The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release.
For a list of current known issues, see: Trellix IPS 11.1 Known Issues (KB96274).
Resolved Manager software issues
The following table lists the high-severity Manager software issues:
Reference # | Resolution |
|---|---|
NSPMGR-28789 | Attack set profiles cannot be deleted after upgrading Linux-based Manager to 11.1 Update 7 software version. |
The following table lists the medium-severity Manager software issues:
Reference # | Resolution |
|---|---|
NSPMGR-29215 | VLAN bridging feature doesn't work in NS9500 stack setup. |
NSPMGR-29113 | After upgrading to 11.1 Minor 6 Manager and Sensor versions, when DNS configuration is disabled on the Sensor, multiple GTI: Risky URL Detected alerts get triggered. |
NSPMGR-28776 | RSA 4096-bit key CA-signed certificates are not visible on the GUI Certificates tab of the Manager → <Admin Domain Name> → Setup → Certificates page after upgrading to 11.1 Update 7 Manager version. |
NSPMGR-28765 | Secondary Manager's GUI certificate is copied to Primary Manager after a force switch over, even though the Copy Certificate option was disabled during the MDR pair configuration. |
NSPMGR-28738 | Unable to generate IPS Sensor Configuration Report in the Manager. |
NSPMGR-28592 | Attack Category drop-down appears blank when IPS Events is selected as Report Category and User defined as Report Type during the configuration of Automation Settings in the Manager → <Admin Domain Name> → Reporting → Report Automation page. |
NSPMGR-28575 | Error is displayed in the Manager when rule object count of more than 140,000 members is configured in NS9600 Sensor. |
NSPMGR-28562 | Managers in MDR pair with large scale pending event syncs (alert and packet logs) occasionally might show high CPU utilization. |
NSPMGR-28553 | IP: Connection Limiting Rule Match alert details In Manager show Observed Value instead of Exceeded Connection Count when the pre-configured threshold value is reached. |
NSPMGR-28543 | In a few cases, the Quarantine option is displayed for configuration in Sensor response actions in IPS policy for SmartVision attacks in 11.1 Update 7 Manager version after an upgrade. |
NSPMGR-28407 | Integration with Trellix Network Investigator (NI) is not inherited into the Sensor(s) in the child domain by default. |
NSPMGR-28074 | Reconnaissance Policy cannot be enabled when updating IPS policy via API in the Manager. |
NSPMGR-12094 | Customized user roles need to be re-assigned after a major version upgrade of IPS Manager. |
The following table lists the low-severity Manager software issues:
Reference # | Resolution |
|---|---|
NSPMGR-27111 | User assigned with a role excluding Guest Portal User Account Manager, User Auditing, and View Packet Captures privileges, is able to perform the same operations as Super User. |
Resolved Sensor software issues
The following table lists the high-severity Sensor software issues:
Reference # | Resolution |
|---|---|
NSPSNSR-16499 | Automatic GAM update fails and GAM engine status changes to uninitialized state due to FQDN change after sensor software upgrade or after executing |
NSPSNSR-16203 | Spike in flow pool memory causes 100% memory usage in Sensors after upgrading to 11.1 Update 5 Sensor version or higher. |
The following table lists the medium-severity Sensor software issues:
Reference # | Resolution |
|---|---|
NSPSNSR-16497 | Sensor crash is observed when aid logging is enabled for system event based attacks. |
NSPSNSR-16462 | Extra random character shows up at the end of the domain name when C&C Server Domain Name alert is generated. |
NSPSNSR-16334 | Sensor incorrectly raises the fault Device voltage is outside its normal range after upgrading to 11.1 Update 5 version. |
NSPSNSR-16333 | Sensor health moves between good and abnormal status due to incorrect reporting of PSU temperature. |
NSPSNSR-16217 | [NS9300] The G3 and G7 interface module LEDs do not turn on after upgrading Sensors to 11.1 Minor 6 version. |
NSPSNSR-16212 | Once Sensor is upgraded to 11.1 Update 5 version, it gets into uninitialized state if Application Identification feature is disabled. |
NSPSNSR-16068 | Packet buffer memory usage values differ between the Performance Charts page of the Manager and CLI output (show mem-usage) on the Sensor. |
NSPSNSR-16057 | Similar Domain names differing in case (block letters or small) were not handled resulting in false positive alerts for Advanced Callback Detection feature. |
NSPSNSR-14401 | SSL Proxy decryption doesn't work when VRRP's virtual IP address is used as default gateway on the client machine, making web application inaccessible. |