The first and foremost aspect of Trellix IPS - Trellix NI integration is to establish communication channels between the Trellix IPS components, that is, the IPS Manager and IPS Sensor, and NI. This process occurs in various phases which are outlined below:
Users or administrators need to first configure Client Profiles using the NI Command Line Interface (CLI). This allows them enable alerts based on the alert severity thresholds and protocol-based L7 metadata which they want to be exported to the NI appliance by the Manager and Sensors, when the integration with Trellix NI is enabled. They need to then map the Client Profiles to individual Client Groups, which they need to create on the NI CLI. An HTTPS-based authentication hash token of 32 bytes is also generated on the NI appliance upon the completion of the Client Group configuration.
Once the Client group creation task is complete on the NI CLI, users need to configure the Client Group name, NI IP address, and the authentication hash pertaining to the Client Group in the Manager UI, and then enable the association of that group at the domain level or device level. The authentication hash token is used by the Manager and Sensors to maintain a persistent connection with NI.
Once the Manager receives the NI setup details, It sends the same to the attached Sensors over SNMP channel. The Sensors receive the setup details and maintain it across reboots.
On receiving the setup details, The Sensors and the Manager request NI configuration details using NI's REST APIs and communicate with the NI appliance or NI cluster over HTTPS channel using default port 443. On receiving the NI configuration details, the Sensors check if L7 metadata configuration is enabled and start capturing metadata and netflow records for the requested protocols, whereas the Manager checks for alerts based on the alert severity threshold chosen and start sending alert information to NI. The Sensors exports the flow records and L7 metadata to NI in batches.
Manager and Sensor periodically poll the NI for any changes in configuration and filter parameters as per the polling interval set by the users during Client Group configuration, retrieve them, and apply those to the alerts, netflows, and L7 metadata before exporting those to NI.
.jpg)
Below are presented some Trellix NI - Trellix IPS integration scenarios:
In case of Sensors in a cluster, each Sensor sends the flow records and L7 metadata to the NI appliance.
In case of Sensors in a stack, each node sends the flow records and L7 metadata to the NI appliance.
In case of Sensors in a public cloud cluster, each member Sensor node sends the flow records and L7 metadata to the NI appliance.
In case there are Primary Manager and Secondary Manager in MDR pair, the active Manager sends alert information to NI. If there is an MDR pair failure, the NI continues to receive alert information from the Primary or the Secondary Manager, depending on whichever acts as the Active Manager at that time.