.
Download artifacts and modify inline policy exceptions in Network Security alert details pages.
For information about establishing connectivity with the HelixConnect client and enable the functionality it offers, see the Helix Integration Guide. For information about the Helix Enterprise Web UI functionality enabled by the HelixConnect client, see the Helix Enterprise Product Guide.
For information about the detection capabilities for Network Security appliances running Classic Edition, SmartVision Mode, and Evidence Collector Edition, see Network Security product editions and SmartVision.
About the Network Security appliance
Some Network Security appliance models are designed to be sensors, so they do not have an Multi-Vector Virtual Execution (MVX) engine. Integrated Network Security appliances do have an MVX engine. You can enable some integrated Network Security appliances as sensors, which means their MVX engine is disabled.
A sensor must be enrolled with at least one MVX cluster before detection is performed. The sensor depends on the Intelligent Virtual Execution - Server compute node in the MVX cluster for further analysis. The Intelligent Virtual Execution - Server's compute node returns the results of the analysis over the SSH connection to the sensor.
You can view the results of the analysis in the Network Security sensor Web UI, which is identical to a Network Security integrated appliance Web UI.
Network Security product editions and SmartVision
On Network Security appliances licensed in release 8.1.2 or later, SmartVision technology is available in two product editions of the appliance: Classic and SmartVision. Network Security appliances licensed before Release 8.1.2 can enable SmartVision in the Classic product edition of the appliance.
On Network Security appliances licensed in release 9.1.0 or later, the SmartVision Mode is introduced. This mode provides SmartVision Edition functionality without the SmartVision license dependency. A Network Security appliance with a Classic license can be converted into SmartVision Mode with the CLI smartvision sv-mode enable.
On Network Security appliances licensed in release 9.1.1 or later, the Evidence Collector Edition is available.
Classic Product Edition
A Network Security appliance with a Classic Edition appliance license provides the full range of standard Network Security appliance features.
SmartVision Mode
A SmartVision Mode sensor (which is a component of the Trellix Network Security, SmartVision Mode solution) is a Network Security appliance with a regular FIREEYE_APPLIANCE license. This type of SmartVision appliance offers a basic, lighter version of the full-featured Classic Network Security appliance with SmartVision modules enabled.
Note
SmartVision Mode is targeted for east-west traffic inspection. Detection capability is limited to lateral movement, WebShell and exfiltration detection.
Evidence Collector Edition
The Evidence Collector (EC) Edition ― is a Network Security appliance with an Evidence Collector FIREEYE_APPLIANCE license. The EC Edition is a simplified virtual Network Security appliance that forwards L7 metatdata events and third-party logs to Helix Enterprise. The EC Edition is supported on all virtual Network Security models, including the public instance on Azure and Amazon Web Services.
Note
The EC edition supports the Tapsender, Communications Broker, event filter and data streaming and detection features.
On Network Security appliances release10.0 or later, you can enable object extraction on the EC Edition Network Security sensor using foxd config object-extract enable CLI.
The following models support the EC Edition:
NX1500V
NX2500V
NX2501V
NX2550V
NX4500V
NX6500V
NX7500V
NX8500V
NXCloudVaz
NXCloudVec2nitro
For information about establishing connectivity with the HelixConnect client and enabling the functionality it offers, see the Helix Integration Guide.
The Network Security appliance product edition is determined by its FIREEYE_APPLIANCE license and not by the software image installed. You can view the product edition in the appliance license details and in other areas of the Network Security Web UI and CLI and, for managed Network Security appliances, in the Central Management System appliance Web UI and CLI.
For more information about using the SmartVision features, see the Network Security SmartVision Feature Guide.
For an overview of the differences between the Classic, SmartVision, and Evidence Collector product editions of Network Security appliances, contact your Trellix sales representative.