A desktop firewall on the Manager server is recommended. Certain ports are used by the components of Trellix IPS. Some of these are required for Manager -- Sensor and Manager client-server communication. All remaining unnecessary ports should be closed.
Trellix strongly recommends that you configure a packet-filtering firewall to block connections to ports 8551, 3306, and 8005 of your Manager server. The firewall can either be a host-based or network-based. Set your firewall to deny connections to these ports if the connections are not initiated by the localhost. The only connections that should be allowed are those from the Manager server itself; that is, the localhost. For example, if another machine attempts to connect to port 8551, 3306, and 8005, the firewall should automatically block any packets sent. If you need assistance in blocking these, contact Trellix Technical Support.
Note
Trellix strongly recommends you not to change the firewall settings in the Linux based Manager.
Note
Use a scanning tool to ensure that there are no ports open other than what is required.
If a firewall resides between the Sensor, Manager, or administrative client, which includes a local firewall on the Manager, refer to the section Set the desktop firewall inTrellix Intrusion Prevention System Manager Product Guide and open the ports mentioned in the section.
Note
If you choose to use non-default ports for the Install port, Alert port, and Log port, ensure that those ports are also open on the firewall.
Close all open programs, including email, the Administrative Tools > Services window, and instant messaging before installation to avoid port conflicts. A port conflict may prevent the application from binding to the port in question because it will already be in use.
Note
The Manager is a standalone system and should not have other applications installed.