The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release.
For a list of current known issues, see: Trellix IPS 11.1 Known Issues (KB96274).
Resolved Manager software issues
The following table lists the high-severity Manager software issues:
Reference # | Resolution |
|---|---|
NSPMGR-29811 | Exported custom attack files are corrupted in Manager version 11.1.7.136. |
NSPMGR-29241 | Target Port value cannot be set in the Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Ignore rules page. |
The following table lists the medium-severity Manager software issues:
Reference # | Resolution |
|---|---|
NSPMGR-29623 | The Port rate chart for the NS9600 Sensor is not displayed in the Performance Chart view. |
NSPMGR-29662 | Interface option cannot be selected in Analysis → Event Reporting → Traditional Reports → User Defined report. |
NSPMGR-29880 | Incorrect file path is displayed in Manager → <Admin Domain Name> → Troubleshooting → Logs page when an invalid Suricata Snort rule is created. |
NSPMGR-29778 | Manually imported Sensor software version is not displayed on Manager → <Admin Domain Name> → Trellix IPS Protection Status → Device Software tab in Firefox browser. |
NSPMGR-29770 | Date range selection for attacks doesn't work in Analysis → Event Reporting → Traditional Reports → User Defined report. |
NSPMGR-29731 | Spelling errors are observed in CLI outputs during the upgrade of Linux-based Manager (MLOS). |
NSPMGR-29687 | "---" automatically appears in the Contact Information, Location, and Comment fields in Devices → <Admin Domain Name> → Devices → <Device Name> → Summary page after upgrading Manager version to 11.1.7.136. |
NSPMGR-29522 | Importing a policy fails when the policy includes an Ignore Rule of the type Network Group for Ignore Rules and contains custom rules. This occurs when you export the policy and then attempt to re-import it into the Manager. |
NSPMGR-29478 | The Device Information option cannot be unchecked for Manager → Reporting → Report Automation → Automation Settings → Configuration Report → IPS Sensor report type. |
NSPMGR-29444 | After manually importing and then bulk editing Reconnaissance Attacks to reconfigure fields, the existing Sensor response action "Send Alert to Manager" is automatically removed. |
NSPMGR-29358 | Unable to assign Firewall-Device First or Firewall-Device Last policy at the device level from the Policy Manager page. |
NSPMGR-29258 | PublicKeyAuth command is not working for HostKey authentication in Linux-based Manager (MLOS). |
NSPMGR-29135 | After Inheriting settings for the IVX integration in a child domain, database initialization failure is observed during Manager upgrade. |
NSPMGR-29126 | Telemetry data handles serialization cleanly by separating the data architecture from service-layer logic. This ensures that daily telemetry updates are saved successfully to the Manager database without generating false fault alerts. |
Resolved Sensor software issues
The following table lists the high-severity Sensor software issues:
Reference # | Resolution |
|---|---|
NSPSNSR-16852 | The Sensor is adding extra bytes to TCP segmented packets, causing traffic delays. |
NSPSNSR-16762 | Packet drop is observed with non-matching certificate flows during SSL inspection. |
The following table lists the medium-severity Sensor software issues:
Reference # | Resolution |
|---|---|
NSPSNSR-16835 | Sensor software version does not get updated in Manager database after upgrading Sensors to 11.1 Update 9 version. |
NSPSNSR-16758 | The Sensor fails to display endpoint-based objects when configuring an exception rule. |
NSPSNSR-16651 | All files submitted to the IVX engine for malware inspection are in a 'Pending' state in the IPS Manager. |
NSPSNSR-15060 | SSL traffic with Diffie Hellman ciphers is getting stuck in Layer7 queue when sessions are for SSL resumption. |
NSPSNSR-15830 | Process tsproc crash is observed. |