This release of Trellix IPS is to provide new features and enhancements on the Manager and NS-series Sensor software.
| Release parameters | Version |
|---|---|
| IPS Manager software | 10.1.7.65 |
| Signature Set | 10.9.37.7 |
| NS-series Sensor software (NS9500, NS9300, NS9200, NS9100, NS7500, NS7350, NS7300, NS7250, NS7200, NS7150, NS7100, NS5200, NS5100, NS3500, NS3200, NS3100) | 10.1.5.190 |
| Trellix SSL Agent (For inbound SSL decryption using DHE/ECDHE ciphers) | 1.0.4 |
| Suricata Snort Engine | 3.2.3 |
Note
The Signature Set version 10.9.37.7 bundled with this release of Manager contains only Digital Envoy database for IP address to Geolocation Mapping. This signature set version will not be a part of the publicly available signature sets.
Note
When you upgrade the Sensor software version to 10.1.5.190, you must also upgrade the corresponding Manager software version to 10.1.7.65
For more information, see Manager and its compatible Sensor software versions in Trellix Intrusion Prevention System 10.1.10 Product Guide.
Note
The Sensor software version 10.1 is not supported on M-series Sensor models. The end-of-life for M-series Sensor models has been declared and the end-of-life is on 31-Dec, 2021. Trellix recommends you to migrate from M-series Sensor models to NS-series Sensor models.
Note
The Manager software 10.1 is not supported on Windows-based Appliance. The end-of-life for Windows-based Appliance has been declared and the end-of-life is on 1-Apr, 2023. Trellix recommends you to migrate from Windows-based Appliance to Linux-based Appliance.
Upgrade support
Trellix regularly releases updated versions of the signature set. You can choose to automatically download and deploy the signature set in the Manager.
Upgrade paths for Manager software versions
Note
Before you start upgrading to the latest 10.1 Manager version, ensure that you do not change the timestamp and timezone values of the Manager.
Caution
Starting with release 10.1.7.50, the Manager software version supports only TLS 1.2 ciphers for Manager and Sensor communication.
Caution
If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 10.1.7.50 or later, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 10.1.7.50 or later versions. Post this, you can upgrade the Sensor to 10.1.5.190
For example, if you have a NS9500 Sensor running on software version 9.2.5.52 (TLS 1.0) and Manager software version 10.1.7.44, and you plan to upgrade the Sensor to 10.1.5.190 and Manager to 10.1.7.65, you must follow the upgrade path as listed below:
- Upgrade your NS9500 Sensor from 9.2.5.52 (Supports TLS 1.0) to 10.1.5.107 (Supports TLS 1.2).
- Upgrade the Manager from 10.1.7.44 to 10.1.7.65
- Upgrade the Sensor from 10.1.5.107 to 10.1.5.190
Similarly, if you have a NS9300 Sensor running on software version 9.2.5.72 (TLS 1.0) and Manager software version 10.1.7.44, you must follow the upgrade path as listed below:
- Upgrade your NS9300 Sensor from 9.2.5.72 (Supports TLS 1.0) to 9.2.5.190 or 10.1.5.106 (Supports TLS 1.2).
- Upgrade the Manager from 10.1.7.44 to 10.1.7.65.
- Upgrade the Sensor from 9.2.5.190 or 10.1.5.106 to 10.1.5.190.
Windows based Manager:
| Version | Upgrade path to 10.1 |
|---|---|
| 9.1.7.11, 9.1.7.15, 9.1.7.49, 9.1.7.63, 9.1.7.73, 9.1.7.75, 9.1.7.77, 9.1.7.80, 9.1.7.83 | 10.1.7.65 |
| 9.2.7.9, 9.2.7.22, 9.2.7.31, 9.2.9.5, 9.2.9.12, 9.2.9.53, 9.2.9.55, 9.2.9.60 | 10.1.7.65 |
| 10.1.7.4, 10.1.7.7, 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61 | 10.1.7.65 |
Linux based Manager:
Caution
After upgrade, the Linux-based Manager reboot automatically. If it fails to reboot, check the installation logs for errors and reboot the Manager manually.
| Version | Upgrade path to 10.1 |
|---|---|
9.1.7.49, 9.1.7.63, 9.1.7.73, 9.1.7.75, 9.1.7.77
|
9.1.7.77.11 | 10.1.7.65 |
| 9.1.7.80, 9.1.7.83 | 10.1.7.65 |
| 9.2.7.31, 9.2.9.8, 9.2.9.12, 9.2.9.53, 9.2.9.55, 9.2.9.60 | 10.1.7.65 |
| 10.1.7.4, 10.1.7.7, 10.1.7.25 (Cloud), 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61 | 10.1.7.65 |
Note
For all direct upgrades to 10.1.7.65 , use the IPSM_101765_setup.bin Version 10.1.7.65 upgrade file.
Upgrade paths for Sensor software versions
Caution
Starting with release 10.1.7.50, the Manager software version supports only TLS 1.2 ciphers for Manager and Sensor communication.
Caution
If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 10.1.7.50 or later, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 10.1.7.50 or later versions. Post this, you can upgrade the Sensor to 10.1.5.190
For example, if you have a NS9500 Sensor running on software version 9.2.5.52 (TLS 1.0) and Manager software version 10.1.7.44, and you plan to upgrade the Sensor to 10.1.5.190 and Manager to 10.1.7.65, you must follow the upgrade path as listed below:
- Upgrade your NS9500 Sensor from 9.2.5.52 (Supports TLS 1.0) to 10.1.5.107 (Supports TLS 1.2).
- Upgrade the Manager from 10.1.7.44 to 10.1.7.65
- Upgrade the Sensor from 10.1.5.107 to 10.1.5.190
Similarly, if you have a NS9300 Sensor running on software version 9.2.5.72 (TLS 1.0) and Manager software version 10.1.7.44, you must follow the upgrade path as listed below:
- Upgrade your NS9300 Sensor from 9.2.5.72 (Supports TLS 1.0) to 9.2.5.190 or 10.1.5.106 (Supports TLS 1.2).
- Upgrade the Manager from 10.1.7.44 to 10.1.7.65.
- Upgrade the Sensor from 9.2.5.190 or 10.1.5.106 to 10.1.5.190.
| Sensor models | Version | TLS support | Upgrade path to 10.1 |
|---|---|---|---|
| NS9500 (Standalone) | 9.2.5.50, 9.2.5.52, 9.2.5.88, 9.2.5.91 | TLS 1.0 | 10.1.5.107 | 10.1.5.190 |
| 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170 | TLS 1.2 | 10.1.5.190 | |
| NS9500 (Stack) | 9.2.5.88, 9.2.5.91 | TLS 1.0 | 10.1.5.107 | 10.1.5.190 |
| 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170 | TLS 1.2 | 10.1.5.190 | |
| NS-series (NS9300, NS9200, NS9100, NS7300, NS7200, NS7100, NS5200, NS5100, NS3200, NS3100) | 9.1.5.9, 9.1.5.20, 9.1.5.23 | TLS 1.2 | 9.1.5.102 | 10.1.5.190 |
| 9.1.5.40, 9.1.5.56, 9.1.5.63, 9.1.5.80, 9.1.5.102 | TLS 1.2 | 10.1.5.190 | |
| 9.2.5.6, 9.2.5.25, 9.2.5.27, 9.2.5.72 | TLS 1.0 | 9.2.5.190 or 10.1.5.106 | 10.1.5.190 | |
| 9.2.5.153, 9.2.5.163, 9.2.5.190 | TLS 1.2 | 10.1.5.190 | |
| 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170 | TLS 1.2 | 10.1.5.190 | |
| NS7500 | 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170 | TLS 1.2 | 10.1.5.190 |
| NS7x50 | 9.1.5.15, 9.1.5.20, 9.1.5.23 | TLS 1.2 | 9.1.5.102 | 10.1.5.190 |
| 9.1.5.40, 9.1.5.56, 9.1.5.63, 9.1.5.80, 9.1.5.102 | TLS 1.2 | 10.1.5.190 | |
| 9.2.5.27, 9.2.5.72 | TLS 1.0 | 9.2.5.190 or 10.1.5.107 | 10.1.5.190 | |
| 9.2.5.153, 9.2.5.163, 9.2.5.190 | TLS 1.2 | 10.1.5.190 | |
| 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170 | TLS 1.2 | 10.1.5.190 | |
| NS3500 | 9.2.5.34 | TLS 1.0 | 10.1.5.106 | 10.1.5.190 |
| 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170 | TLS 1.2 | 10.1.5.190 |
Note
If the Sensor is running on 10.1.5.153 or a later version of 10.1 and you plan to downgrade it to 10.1.5.106 (for NS9300, NS9200, NS9100, NS7500, NS7300, NS7200, NS7100, NS5200, NS5100, NS3500, NS3200, NS3100) or 10.1.5.107 (for NS9500, NS7350, NS7250, NS7150) or any older version, you need to first downgrade the Sensor to 10.1.5.116 and then, downgrade it to the targeted version.
Important
- When you are downloading the Sensor software in the Manager, ensure that the Manager software release is equal to or higher than the Sensor software release. For example: If you are using 10.1.7.55 (10.1 Update 8) Manager, the Sensor software must be 10.1.5.153 (10.1 Update 8) or any lower version. You must not download the Sensor software 10.1.5.170 (10.1 Update 9) or higher version using the 10.1.7.55 (10.1 Update 8) Manager.
- If you have already downloaded a higher release of Sensor software in an older Manager release, the Manager is in a bad state. To recover the Manager, manually delete the Sensor software files.
Heterogeneous support
This version of 10.1 Manager software can be used to configure and manage the following devices:
Note
For this release of 10.1, heterogeneous environment with Virtual IPS Sensors for AWS and Azure is not supported.
| Device | Version |
|---|---|
| NS-series Sensors (NS3100, NS3200, NS5100, NS5200, NS7100, NS7200, NS7300, NS7150, NS7250, NS7350, NS9100, NS9200, NS9300) | 9.1, 9.2, 10.1 |
| NS-series Sensors (NS3500, NS9500 standalone and stack) | 9.2, 10.1 |
| NS-series Sensors (NS7500) | 10.1 |
| Virtual IPS for ESXi server (IPS-VM600) | 9.1, 9.2, 10.1 |
| M-series Sensors (M-1250, M-1450, M-2850, M-2950, M-3030, M-3050, M-4030, M-4050, M-6030, M-6050, M-8000, M-8030) | 9.1 |
| M-8000XC Cluster Appliance | 9.1 |
| NTBA Appliances (T-600, T-1200) | 9.1 |
| Virtual NTBA Appliances (T-VM, T-100VM, T-200VM) | 9.1 |
Integration support
Trellix IPS version 10.1 supports integration with the following product versions:
Note
Starting with this release of 10.1, integration with McAfee Host Intrusion Prevention is no longer supported.
| Product | Version supported |
|---|---|
| McAfee ePO™ | 5.10.0 Update 13 |
| Trellix Endpoint Security (formerly, McAfee Endpoint Security) | 10.7.0 |
| Trellix Global Threat Intelligence™ (formerly, McAfee Global Threat Intelligence™) | Compatible with all versions |
| McAfee Endpoint Intelligence Agent | 3.2.4 |
| McAfee Logon Collector | 3.0.10 |
| Trellix Threat Intelligence Exchange (formerly, McAfee Threat Intelligence Exchange) | 3.0.1 |
| Trellix Data Exchange Layer (formerly, McAfee Data Exchange Layer) | 6.0.3 |
| Trellix Intelligent Sandbox (formerly, McAfee Advanced Threat Defense) | 5.0, 4.14.2 |
| Virtual Trellix Intelligent Sandbox (formerly, McAfee Virtual Advanced Threat Defense ) | 5.0, 4.14.2 |
| McAfee Vulnerability Manager | 7.5.14 |
| Trellix Virtual Execution | 9.1.2 and above |