You can use the Web UI or CLI to prepare the Network Security appliance to support IPS features:
About enabling IPS capabilities
Preparing to support IPS features (web UI)
Preparing to support IPS features (CLI)
About enabling IPS capabilities
The IPS feature license is now embedded in the appliance software and a license key is no longer required. You can apply IPS policies to appliance monitoring interfaces on IPS-enabled appliances.
Note
The requisite version of guest images must be installed for the appliance to perform MVX verification.
In a single-appliance deployment, the Network Security appliance can download security content updates (as well as software updates and software patches) from Trellix via a network connection to the Trellix Dynamic Threat Intelligence (DTI) cloud. For a Network Security appliance in a central management domain, the Central Management System appliance obtains update files from the DTI cloud and distributes them to the connected appliances.
Next step in setting up IPS
Preparing to support IPS features (web UI)
This topic describes how to use the Web UI to prepare a Network Security appliance to support IPS features.
To prepare the appliance to support IPS features:
Log in to the appliance Web UI as Operator or Admin. To display the role associated with your user account, use the show whoami CLI command
To access the FireEye Appliance login page for your Network Security appliance, open a supported Web browser and enter https://
appliance
in the address box, where
appliance
is the IP address or hostname of your appliance.
Verify that the appliance can connect to FireEye's DTI cloud, as described in the Network Security System Administration Guide.
The following list summarizes security content update requirements for a standalone Network Security appliance.
The appliance communicates with the DTI cloud through its ether1 Ethernet management interface, and the ether1 port requires a static IP address or reserved DHCP address and IP subnet mask.
Your network configuration must allow the appliance to establish outbound connections from the management over UDP port 53 and TCP port 443 to the Internet and exchange data encrypted via 256-bit SSL (Secure Sockets Layer).
Note
These communications port requirements are in addition to the basic requirements that network configuration must allow the appliance management port to be accessed via TCP port 22 (for the SSH command-line interface) and TCP port 443 (for the HTTPS Web user interface).
Your network configuration must allow the appliance to connect to cloud.fireeye.com. If your network configuration includes domain-based proxy ACL rules, ensure that the rules allow access to the *.fireeye.com domain.
Receiving security content updates from the DTI cloud requires login credentials. If you do not have DTI cloud login credentials, contact support@fireeye.com or visit the FireEye Customer Support Portal (login required): https://www.trellix.com/en-us/support.html.
Verify that the appliance is licensed for security content updates.
Choose Settings > Appliance Licenses to display information about licenses on the appliance. Security content updates are enabled if the Appliance License Settings table displays a license for the "CONTENT_UPDATES" feature, and the license is both "valid" and "active".
If you do not have a license for security content updates, contact support@fireeye.com or visit the FireEye Customer Support Portal (login required): : https://www.trellix.com/en-us/support.html.
(Recommended) Schedule automatic updating of security content. The following steps summarize the more detailed information provided in the Network Security System Administration Guide.
Choose Settings > DTI Network to display settings for the FireEye services installed on the appliance.
In the Service Type column, click the Security Contents link to display the scheduling settings in the Settings column.
Use the Update Frequency field to specify how often the appliance receives automatic updates of security content.
If you want to enable or disable notifications of security content uploads, select or clear the option in the Notify field.
Click Apply Settings.
Next step in setting up IPS
Go to About Enabling IPS Capabilities.
Preparing to support IPS features (CLI)
This topic describes how to use the CLI to prepare a Network Security appliance to support IPS features.
To prepare the appliance to support IPS features:
Log in to the appliance CLI as Operator or Admin. To display the role associated with your user account, use the
show whoamiCLI command.You can access the CLI from your computer through a direct connection (from a null modem cable to the appliance's DB‑9 serial console port) or remotely (through a secure shell [SSH] connection over port 22 to the appliance's ether1 management port).
Verify that the appliance can connect to FireEye's DTI cloud, as described in the Network Security System Administration Guide.
The following list summarizes the requirements for security content updates for a standalone Network Security appliance.
The appliance communicates with the DTI cloud through its ether1 Ethernet management interface, and the ether1 port requires a static IP address or reserved DHCP address and IP subnet mask.
Your network configuration must allow the appliance to establish outbound connections from the management over UDP port 53 and TCP port 443 to the Internet and exchange data encrypted via 256-bit SSL (Secure Sockets Layer).
Note
These communications port requirements are in addition to the basic requirements that network configuration must allow the appliance management port to be accessed via TCP port 22 (for the SSH command-line interface) and TCP port 443 (for the HTTPS Web user interface).
Your network configuration must allow the appliance to connect to
cloud.fireeye.com. If your network configuration includes domain-based proxy ACL rules, ensure that the rules allow access to the*.fireeye.comdomain.Receiving security content updates from the DTI cloud requires login credentials. If you do not have DTI cloud login credentials, contact support@fireeye.com or visit the FireEye Customer Support Portal (login required): https://www.trellix.com/en-us/support.html.
Verify that your appliance is licensed for security content updates. The security content updates service license is in place if the
show licensesCLI command output displays a license for the "CONTENT_UPDATES" feature, and the license is both "valid" and "active".If you do not have a license for security content updates, contact support@fireeye.com or visit the FireEye Customer Support Portal (login required): https://www.trellix.com/en-us/support.html.
(Recommended) Use the
fenet security‑content autoupdate schedulecommand to schedule automatic updates of security content.Save your changes.
hostname (config) # write memory
Next step in setting up IPS
Go to About enabling IPS capabilities.