The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Hardening the Manager Server for Linux platform

Prev Next

During the Manager installation, configurational scripts are run automatically to harden the operating system as a best practice. After the configuration, only the ports required for communication between the Manager and point integrations, such as Sensor, ePolicy Orchestrator, and Alert Service, are open. The communication on the non-essential ports is disabled.

Reconfiguration of SSH

After running the configuration script, the SSH configuration file contains the following configuration:

Configuration Comments
Protocol 2 Use of protocol version 1 is not recommended. It may be susceptible to man-in-the-middle attacks.
Ciphers
  • AES: aes256-gcm@openssh.com, aes128-gcm@openssh.com
  • MAC: hmac-sha2-256, and hmac-sha2-512
  • KexAlgorithms: ecdh-sha2-nistp256
Use of strong cipher suites to make the encryptions better. The MAC (Message Authentication Code) algorithm is used in protocol version 2 for data integrity protection. Multiple algorithms must be comma-separated.

Reconfiguration of SSHD

After running the configuration script, the SSHD configuration file contains the following configuration:

Configuration Comments
Port 22 Used for SSH communication
Protocol 2 Use of protocol version 1 is not recommended. It may be susceptible to man-in-the-middle attacks.
HostKey /etc/ssh/ssh_host_dsa_key Specifies a file containing a private host key used by SSH
RekeyLimit 1G 1h The first argument specifies the maximum amount of data that can be transmitted before the session key is renegotiated. The second argument, which is optional, specifies the maximum amount of time that may pass before the session key is renegotiated. The first argument is specified in bytes and may have a suffix of K, M, or G to indicate Kilobytes, Megabytes, or Gigabytes, respectively.
SyslogFacility AUTH Specifies the facility code that is used when logging messages from sshd. The default value is AUTH
LogLevel VERBOSE Specifies the verbosity level that is used when logging messages from sshd
Ciphers
  • AES: aes256-gcm@openssh.com, aes128-gcm@openssh.com
  • MAC: hmac-sha2-256, and hmac-sha2-512
  • KexAlgorithms: ecdh-sha2-nistp256
Use of strong cipher suites to make the encryptions better. The MAC (Message Authentication Code) algorithm is used in protocol version 2 for data integrity protection. Multiple algorithms must be comma-separated.
LoginGraceTime 300 Specifies the time limit after which the server disconnects if the user is not successfully logged in
PermitRootLogin no Specifies whether the root user can log in using ssh. The default value is yes.
StrictModes yes Specifies whether sshd should check file modes and ownership of the user's files and home directory before accepting login. The default value is no.
MaxAuthTries 3 Specifies the maximum number of authentication attempts permitted per connection
HostbasedAuthentication no Specifies whether rhosts or /etc/hosts.equiv authentication together with successful public key client host authentication is allowed.
IgnoreUserKnownHosts yes Specifies whether sshd should ignore the user's ~/.ssh/known_hosts during RhostsRSAAuthentication or HostbasedAuthentication
AllowAgentForwarding no Specifies whether ssh-agent forwarding is permitted
AllowTcpForwarding no Specifies whether TCP forwarding is permitted
X11Forwarding no Specifies whether X11 forwarding is permitted
PrintMotd yes Specifies whether sshd should print /etc/motd when a user logs in interactively
TCPKeepAlive yes Specifies whether the system should send TCP keepalive messages to the other side. The default is yes (to send TCP keepalive messages), and the server will notice if the network goes down or the client host crashes. This avoids infinitely hanging sessions.
MaxStartups 3 Specifies the maximum number of concurrent unauthenticated connections to the SSH daemon. Additional connections will be dropped until authentication succeeds or the LoginGraceTime expires for a connection.
Banner /etc/legal The contents of the specified file are sent to the remote user before authentication is allowed.
Subsystem sftp /usr/libexec/sftp-server (modified from Subsystem sftp /usr/libexec/openssh/sftp-server) Configures an external subsystem, such as a file transfer daemon. Arguments should be a subsystem name and a command to execute upon subsystem request. The sftp-server command implements the SFTP file transfer subsystem.

Reconfiguration of IP tables, and ports used by the Manager and Sensor, integrated products, and other third-party applications for communications

For more information on the IP Table configuration after running the reconfiguration script, ports and traffic destinations as used by the Manager and Sensor, and ports used by third-party applications and integrated products, such as NTBA, Intelligent Sandbox, ePO, MVX etc., refer to the section Set the desktop firewall.

For information of how to disable or enable firewall ports in MLOS, refer to the section Steps to disable or enable ports on firewall in MLOS in Trellix Intrusion Prevention System Manager Appliance Product Guide.