The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor features in FIPS compliant images

Prev Next

The algorithms implemented in the Sensor image are FIPS 140-3 compliant. Make note of the following features when FIPS compliant images are enabled in the Sensor:

Note

For a list of Sensor features that do not specifically relate to FIPS mode, refer to Trellix Intrusion Prevention System 11.1.x Product Guide.

  • The Sensor version supports features that are mandatory requirement for Common Criteria certification.

  • This FIPS Sensor image permits loading only SHA-256 signed images. You must netboot the Sensor to load a non-FIPS image signed with a weaker algorithm.

  • All critical security parameters (CSPs)/Sensitive security parameters (SSPs) are zeroized, in compliance with FIPS 140-3.

  • The following channels operate with algorithms approved by FIPS 140-3:

    • Install channel (8501)

    • Alert channel (8502)

    • Packet Log channel (8503)

    • Authentication channel (8502)

    • Malware file upload channel (8510)

    Note

    The SNMPv3 channel between the Manager and Sensor uses AES128 encryption, SHA authentication, and is RFC3414 and RFC3826 compliant. All CSP/SSP information on this channel is additionally encrypted by the Manager using the Sensor 2048-bit RSA public key and can be decrypted only by the Sensor private key.

  • Common Criteria compliance requires the use of specific secure protocols. Hence, SNMPv3 is further encapsulated within TLS (TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384). The Sensor will use port 18500 as a TLS server for this service.

    Note

    If the trust between the Manager and Sensor is established using a self-signed certificate, the Sensor will use port 8500 to service SNMPv3 as a TCP/UDP server. If the trust between the Manager and Sensor is established using a CA-signed certificate, the Sensor will use port 18500 to service SNMPv3 as a TLS server.

  • The Sensor supports read-only access to third party SNMPv3 clients. Third party SNMPv3 clients can only be configured at the Manager. The Sensor retains the use of port 8500 for SNMPv3 service to these clients.

  • The Sensor install, alert, packet log, authentication, and malware file upload channels use TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384.

  • TACACS+ authentication configuration is disabled at the Sensor level.

  • Stronger authentication for user login is enforced.

  • The Manager version that supports FIPS can manage Sensors that are not FIPS compliant. In the Common Criteria (CC) evaluated configuration, all Sensors must be in FIPS mode.

  • When a Sensor of a fail-over pair is running a FIPS image, it is mandatory for the peer Sensor to also be FIPS compliant.

    Note

    Before you upgrade, convert the Sensors in the fail-over pair to standalone Sensors. If you do not do this, trust will not be re-established after the upgrade.

  • The channels use RSA certificates based on 2048-bit RSA keys.

  • Use SCP for file transfers. The use of TFTP is not permitted.

  • Cryptographic support is provided by Trellix modified OpenSSL-FIPS-Object-Module v2.0 and OpenSSL 1.0.2zh-fips for IPS Manager.

  • Cryptographic support is provided by OpenSSL 1.0.2zk-fips for IPS Sensor.

  • Trellix modified OpenSSH v7.8p1 is configured to support only the following:

    SSH Client Configuration:

    • Ciphers: aes256-gcm@openssh.com and aes128-gcm@openssh.com

    • MACs: Implicit

    • KexAlgorithms: ecdh-sha2-nistp256

    • HostKeyAlgorithms: ecdsa-sha2-nistp256

    SSH Server Configuration:

    • Ciphers: aes256-gcm@openssh.com and aes128-gcm@openssh.com

    • MACs: Implicit

    • KexAlgorithms: ecdh-sha2-nistp256

    • HostKeyAlgorithms: ecdsa-sha2-nistp256

    User authentication:

    • Password, ssh-rsa, rsa-sha2-256, rsa-sha2-512 and ecdsa-sha2-nistp256

  • SSH in 11.1 FIPS Sensor image is restricted to AES128 and AES256 GCM Mode cipher only. The use of AES CBC or CTR mode is not permitted.

  • This requires that an external SSH client or server must support AES128 and AES256 GCM mode ciphers. Some popular clients (like PuTTY) may not support them currently. In such scenarios, you must migrate to an alternative SSH client or server approved by your local administrator.

  • The external SSH client is used to log into a Sensor running 11.1 FIPS image.

  • The external SSH server is used to host a remote Sensor image, that you can SCP into the Sensor running a 11.1 FIPS image using the loadimage CLI command.