A desktop firewall on the Manager server is recommended. Certain ports are used by the components of Trellix IPS. Some of these are required for Manager -- Sensor and Manager client-server communication. All remaining unnecessary ports should be closed.
Trellix strongly recommends that you configure a packet-filtering firewall to block connections to ports 8551, 3306, and 8005 of your Manager server. The firewall can either be a host-based or network-based. Set your firewall to deny connections to these ports if the connections are not initiated by the localhost. The only connections that should be allowed are those from the Manager server itself; that is, the localhost. For example, if another machine attempts to connect to port 8551, 3306, and 8005, the firewall should automatically block any packets sent. If you need assistance in blocking these, contact Trellix Technical Support.
Note
Trellix strongly recommends you not to change the firewall settings in the Linux based Manager.
Note
Use a scanning tool, such as Vulnerability Manager, to ensure that there are no ports open other than what is required.
If a firewall resides between the Sensor, Manager, or administrative client, which includes a local firewall on the Manager, the following ports must be opened:
| Port # | Protocol | Description | Direction of communication |
|---|---|---|---|
|
UDP | Default SNMPv3 (command channel) | Manager<-->Sensor |
| 8500 (destination port on the Sensor) | UDP | Default SNMPv3 (command channel) | Sensor<-->Manager |
| 8501 | TCP | Proprietary (install channel using SHA256 2048-bit self-signed certificate) | Sensor<-->Manager |
| 8502 | TCP | Proprietary (alert channel/control channel using SHA256 2048-bit self-signed certificate) | Sensor<-->Manager |
| 8503 | TCP | Proprietary (packet log channel using SHA256 2048-bit self-signed certificate) | Sensor<-->Manager |
| 8504 | TCP | Proprietary (file transfer channel) | Sensor<-->Manager |
| 8506 | TCP | Proprietary (install channel for SHA256 2048-bit CA-signed certificates) | Sensor<-->Manager |
| 8507 | TCP | Proprietary (alert channel/control channel using SHA256 2048-bit CA-signed certificates) | Sensor<-->Manager |
| 8508 | TCP | Proprietary (packet log channel using SHA256 2048-bit CA-signed certificates) | Sensor<-->Manager |
| 8509 | TCP | Proprietary (Bulk file transfer channel using SHA256 2048-bit CA-signed certificates) | Sensor<-->Manager |
| 8510 | TCP | Proprietary (Bulk file transfer channel using SHA256 2048-bit self-signed certificates) | Sensor<-->Manager |
| 443 | TCP | HTTPS | client-->Manager |
| 80 | TCP | Web-based user interface | client-->Manager |
| 22 | TCP | SSH | Remote console access |
Note
If you choose to use non-default ports for the Install port, Alert port, and Log port, ensure that those ports are also open on the firewall.
- Note that 3306/TCP is used internally by the Manager to connect to the MariaDB database.
- If you have Email Notification or SNMP Forwarding configured on the Manager, and there is firewall residing between the Manager and your SMTP or SNMP server, ensure the following ports are available as well.
Additional communication ports
| Port # | Protocol | Description | Direction of communication |
|---|---|---|---|
| 25 | TCP | SMTP | Manager-->SMTP server |
| 49 | TCP | TACACS+ Integration | Sensor-->TACACS+ server |
| 162 | UDP | SNMP Forwarding | Manager-->SNMP server |
| 389 | TCP | LDAP Integration (without SSL) | Manager-->LDAP server |
| 443 | TCP | Secure communication for MDR | Manager 1 -->Manager 2 |
| 443 | TCP | Secure communication for MDR | Manager 2-->Manager 1 |
| 514 | UDP | Syslog forwarding (ACL logging) | Manager-->Syslog server |
| 636 | TCP | LDAP Integration (with SSL) | Manager-->LDAP server |
| 1812 | UDP | RADIUS Integration | Manager-->RADIUS server |
If you have Trellix ePO - On-prem integration configured on Manager, and there is firewall between Manager and the Trellix ePO - On-prem Server, ensure the following port is also allowed through firewall.
| Port | Description | Communication |
|---|---|---|
| 8443 | Trellix ePO - On-prem communication port | Manager to Trellix ePO - On-prem server |
- Close all open programs, including email, the Administrative Tools > Services window, and instant messaging before installation to avoid port conflicts. A port conflict may prevent the application from binding to the port in question because it will already be in use.
Note
The Manager is a standalone system and should not have other applications installed.