If you are upgrading the Sensor from version 10.1 or 11.1 to version 11.1.5.84, read the following sections carefully.
Introducing Trellix Intrusion Prevention System Sensor - NS7600
This release of 11.1 introduces Trellix's next-generation IPS NS7600 Sensor model. The NS7600 Sensor operates at 5 Gbps, 10 Gbps, and 15 Gbps throughput depending on the license purchased.
The NS7600 Sensors are 1RU units equipped with the following components:
4 SFP/SFP+ 1/10 Gigabit Ethernet ports in built-in G0 module
Three slots (G1, G2 and G3) for pluggable and hot swappable I/O modules:
6-port RJ45 10/1 Gigabit with internal fail-open interface module
8-port 10/1 Gigabit SM (8.5 micron) with internal fail-open interface module
8-port 10/1 Gigabit MM (50 or 62.5 micron) with internal fail-open interface module
Caution
Apart from the network interface modules mentioned above, no other interface modules are compatible with the NS7600 Sensor.
SFP+ (SM and MM), SFP Fiber (SM and MM), and SFP Copper transceiver modules are supported in NS7600 Sensor models.
Note
Transceiver modules are supported in the built-in G0 module only.
One console port
Two external USB ports for Storage/Rescue applications
One RJ-45 10 Gbps/1 Gbps Management port
One RJ-45 10 Gbps/1 Gbps Response port
The front and rear panel LEDs provide status information for the health of the Sensor and the activity on its ports
To know information on NS7600 Sensor capacity, refer to the section NS7600 Sensor capacity. Note that the following features are not supported in NS7600 Sensors:
Suricata Snort engine
Proxy-based SSL decryption (both inbound and outbound)
Introducing Trellix Intrusion Prevention System Sensor - NS3600
This release of 11.1 introduces Trellix's next-generation IPS NS3600 Sensor model. The NS3600 Sensor model provides 1 Gbps, 3 Gbps, and 5 Gbps throughput.
The NS3600 Sensors are equipped with the following components:
Console port
USB port
RJ-45 10/100/1000 Mbps Ethernet Monitoring ports
RJ-45 10/100/1000 Management port (MGMT)
RJ-45 10/100/1000 Response port (R1)
2-port 10/1 Gbps Ethernet Monitoring ports (This requires SFP/SFP+ transceivers and they are sold separately.)
The Sensor LEDs provide status information for the health, link, speed, and activity on its management/response/monitoring ports.
The NS3600 Sensors support the 4-port copper and fiber interface modules. These interface modules can be installed in only one slot that includes ports 11-14 on the Sensor. Note that the interface modules are not hot-swappable. The NS3600 Sensors support the following interface modules:
4-port RJ-45 1 Gbps/100 Mbps/10 Mbps with internal fail-open Network Interface Module
4-port 10/1 GigE MM 50/62.5 μm with internal fail-open Network Interface Module
In NS3600 Sensors, transceiver modules are supported only in ports 5 and 6. It includes SFP+ (SM and MM) and SFP Fiber (SM and MM).
The following features are not supported in NS3600 Sensors:
Suricata Snort engine
Proxy-based SSL decryption (both inbound and outbound)
IPS CLI enhancements
The following Sensor CLI command is added:
Command | Description |
|---|---|
| This command displays the status of the behavioral scan on the Gateway Anti-Malware engine as enabled or disabled. |
Command | Description |
|---|---|
| This command allows users to enable or disable behavioral scans on the Gateway Anti-Malware engine. |
| This command displays counter specifics related to successful metadata export per protocol to Trellix Network Investigator when the integration with Trellix NI is enabled. |
The following Sensor CLI command is updated:
Command | Description |
|---|---|
| (Applicable to NS7600 Sensors only) The
|
Command | Description |
|---|---|
| This command now shows additional counter specifics related to netflow and metadata export to Trellix NI. Some of these counters include the following:
|
This release provides the following enhancements related to platforms, environments, or operating systems:
OpenSSL upgrade
Starting with this release of 11.1, the OpenSSL version is upgraded to 1.0.2zh-fips. This new version includes additional security against new vulnerabilities.