If you are upgrading the Manager from version 10.1 or 11.1 to version 11.1.19.27, read the following sections carefully.
IAM domain URL updates
The Identity and Access Management (IAM) domain URLs used by Trellix Intrusion Prevention System have been updated. As a user, you must update the destination URLs in your firewall configuration to ensure uninterrupted communication to the IAM service. The following table outlines the changes to the IAM domain URLs:
Existing destination URL | Updated destination URL |
|---|---|
iam.skyhigh.cloud iam-rs.skyhigh.cloud | iam.cloud.trellix.com iam-rs.cloud.trellix.com |
Public GTI communication interface upgrade for IP and URL Reputation
Starting with this release, Trellix IPS uses ECHDE ciphers to connect to Public GTI for IP and URL Reputation. During the configuration, the Sensor will receive a certificate bundle automatically. The ECDHE certificates are created manually and expire annually. The yearly generated certificate will be accessible in the IPS Update Server. The Manager fetches and downloads the certificate to send it to the Sensor. For any issues, contact Trellix support.
The following CLI command is updated with new GTI counters:
Command | Description |
|---|---|
| The command displays the status of various download and upload operations from the Manager to Sensor and from the Sensor to Manager. It also lists the number of times you operated and status of your previous attempt to operate. The time of the command execution is also listed. |
You can verify certificate transfers through User Activities logged in the Manager. If there are any issues such as invalid certificates, missing certificates, or DNS configuration issues, you can view the detailed information through several system generated Faults displayed in the Manager.
Support for import of multiple licenses in the Manager
Starting with this release of 11.1, the Manager facilitates the import of multiple licenses (SKU files in the .zip format). You can import multiple licenses in the System, Proxy Decryption, and Virtual Sensors tab of Licenses page in Manager → <Admin Domain Name> → Setup . When importing multiple license files, if they contain any combination of pre-existing, expired, or invalid licenses, the Manager will skip those files with an appropriate Error message, and valid license files will be imported.
.png)
Note
Upgrade licenses are not supported for multiple imports. You must import the upgrade license file individually.
Syslog server configuration enhancement
Starting with this release, you can configure the syslog server timeout value in minutes using 'notifications.syslog.tcptimeout'. When 'notifications.syslog.tcptimeout' is configured, the Manager reconnects to the syslog server at given intervals. If the time since the last connection re-establishment to the syslog server exceeds the configured timeout, the Manager will re-establish the connection before sending the syslog message. However, if 'notifications.syslog.tcptimeout' is not configured, the Manager will not reconnect once the trust has been established. After configuring 'notifications.syslog.tcptimeout', you must restart the Manager service for the changes to take effect.
You can customize the timeout value by navigating to the <Manager_Install_Dir>\App\Config folder. If the 'advanced-config.properties' file does not exist, create it. Then, add 'notifications.syslog.tcptimeout' and specify the timeout value in minutes.
Example: notifications.syslog.tcptimeout = 5
Note
The IPS Manager can now send 16384 bytes in a single syslog message.
Support for DNS protocol for layer 7 data collection
Starting with this release of 11.1, Trellix IPS supports collecting layer 7 data for DNS request fields and the export of the DNS request based L7 metadata to other Trellix products, such as Trellix Network Investigator (NI).
You can navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection and enable L7 data collection for DNS request fields per interface or sub-interface of selected Sensors.
Note
To view or customize DNS settings, you need to use Manager and Sensor that are running on 11.1 Minor 6 release versions, and a compatible signature set (11.10.19.7 or above) with DNS related attack signatures.
Only DNS request based fields can be enabled, disabled, or customized for Layer 7 data collection in the Manager.
Enhancements in Trellix IPS Manager
With this release of 11.1, several enhancements have been made to speed up Manager operations and improve its functionality and stability. Few of the key areas of enhancement are as follows:
From this release onwards, the fields in the Capture Packets section (for both Attack and Pre-Attack and Post-Attack) are set to disabled by default for all attacks of Informational and low severity levels, and not available for configuration for some specific attack IDs. This is done to prevent certain scenarios of excessive packet log generation.
Note
If you are running a Manager version lower than 11.1 Minor 6 release in which the packet logging is already enabled for any of the specific attack IDs (either inherit-enabled by signature set or manually enabled by the user) and you perform an upgrade, the fields in the Capture Packets section will still be visible during attack details configuration.
The Manager makes asynchronous request to Trellix IPS Update Server, and in case of connectivity errors, it logs the error messages in updateserver.log file for troubleshooting purposes. This is done to enhance the overall performance and stability of the Manager UI.
Several log files have been added for troubleshooting purposes, such as c3p0.log, c3p0monitor.log alertRate.log, and packetlogRate.log
Alert Pruning and Database Tuning enhancement
Starting with this release of 11.1, When data tuning gets triggered while the alert pruning operation is in progress, data tuning waits for permission and resumes after alert pruning is complete. Similarly, when alert pruning gets triggered while the data tuning operation is in progress, alert pruning waits for permission and resumes after data tuning is complete. This enhancement prevents overlapping and failure scenarios of data tuning and alert pruning.
Terminology updates in the UI
Navigation Path | Prior to 11.1.19.27 | 11.1.19.27 and later |
|---|---|---|
Analysis → <Admin Domain Name> → Event Reporting | The option available: Next Generation Reports | The option is renamed to Custom Reports |
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.6 which includes additional security against new vulnerabilities and bug fixes.
JDK and Java upgrade
Starting with this release of 11.1, the IPS Manager uses JDK and Java version 1.8.0_412 which includes additional security against new vulnerabilities.
Apache Tomcat server upgrade
Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.88. This server update provides a collection of security fixes.
OpenSSL upgrade
Starting with this release of 11.1, the OpenSSL version is upgraded to 1.0.2zj-fips. This new version includes additional security against new vulnerabilities.