This release of Trellix IPS is to provide new features and enhancements on the Manager and NS-series Sensor software.
Release parameters | Version |
|---|---|
IPS Manager software | 11.1.7.168 |
Signature Set | 11.10.38.3 |
NS-series Sensor software (NS9600, NS9500, NS7600, NS7500, NS7350, NS7250, NS7150, NS5200, NS5100, NS3600, NS3500, NS3200, NS3100) | 11.1.5.167 |
Trellix SSL Agent (For inbound SSL decryption using DHE/ECDHE ciphers) | 1.0.5 |
Suricata Snort Engine | 3.2.3 |
Caution
The IPS Manager no longer supports HTTP-based connection and can be accessed via HTTPS connection only. You need to manually enter the following on the supported browsers to access the Manager UI.
For Hostname or IPv4:
https://hostname or host-IPExample: https://localhost or https://10.x.x.x
For IPv6:
https://[IPv6 address]Example: https://[2607:8xxx:4xx:2xxx::5100]
Note
A direct upgrade from 11.1.7.153 or 11.1.7.153.9 to 11.1.7.168 is not supported on Trellix OS IPS Manager. These builds require a specific upgrade procedure. If you plan to upgrade from these builds, contact support for assistance.
If you plan to upgrade the Sensor software version to 11.1.5.167, you must first upgrade the corresponding Manager software to version 11.1.7.168 and then proceed with the Sensor upgrade.
For more information, see Manager and its compatible Sensor software versions in Trellix Intrusion Prevention System 11.1.x Product Guide.
Note
If you have a 9.x Manager managing 9.x NTBA, you should consider upgrading 9.x Manager to 10.1 or 11.1. If you plan to upgrade the Manager to 11.1, you need to first upgrade it to 10.1.7.65 and then to 11.1. From this release onwards, this only applies to Windows-based Manager upgrades.
Upgrade support
Trellix regularly releases updated versions of the signature set. You can choose to automatically download and deploy the signature set in the Manager.
Upgrade paths for Manager software versions
Note
Before you start upgrading to the latest 11.1 Manager version, ensure that you do not change the timestamp and timezone values of the Manager.
Caution
The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.
If you are currently using the Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.168, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.168. Post this, you may upgrade the Sensor to 11.1.5.167.
Windows-based Manager:
Version | Upgrade path to 11.1 |
|---|---|
10.1.7.4, 10.1.7.7, 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66.3, 10.1.7.66.11 | 11.1.7.168 |
11.1.7.3, 11.1.7.3.5, 11.1.7.26, 11.1.7.41, 11.1.7.41.2, 11.1.7.56, 11.1.7.71, 11.1.7.84, 11.1.7.97, 11.1.7.111, 11.1.7.121, 11.1.7.136, 11.1.7.136.2, 11.1.7.154 | 11.1.7.168 |
Note
For all direct upgrades to 11.1.7.168 for Windows-based Manager, use the
IPSM_1117168_setup.exefile.
Linux-based Manager:
Important
Physical appliances: To install the 11.1 Update 11 (Trellix OS) on your Manager appliance, you must migrate from 11.1 Update 9 (MLOS). For more information, see Migrating from MLOS Manager Appliance to Trellix OS Manager Appliance.
VM instances: You cannot perform a direct upgrade or migrate from 11.1 Update 9 to 11.1 Update 11. To install the 11.1 Update 11 version of the Trellix OS Manager on a VM, you must perform a fresh deployment and restore
All Table Backup. For more information, see Prepare for Trellix OS Manager fresh virtual machine instance deployment.
Version | Upgrade path to 11.1 |
|---|---|
11.1.7.154 | 11.1.7.168 |
Upgrade paths for Sensor software versions
Caution
The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.
If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.168, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.168. Post this, you may upgrade the Sensor to 11.1.5.168.
Sensor models | Version | Upgrade path to 11.1 |
|---|---|---|
NS9600 (Standalone and stack) | 11.1.5.113, 11.1.5.114, 11.1.5.139,11.1.5.151 | 11.1.5.167 |
NS9500 (Standalone) | 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190, 10.1.5.204 | 11.1.5.167 |
11.1.5.2, 11.1.5.22, 11.1.5.44, 11.1.5.57, 11.1.5.72, 11.1.5.84, 11.1.5.98, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.139, 11.1.5.151 | 11.1.5.167 | |
NS9500 (Stack) | 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190, 10.1.5.204 | 11.1.5.167 |
11.1.5.2, 11.1.5.22, 11.1.5.44, 11.1.5.57, 11.1.5.72, 11.1.5.84, 11.1.5.98, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.139, 11.1.5.151 | 11.1.5.167 | |
NS-series (NS5200, NS5100, NS3200, NS3100) | 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190, 10.1.5.202 | 11.1.5.167 |
11.1.5.2, 11.1.5.22, 11.1.5.44, 11.1.5.56, 11.1.5.72, 11.1.5.84, 11.1.5.98, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.136, 11.1.5.151 | 11.1.5.167 | |
NS7600 | 11.1.5.84, 11.1.5.99, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.139, 11.1.5.151 | 11.1.5.167 |
NS7500 | 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190, 10.1.5.202 | 11.1.5.167 |
11.1.5.2, 11.1.5.22, 11.1.5.44, 11.1.5.56, 11.1.5.72, 11.1.5.84, 11.1.5.98, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.139, 11.1.5.151 | 11.1.5.167 | |
NS7x50 | 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.107, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190, 10.1.5.204 | 11.1.5.167 |
11.1.5.2, 11.1.5.22, 11.1.5.44, 11.1.5.57, 11.1.5.72, 11.1.5.84, 11.1.5.98, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.136, 11.1.5.151 | 11.1.5.167 | |
NS3600 | 11.1.5.84, 11.1.5.98, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.139, 11.1.5.151 | 11.1.5.167 |
NS3500 | 10.1.5.3, 10.1.5.5, 10.1.5.41, 10.1.5.64, 10.1.5.75, 10.1.5.92, 10.1.5.106, 10.1.5.116, 10.1.5.153, 10.1.5.170, 10.1.5.190, 10.1.5.202 | 11.1.5.167 |
11.1.5.2, 11.1.5.22, 11.1.5.44, 11.1.5.56, 11.1.5.72, 11.1.5.84, 11.1.5.98, 11.1.5.113, 11.1.5.114, 11.1.5.122, 11.1.5.136, 11.1.5.151 | 11.1.5.167 |
Note
If the Sensor is running on 10.1.5.153 or a later version of 10.1 and you plan to downgrade it to 10.1.5.106 (for NS7500, NS5200, NS5100, NS3500, NS3200, NS3100) or 10.1.5.107 (for NS9500, NS7350, NS7250, NS7150) or any older version, you need to first downgrade the Sensor to 10.1.5.116 and then downgrade it to the targeted version.
Heterogeneous support
This version of 11.1 Manager software can be used to configure and manage the following devices:
Device | Version |
|---|---|
NS-series Sensors (NS3100, NS3200, NS3500, NS5100, NS5200, NS7150, NS7250, NS7350, NS7500, NS9500 standalone and stack) | 10.1, 11.1 |
NS-series Sensors (NS3600, NS7600, and NS9600 - standalone and stack)
| 11.1 |
Virtual IPS for KVM and ESXi server (IPS-VM600 and IPS-VM5000)
| 10.1, 11.1 |
Integration support
Trellix IPS version 11.1 supports integration with the following product versions:
Product | Version supported |
|---|---|
Trellix Data Exchange Layer | 6.0.3 |
Trellix Endpoint Security | 10.7.0 |
Trellix ePolicy Orchestrator - On-prem | 5.10 SP1 |
Trellix Global Threat Intelligence | Compatible with all versions |
Trellix Intelligent Sandbox | 5.4.0 and above |
Virtual Trellix Intelligent Sandbox | 5.4.0 and above |
Trellix Intelligent Virtual Execution - Server | 10.0.0, 11.0.1 |
Trellix Intelligent Virtual Execution Cloud | Version 25R4 |
Trellix Logon Collector | 3.0.11 |
Trellix Network Investigator (Appliance and Virtual) | 3.2.0 and 4.0.0 |
Trellix Threat Intelligence Exchange | 4.0.0 |