The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release.
For a list of current known issues, see: Trellix IPS 11.1 Known Issues (KB96274).
Resolved Manager software issues
The following table lists the high-severity Manager software issues:
Reference # | Resolution |
|---|---|
NSPMGR-30119 | Fixes an issue where the system remained in a persistent loading state when attempting to create Correlation-Based Custom Reconnaissance Attack. |
NSPMGR-30010 | Updated the compilation failure message to specify the missing rule object ID when a signature deployment fails. |
The following table lists the medium-severity Manager software issues:
Reference # | Resolution |
|---|---|
NSPMGR-30213 | Changes to the Syslog Facility option in the Manager → Setup → Notification → IPS quarantine access events page would not save and reverted to the default value. |
NSPMGR-30208 | Enhances the scheduler logic to automatically download the Public Global Threat Intelligence (GTI) certificate file (tsgtipubcerts.bin) if it is missing from the Manager. |
NSPMGR-30098 | The CustomJSSEcaCerts file (/opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts) is set to read-only permissions after a fresh installation or migration to TREFOS. This prevents write access and causes LDAP authentication failures. |
NSPMGR-30097 | The show ipsmanager logs command fails to list the logs in the CLI and displays the error: % No folder/directory present: /var/opt/ipsm/logs/. Workaround: Log in to root mode to access the log files. |
NSPMGR-30018 | Ensures the option to copy the Graphical User Interface (GUI) certificate is respected during MDR pair creation. |
NSPMGR-29918 | The automatic Callback Detectors successfully deploys to Sensors on the Azure platform. |
NSPMGR-29870 | The Post-Attack notation appears correctly in the Capture Packets field of the attack definitions grid when viewed in the policy screen. |
NSPMGR-29865 | Snort rule validation correctly shows failed status for invalid rules, and rule syntax remains visible after adding a rule. |
NSPMGR-29753 | Changing the Application Identification setting for member Sensors in a stack correctly triggers the Deploy Pending Changes flag. |
NSPMGR-29484 | The CSV files containing Chinese characters in the filename import correctly into the blocked file hash list. |
NSPMGR-29467 | The Manager is correctly excluded as a fault source in the Fault Report when only the Sensor is selected in Manager → Reporting → Configuration Reports → Faults. |
NSPMGR-29251 | Windows-based Managers successfully access APIs related to cloud clusters without internal errors. |
NSPMGR-28850 | Azure cloud discovery works correctly when using a proxy server by properly handling HTTPS proxy requests. |
NSPMGR-27897 | NTP and Restrict SSH Access settings persist on Failover (FO) Sensors after changing the Sensor's Internet Protocol (IP) address. |
Resolved Sensor software issues
The following table lists the high-severity Sensor software issues:
Reference # | Resolution |
|---|---|
NSPSNSR-17183 | The backend processor incorrectly handled memory segments during the decode process. This caused buffer corruption resulting in a backend process crash. |
NSPSNSR-17103 | Global Threat Intelligence (GTI) credentials remain persistent across sensor reboots. This ensures that authentication checks pass successfully using existing data, preventing "Invalid GTI Private Cloud Server username" errors. |
The following table lists the medium-severity Sensor software issues:
Reference # | Resolution |
|---|---|
NSPSNSR-17187 | The NS3600 sensor model supports up to 100,000 customized attacks. This increase from the previous 40,000 limit allows successful configuration pushes when attack counts are high. |
NSPSNSR-17091 | Enhanced alert throttling (specifically the 24-hour alert suppression window) is unavailable on NS7600 Sensors running with a 20 Gbps license. |
NSPSNSR-17079 | The Alert Channel connection to the Standby Manager intermittently disconnects and reconnects (flaps) on Virtual IPS Sensor configured with a CA-signed 2048-bit trust certificate in an MDR environment. |
NSPSNSR-17030 | SSL proxy exceptions were not working correctly in scenarios where the traffic bypass decision was delayed. |
NSPSNSR-17019 | Allow list/Block list bulk update fails when there are hash entries with file size 0. |
NSPSNSR-16940 | [NS3600] "Keep Monitoring ports enabled on Link Failures" does not work when NS3600 sensors are configured for failover. |
NSPSNSR-16939 | Corrects misleading malware statistics for the IVX engine by ensuring files are marked as "Ignored" instead of "Processed" when no broker is configured. |
NSPSNSR-16774 | Malware FFP Bulk Update failure was seen due to list corruption. |
NSPSNSR-16411 | Resolves a delay in Secure Shell (SSH) connection establishment and CLI command execution observed after upgrading Sensors to version 11.1. |