This version of the release supports features that are mandatory requirements for CC certification.
The software combination recommended by Trellix to use along with this release of NS-series Sensor software are as listed below:
Release parameters | Version |
|---|---|
IPS Manager software version | 11.1.19.27 |
Signature Set | 11.10.19.7 |
NS-series Sensor software version (N9500, NS9300, NS9200, NS9100, NS7500, NS7350, NS7250, NS7150, NS5200, NS5100, NS3600, NS3200, NS3100) | 11.1.17.29 |
NS-series Sensor software version (NS7600) | 11.1.17.31 |
OpenSSL | 1.0.2zj-fips |
Important
Only NS9500, NS7600, NS7500, NS3600, and NS3200 Sensors and Trellix IPS Manager Appliance (Linux) are CC certified. For more information, see Trellix Intrusion Prevention System 11.1 FIPS and CC Certification Guide.
Trellix IPS 11.1 release is CC certified and the review process for Trellix IPS 11.1 FIPS certification is currently in progress. Trellix Intrusion Prevention System 11.1 FIPS and CC Certification Guide contains information on both FIPS and CC compliant images. The content mentioned in the guide for FIPS and CC compliance also applies to CC certified software images.
This version supports all the features that are supported in Trellix Intrusion Prevention System 11.1.x non-CC versions. Above and beyond that, it includes support for FIPS. If you wish to learn about features released in non-CC compliant versions of the product, please refer to the following release notes:
IPS 11.1.7.97-11.1.5.98-11.1.5.99 NS-Series Release Notes
IPS 11.1.7.84-11.1.5.84 NS-Series Release Notes
IPS 11.1.7.71-11.1.5.72 NS-Series Release Notes
IPS 11.1.7.56-11.1.5.56 NS-Series Release Notes
IPS 11.1.7.41-11.1.5.44 NS-Series Release Notes
IPS 11.1.7.26-11.1.5.22 NS-Series Release Notes
IPS 11.1.7.3-11.1.5.2 NS-Series Release Notes
Note
Manager software version 11.1 is not supported on Dell-based Manager Appliances. Trellix recommends that you use Intel-based Manager Appliances instead.
Note
If you have a 9.x Manager managing 9.x NTBA, you should consider upgrading 9.x Manager to 10.1 or 11.1. If you plan to upgrade the Manager to 11.1, you need to first upgrade it to 10.1.19.56 and then to 11.1.
Upgrade support
Trellix regularly releases updated versions of the signature set. You can choose to automatically download and deploy the signature set in the Manager.
Upgrade paths for Manager software versions
Note
Windows-based Manager is not CC certified.
Linux-based Manager:
Manager upgrade paths
Manager version | Recommended Manager version |
|---|---|
10.1.19.17, 10.1.19.30, 10.1.19.33, 10.1.19.38, 10.1.19.47, 10.1.19.53, 10.1.19.56, 10.1.19.56.8 | 11.1.19.27 |
11.1.19.11 | 11.1.19.27 |
Important
After the upgrade, make sure to reboot the Linux-based Manager.
Upgrade paths for Sensor software versions
Sensor upgrade paths
Sensor model | Current Sensor software (CC compliant) | Upgrade path to latest CC compliant Sensor software |
|---|---|---|
NS9500, NS7350, NS7250, NS7150 | 10.1.17.15, 10.1.17.26, 10.1.17.36, 10.1.17.50, 10.1.17.63, 10.1.17.75, 10.1.17.91, 10.1.17.96 | 11.1.17.29 |
11.1.17.13 | 11.1.17.29 | |
NS9300, NS9200, NS9100, NS5200, NS5100, NS3200, NS3100 | 10.1.17.15, 10.1.17.26, 10.1.17.36, 10.1.17.47, 10.1.17.63, 10.1.17.75, 10.1.17.91, 10.1.17.99 | 11.1.17.29 |
11.1.17.14 | 11.1.17.29 | |
NS7600 | 11.1.17.14 | 11.1.17.31 |
NS7500 | 10.1.17.15, 10.1.17.36, 10.1.17.47, 10.1.17.63, 10.1.17.75, 10.1.17.91, 10.1.17.99 | 11.1.17.29 |
11.1.17.14 | 11.1.17.29 | |
NS3600 | 11.1.17.14 | 11.1.17.29 |
Note
To upgrade the Sensor to the 11.1.17.13/11.1.17.14 version, contact Trellix support.
Important
When you are downloading the Sensor software in the Manager, ensure that the Manager software release is equal to or higher than the Sensor software release. For example: If you are using 10.1.19.47 (10.1 Update 8) Manager, the Sensor software must be 10.1.17.63 (10.1 Update 8) or any lower version. You must not download the Sensor software 10.1.17.75 (10.1 Update 9) or a higher version using the 10.1.19.47 (10.1 Update 8) Manager.
If you have already downloaded a higher release of Sensor software in an older Manager release, the Manager is in a bad state. To recover the Manager, manually delete the Sensor software files.
Heterogeneous support
This version of 11.1 Manager software can be used to configure and manage the following devices:
Note
For this release of 11.1, a heterogeneous environment with Virtual IPS Sensors for AWS and Azure is not supported.
Device | Version |
|---|---|
NS-series Sensors (NS3100, NS3200, NS5100, NS5200, NS7150, NS7250, NS7350, NS7500, NS9100, NS9200, NS9300, NS9500 standalone and stack) | 10.1, 11.1 |
NS-series Sensors (NS3500, NS7100, NS7200, and NS7300) | 10.1 |
Virtual NTBA Appliances (T-VM, T-100VM, T-200VM) | 9.1 |
Integration support
The above-mentioned Trellix IPS software versions support integration with the following product versions
Product | Version supported |
|---|---|
Trellix Data Exchange Layer | 6.0.3 |
Trellix Endpoint Security | 10.7.0 |
Trellix ePolicy Orchestrator - On-prem | 5.10.0 Service Pack 1 Update 3 |
Trellix Global Threat Intelligence | Compatible with all versions |
Trellix Intelligent Sandbox | 5.2.0 and above |
Virtual Trellix Intelligent Sandbox | 5.2.0 and above |
Trellix Intelligent Virtual Execution - Server | 10.0.0, 9.1.4 |
Trellix Intelligent Virtual Execution Cloud | Version 24R1 |
Trellix Logon Collector | 3.0.11 |
Trellix Network Investigator (Appliance and Virtual) | 3.1.0 |
Trellix Threat Intelligence Exchange | 4.0.0 |