If there is a connection failure suspected between Trellix IPS and Trellix NI after the integration, the underlying reason might be that Trellix IPS solution is unable to communicate with Trellix NI. Perform the following steps to troubleshoot the problem.
Ensure that the NI appliance integrated with the IPS solution is up and running.
In the Manager:
Check the Client Group configuration details specified in the Manager, i.e, the Client Group name, NI appliance IP address, and authentication hash token, are correct. Check the Client Group association settings at both domain and device level and ensure that a valid Client Group is associated with the Manager.
Ensure that communication via default HTTPS port 443 is allowed from the Manager and required Sensor(s) to the NI appliance.
Check if there are any fault messages related to NI connectivity or NI authentication failure on → → → → tab.
In the Sensor:
Enter
debugmode in the Sensor CLI and run theshow ni statuscommand. Make sure thatNI Communication Statusis displayed asUPin the output.Run the
getnistatscommand and see whether there is any increase in the NI config and metadata counters. Static counter specifics even after the poll config timer expiry might indicate integration issues with Trellix NI.Check the output by running the
ninetflowstatcommand on Sensor CLI. If network traffic is running and a valid Client Group is configured, the statistics specifics related to netflow and L7 metadata should increase as well over time.