The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes for upgrading from 9.1, 9.2, or 10.1 to 10.1.5.92

Prev Next

Configuring Private Cloud for Global Threat Intelligence integration

Previously, the communication between Network Security Platform and the Global Threat Intelligence Public or Private cloud was using the UDP protocol on port 53. Starting with this release, Network Security Platform and the Global Threat Intelligence Public or Private cloud uses TCP protocol on port 443. By default, Network Security Platform is configured to communicate with the McAfee Global Threat Intelligence server. You can configure Network Security Platform to communicate with a Private Cloud in the Manager → <Admin Domain Name> → Integration → GTI page.

The GTI page has the following tabs:

  • File Reputation: Allows configuring public or private cloud for file reputation queries. You must have the file reputation server name or IP address with the user name and password for configuration.
  • Endpoint/URL Reputation: Allows configuring public or private cloud for endpoint/URL reputation queries. You must need the IP address for the Private GTI Cloud server and .ZIP file that contains Network Security Platform certificate, Private key for Network Security Platform certificate, and GTI Private Cloud CA certificate files in the PEM format.

IPS CLI enhancements

The following Sensor CLI commands are updated:

Normal mode
CLI Command Description
pktcapturefile Uploads packet capture file to the SCP server or Manager or deletes a packet capture file in the Sensor. With this release of 10.1, the command is now applicable to all NS-series Sensors.
pktcapture intfport Captures incoming and outgoing packets on a single monitoring port. With this release of 10.1, the command is now applicable to all NS-series Sensors.
pktcapture intfport-pair Captures incoming and outgoing packets on two different monitoring ports. With this release of 10.1, the command is now applicable to all NS-series Sensors.
show gti config Displays the GTI configuration details for File reputation and IP/URL reputation.
Debug mode
CLI Command Description
show malwareserverstats Displays additional counters for Network Security Platform communication with the Global Threat Intelligence using REST.