The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes about upgrading from 9.1, 9.2, or 10.1 to 10.1.7.35

Prev Next

New counters for dropped packets

Starting with this release, the Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Traffic Statistics → Dropped Packets tab displays the following new counters:

  • Backend - Total number of miscellaneous packets dropped at back-end.
  • Backplane - Total number of miscellaneous packets dropped at BMC switch.
  • Frontend - Total number of miscellaneous packets dropped at front-end.
  • Layer 2 Non-Errors - Total number of layer 2 packets dropped due to other reasons.
  • NIC - Total number of miscellaneous packets dropped at NIC.

Additionally, the following counters are renamed:

Prior 10.1.7.35 10.1.7.35 and above
Other Layer 2 Errors Layer 2 Errors
Policy Response Actions - Firewall Policy Response - Stateful Firewall
Policy Response Actions - IPS Policy Response - IPS Attack
Policy Response Actions - IPv4 Quarantine Policy Response - IPv4 Quarantine
Policy Response Actions - IPv6 Quarantine Policy Response - IPv6 Quarantine

Callback detector enhancements

With this release of 10.1, the callback detector files are available in the McAfee Update Server. Going forward, you must download the latest callback detectors from the McAfee Network Security Update Server to the Manager. The Download Callback Detectors page displays the latest 10 versions of the callback detectors.

To view the Download Callback Detectors page, go to Manager → <Admin Domain Name> → Updating → Download Callback Detectors.

Expiry restrictions for capacity license

Previously, the expiration date was displayed for production level capacity licenses in the Licenses page. Starting from this release of 10.1, the expiration date is no longer displayed for production level capacity licenses as they are perpetual.

To view the capacity license, go to System tab under Manager → <Admin Domain Name> → Setup → Licenses.

Terminology update in UI

This release contains the following terminology update in the UI to keep up with the global standard:

Navigation Path Prior 10.1.7.35 10.1.7.35 and later
Analysis → Threat Explorer Blacklisted/Whitelisted under the Executable Classification column in the Top Executables table Blocked/Allowed under the Executable Classification column in the Top Executables table
Analysis → Malware Files Blacklist column under Individual Engine Confidence column Block column under Individual Engine Confidence column
Manage Whitelist and Blacklist Manage allow and block lists
Analysis → Network Forensics Under Suspicious Flows Panel → Suspicious activity indicators → Blacklisted executable Under Suspicious Flows Panel → Suspicious activity indicators → Blocked executable
Analysis → Endpoint Executables Manage Whitelist and Blacklist Manage allow and block lists
Blacklisted/Whitelisted under the Classification column Blocked/Allowed under the Classification column
Double-click on an alert and go to EIA Details tab. Local Classification: Blacklisted/Whitelisted. Double-click on an alert and go to EIA Details tab. Local Classification: Blocked/Allowed.
Analysis → Attack Log

Note

Only for alerts with files and domains in them.

Click Other Actions → Create Exception → Blacklist File Hash: < hash file> or double-click on an alert and go to Details tab. Select Blacklist. Click Other Actions → Create Exception → Block File Hash: < hash file> or double-click on an alert and go to Details tab. Select Block.
Click Other Actions → Create Exception → Whitelist File Hash: <hash file> or double-click on an alert and go to Details tab. Select Whitelist. Click Other Actions → Create Exception → Allow File Hash: < hash file> or double-click on an alert and go to Details tab. Select Allow.
Policy → Intrusion Prevention → Exceptions → File Hashes Whitelisted Hashes Allowed Hashes
Take Action -
  • Move selected hashes to blacklist
  • Move all hashes to blacklist
Take Action -
  • Move selected hashes to block list
  • Move all hashes to block list
Import - On selecting, Import Whitelisted Hashes dialog is displayed. Import - On selecting, Import Allowed Hashes dialog is displayed.
Export Whitelist Export Allowed
Blacklisted Hashes Blocked Hashes
Take Action -
  • Move selected hashes to whitelist
  • Move all hashes to whitelist
Take Action -
  • Move selected hashes to allow list
  • Move all hashes to allow list
Import- On selecting, Import Blacklisted Hashes is displayed. Import- On selecting, Import Blocked Hashes is displayed.
Export Blacklist Export Block List
Policy → Intrusion Prevention → Exceptions → Domain Names Callback Detection Whitelist Callback Detection Exclusions
Import - On selecting, Import Whitelisted Domains dialog is displayed. Import - On selecting, Import Allowed Domains dialog is displayed.
IPS Inspection Whitelist IPS Inspection Exclusions
Policy → Intrusion Prevention → Exceptions SSL Decryption Exceptions SSL Decryption Exclusions
Policy → Intrusion Prevention → Policy Types → Advanced Malware Policies New or an existing policy - Blacklist and Whitelist column under the Scanning Options section. New or an existing policy - Allow and Block Lists column under the Scanning Options section.
Policy → Intrusion Prevention → Policy Types → Inspection Option Policies Domain Name Whitelist Processing under tab Inspection Options → Advanced Callback Detection Domain Name Exclusion List Processing under tab Inspection Options → Advanced Callback Detection
Blacklisted Text under tab Inspection Options → Web Server - Heuristic Analysis Blocked Text under tab Inspection Options → Web Server - Heuristic Analysis