The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Importing the SSL certificates and the private keys for the Communications Broker Sender

Prev Next

You can import the public certificate and private key for the SSL server and the root CA certificate to establish a secure SSL connection for the Communications Broker Sender (Comm Broker) by using the appliance Web UI or CLI:

The SSL input module allows the Comm Broker to receive third-party syslog and JSON formatted logs in encrypted format on the Network Security appliance. The logs are always sent to Helix in encrypted format. You can receive incoming events that are sent over SSL. You can configure a maximum of three syslog input type modules and three JSON input type modules for the Comm Broker configuration.

Important

Mutual authentication between the Network Security appliance and the third-party log forwarding server is required. The third-party server must provide a client certificate and the client certificate must be trusted by the Network Security appliance. See your third-party log forwarding server documentation for steps to set up a client TLS certificate.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Verify that the Comm Broker is disabled. Use the show commbroker status command.

  • A client TLS certificate for the third-party server.

  • Download the bootstrap certificate bundle to your local desktop from the Operational Dashboard in the Helix Web UI. For details about how to download the certificate bundle, refer to the Unmanaged Communications Broker Installation and Configuration Guide.

  • An archive management program for files extracted to the desktop.