Before you begin
You must make sure that you have
- Set up and configured a Trellix ePO - On-prem server.
- Set up and configured the Threat Intelligence Exchange server and DXL brokers.
To implement the Threat Intelligence Exchange integration, you must follow a series of steps to make sure that the integration works as expected.
Task
- Log on to the Manager.
- Configure Trellix ePO - On-prem by providing the appropriate Trellix ePO - On-prem server IP address and credentials.
- Configure DXL integration either for a domain or for a device.
- Create an advanced malware policy in which TIE / GTI File Reputation is enabled for one or more file types.
- Apply this policy to the Sensor ports you want to use and specify the direction of traffic that is to be monitored with this policy.
- Perform a configuration update on the Sensor.