If you are upgrading the Sensor from version 10.1 or 11.1 to version 11.1.17.29 or 11.1.17.31, read the following sections carefully.
Public GTI communication interface upgrade for IP and URL Reputation
Starting with this release, Trellix IPS uses ECHDE ciphers to connect to Public GTI for IP and URL Reputation. During the configuration, the Sensor will receive a certificate bundle automatically. The ECDHE certificates are created manually and expire annually. The yearly generated certificate will be accessible in the IPS Update Server. The Manager fetches and downloads the certificate to send it to the Sensor. For any issues, contact Trellix support.
The following CLI command is updated with new GTI counters:
Command | Description |
|---|---|
| The command displays the status of various download and upload operations from the Manager to Sensor and from the Sensor to Manager. It also lists the number of times you operated and status of your previous attempt to operate. The time of the command execution is also listed. |
You can verify certificate transfers through User Activities logged in the Manager. If there are any issues such as invalid certificates, missing certificates, or DNS configuration issues, you can view the detailed information through several system generated Faults displayed in the Manager.
Support for DNS protocol for layer 7 data collection
Starting with this release of 11.1, Trellix IPS supports collecting layer 7 data for DNS request fields and the export of the DNS request based L7 metadata to other Trellix products, such as Trellix Network Investigator (NI).
You can navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection and enable L7 data collection for DNS request fields per interface or sub-interface of selected Sensors.
Note
To view or customize DNS settings, you need to use Manager and Sensor that are running on 11.1 Minor 6 release versions, and a compatible signature set (11.10.19.7 or above) with DNS related attack signatures.
Only DNS request based fields can be enabled, disabled, or customized for Layer 7 data collection in the Manager.
CA-signed certificate file size enhancement
Starting with this release, the CA certificate file size has been increased to support more than 2046 bytes.
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.6 which includes additional security against new vulnerabilities and bug fixes.
JDK and Java upgrade
Starting with this release of 11.1, the IPS Manager uses JDK and Java version 1.8.0_412 which includes additional security against new vulnerabilities.
Apache Tomcat server upgrade
Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.88. This server update provides a collection of security fixes.
OpenSSL upgrade
Starting with this release of 11.1, the OpenSSL version is upgraded to 1.0.2zj-fips. This new version includes additional security against new vulnerabilities.