Usage of NTP is not permitted. The system time may be configured by authorized administrators via the “date” command of the CLI.
The TLS functionality of the Trellix IPS components is pre-configured and fixed with the following behaviors:
- Only TLS v1.2 is supported
- The reference identifier is the IP address or fully qualified domain name of the configured endpoint (matching the type used to configure the endpoint) and may be found in the SAN or CN fields of the presented certificate.
- The management GUI interface on the Manager supports the following cipher suite:
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- The interface on the Manager supports secp256r1 and secp384r1 Elliptic Curve Extensions.
- Between Sensors and the Manager, the cipher suite used to perform mutual authentication is TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256. The systems must use CA-signed RSA certificates with key size 2048 bits.
- The syslog server interface on the Manager supports the following cipher suites:
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289