This version of the release supports features that are mandatory requirements for CC certification.
The software combination recommended by Trellix to use along with this release of NS-series Sensor software are as listed below:
Release parameters | Version |
|---|---|
IPS Manager software version | 11.1.19.11 |
Signature Set | 11.10.18.2 |
NS-series Sensor software version (NS7150, NS7250, NS7350, and N9500 Sensors) | 11.1.17.13 |
NS-series Sensor software version (NS3100, NS3200, NS3600, NS5100, NS5200, NS7500, NS7600, NS9100, NS9200, and NS9300 Sensors) | 11.1.17.14 |
OpenSSL | v1.0.2zh-fips |
Important
Only NS9500, NS7600, NS7500, NS3600, and NS3200 Sensors and Trellix IPS Manager Appliance (Linux) are CC certified. For more information, see Trellix Intrusion Prevention System 11.1 FIPS and CC Certification Guide
Trellix IPS 11.1 release is CC certified and the review process for Trellix IPS 11.1 FIPS certification is currently in progress. Trellix Intrusion Prevention System 11.1 FIPS and CC Certification Guide contains information on both FIPS and CC compliant images. The content mentioned in the guide for FIPS and CC compliance also applies to CC certified software images.
This version supports all the features that are supported in Trellix Intrusion Prevention System 11.1.x non-CC versions. Above and beyond that, it includes support for FIPS. If you wish to learn about features released in non-CC compliant versions of the product, please refer to the following release notes:
IPS 11.1.7.84-11.1.5.84 NS-Series Release Notes
IPS 11.1.7.71-11.1.5.72 NS-Series Release Notes
IPS 11.1.7.56-11.1.5.56 NS-Series Release Notes
IPS 11.1.7.41-11.1.5.44 NS-Series Release Notes
IPS 11.1.7.26-11.1.5.22 NS-Series Release Notes
IPS 11.1.7.3-11.1.5.2 NS-Series Release Notes
Note
Manager software version 11.1 is not supported on Dell-based Manager Appliances. Trellix recommends that you use Intel-based Manager Appliances instead.
Note
If you have a 9.x Manager managing 9.x NTBA, you should consider upgrading 9.x Manager to 10.1 or 11.1. If you plan to upgrade the Manager to 11.1, you need to first upgrade it to 10.1.19.56 and then to 11.1.
Upgrade support
Trellix regularly releases updated versions of the signature set. You can choose to automatically download and deploy the signature set in the Manager.
Important
Trellix IPS Manager 11.1.19.11 enhances the communication security between the Manager and Central Manager (CVE-2024-5671, CVE-2024-5731). You must upgrade the Manager and Central Manager to the same version to avoid alert synchronization issues.
Upgrade paths for Manager software versions
Note
Windows-based Manager is not CC certified.
Linux-based Manager:
Manager upgrade paths
Manager version | Recommended Manager version |
|---|---|
10.1.19.17, 10.1.19.30, 10.1.19.33, 10.1.19.38, 10.1.19.47, 10.1.19.53, 10.1.19.56, 10.1.19.56.8 | 11.1.19.11 |
Important
After the upgrade, make sure to reboot the Linux-based Manager.
Upgrade paths for Sensor software versions
Sensor upgrade paths
Sensor model | Current Sensor software (CC compliant) | Upgrade path to latest CC compliant Sensor software |
|---|---|---|
NS3100, NS3200, NS5100, NS5200, NS9100, NS9200, NS9300 | 10.1.17.15, 10.1.17.26, 10.1.17.36, 10.1.17.47, 10.1.17.63, 10.1.17.75, 10.1.17.91, 10.1.17.99 | 11.1.17.14 |
NS7150, NS7250, NS7350, N9500 | 10.1.17.15, 10.1.17.26, 10.1.17.36, 10.1.17.50, 10.1.17.63, 10.1.17.75, 10.1.17.91, 10.1.17.96 | 11.1.17.13 |
NS7500 | 10.1.17.15, 10.1.17.36, 10.1.17.47, 10.1.17.63, 10.1.17.75, 10.1.17.91, 10.1.17.99 | 11.1.17.14 |
NS3600, NS7600 | NA | 11.1.17.14 |
Note
To upgrade the Sensor to the 11.1.17.13/11.1.17.14 version, contact Trellix support.
Important
When you are downloading the Sensor software in the Manager, ensure that the Manager software release is equal to or higher than the Sensor software release. For example: If you are using 10.1.19.47 (10.1 Update 8) Manager, the Sensor software must be 10.1.17.63 (10.1 Update 8) or any lower version. You must not download the Sensor software 10.1.17.75 (10.1 Update 9) or a higher version using the 10.1.19.47 (10.1 Update 8) Manager.
If you have already downloaded a higher release of Sensor software in an older Manager release, the Manager is in a bad state. To recover the Manager, manually delete the Sensor software files.
Pre-requisites for using the Sensor software 11.1.17.13 and 11.1.17.14
Upgrade Baseboard Management Controller (BMC) firmware
The 11.1.17.13 version contains BMC firmware updates for NS9500 and NS7x50 Sensors. For further assistance, contact Trellix support.
Update Gateway Anti-Malware (GAM) engine to version 2023
You need to update the Gateway Anti-Malware (GAM) engine running on NS-series Sensors to version 2023 to detect malware files in air-gap network environments. Perform the steps listed below to manually download the Gateway Anti-Malware Engine update file (.upd) and deploy it to your Sensors:
Using a recent version of your browser, go to the Gateway Anti-Malware Update Server URL (https://contentsecurity.skyhigh.cloud/UPDATE) and download the GAM update package file (.upd).
After the file is downloaded, log on to the Manager and go to Manager → <Admin Domain Name> → Trellix IPS Protection Status. Go to the Manual Import tab, select the required package file, and click Import.
From the Sensor CLI, run the
reset-gam-updatecommand in debug mode to delete all previous GAM packages and related data.In the Manager, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Deploy Pending Changes. In the Deploy Pending Changes page, the Pending Changes column displays New Gateway Anti-Malware Versions. Select the checkbox for GAM Updates and click Deploy.
Alternatively, you can navigate to Devices → <Admin Domain Name> → Global → Device Manager page and perform a bulk sync by selecting multiple Sensors for the deployment of GAM updates. Once the GAM update is successfully deployed and initialized on the required Sensors, those will start to detect the malware files. For more information, see Update Gateway Anti-Malware Engine manually in Trellix Intrusion Prevention System 11.1 Installation Guide.
Heterogeneous support
This version of 11.1 Manager software can be used to configure and manage the following devices:
Note
For this release of 11.1, a heterogeneous environment with Virtual IPS Sensors for AWS and Azure is not supported.
Device | Version |
|---|---|
NS-series Sensors (NS3100, NS3200, NS5100, NS5200, NS7150, NS7250, NS7350, NS7500, NS9100, NS9200, NS9300, NS9500 standalone and stack) | 10.1, 11.1 |
NS-series Sensors (NS3500, NS7100, NS7200, and NS7300) | 10.1 |
Virtual NTBA Appliances (T-VM, T-100VM, T-200VM) | 9.1 |
Integration support
The above-mentioned Trellix IPS software versions support integration with the following product versions:
Product | Version supported |
|---|---|
Trellix Data Exchange Layer | 6.0.3 |
Trellix Endpoint Security | 10.7.0 |
Trellix ePolicy Orchestrator - On-prem | 5.10.0 Service Pack 1, Update 2 |
Trellix Global Threat Intelligence | Compatible with all versions |
Trellix Intelligent Sandbox | 5.2.4, 5.2.2 |
Virtual Trellix Intelligent Sandbox | 5.2.4, 5.2.2 |
Trellix Intelligent Virtual Execution - Server | 10.0.0, 9.1.4 |
Trellix Intelligent Virtual Execution Cloud | Version 24R1 |
Trellix Logon Collector | 3.0.11 |
Trellix Network Investigator (Appliance and Virtual) | 3.0.0 |
Trellix Threat Intelligence Exchange | 4.0.0 |
McAfee Endpoint Intelligence Agent | 3.2.4 |
Note
After upgrading the Manager to 11.1.19.11, download the latest ePO extension and import it into the ePO user interface to avoid connectivity issues.