It is recommended that a desktop firewall operates on the Manager server. The following ports are required for Manager-Sensor communication.
Note
Ensure that there are no other open ports using a scanning tool, such as McAfee Vulnerability Manager.
| Port | Source | Destination | Description | Comments |
|---|---|---|---|---|
| 80 | Client | Manager | HTTP Port | Communication from client to Manager: Webstart/JNLP, Console applets |
| 443 | Client | Manager | HTTPS | Communication from client to Manager |
| 443 | Manager | NTBA Appliance | Command Channel (TCP) | Manager to NTBA Appliance. Communication is bidirectional |
| 3306 | Internal | Manager | Manager Database (MySQL or MariaDB) | Internal to Manager; can be used externally to connect to the database |
| 4166 | Manager | Sensor | Command Channel (UDP) | Source port for IPv6 Manager to Sensor Communication (Manager Java 1.7u45 and later). Communication between Sensor and Manager is bidirectional. |
| 4167 | Manager | Sensor | Command Channel (UDP) | Source port for IPv4 Manager to Sensor Communication. Communication between Sensor and Manager is bidirectional. |
| 8005 | Internal | Manager | Tomcat Shutdown Port (TCP) | Tomcat uses this port to listen for shutdown hook |
| 8007 | Internal | Manager | Tomcat AJP 12 Port (TCP) | Internal to Manager |
| 8009 | Internal | Manager | Tomcat AJP 13 Port (TCP) | Internal to Manager |
| 8500 | Manager | Sensor | Command Channel (UDP) | Communication between Sensor and Manager is bidirectional |
| 8501 | Sensor | Manager | Install Port/Channel (TCP) | Communication between Sensor and Manager is bidirectional |
| 8502 | Sensor | Manager | Alert Channel (Control Channel) (TCP) | Communication between Sensor and Manager is bidirectional |
| 8503 | Sensor | Manager | Packet Log Channel (TCP) | Communication between Sensor and Manager is bidirectional |
| 8504 | Sensor | Manager | File Transfer Channel (TCP) | Communication between Sensor and Manager is bidirectional |
| 8506 | Sensor | Manager | Install channel (TCP) (2048-bit) | Communication between Sensor and Manager is bidirectional |
| 8507 | Sensor | Manager | Alert channel (TCP) (2048-bit) | Communication between Sensor and Manager is bidirectional |
| 8508 | Sensor | Manager | Packet log channel (TCP) (2048-bit) | Communication between Sensor and Manager is bidirectional |
| 8509 | Sensor | Manager | Bulk file transfer channel for 2048-bit certificates (TCP) | Communication between Sensor and Manager is bidirectional |
| 8510 | Sensor | Manager | Bulk file transfer channel for 1024-bit certificates (TCP) | Communication between Sensor and Manager is bidirectional |
| 8551 | Internal | Manager | Lumos Nameserver (TCP) | Internal to Manager (RMI/IIOP) |
| 8552 | Internal | Manager | JONAS Nameserver (TCP) | Internal to Manager (RMI) |
| 8555 | Client | Manager | Alert Viewer (TCP) | Client to Manager SSL/TCP/IP
|
Note
- Ports 8501 to 8503, 8510 use SHA256 signed 2048 bit key length Self-Signed certificate.
- Ports 8506 to 8509 use SHA256 signed 2048 bit key length CA-Signed certificate.
If you configure Email Notification or SNMP Forwarding on the Manager, and have a firewall between the Manager and SMTP or SNMP Server, allow the following ports:
| Port | Description | Communication |
|---|---|---|
| 25 | SMTP port | Communication from Manager to SMTP server |
| 162 | SNMP forwarding | Communication from Manager to SNMP server |
Important
You must disable other web services before you install the Manager. The Manager server must integrate with the Apache server that's shipped with the Manager installation package. If other web services that use port 80 and 443 aren't disabled, the Manager installation fails. The failure happens because the Manager isn't able to run the Apache server.
Ports used by the Sensor
| Port | Description | Communication |
|---|---|---|
| 22 | SSH | SSH connection for command-line access to Sensor and Secure Copy from the Sensor to an SCP server for a manual load image or load configuration. |
Ports used for lookups and updates
| Port | Source | Destination | Comments |
|---|---|---|---|
| 80 TCP | Manager | download.nai.com | For downloading Botnet Detectors |
| 443 TCP | Sensor | nsp.rest.gti.trellix.com | Trellix GTI File Reputation query |
| 443 TCP | Manager/Sensor | nsp.repl.gti.trellix.comlist.smartfilter.com | Trellix GTI IP/URL reputation query |
| 443 TCP | Manager (MLOS only) | download.nai.com | For downloading Antivirus DAT Signatures |
| 443 TCP | Manager | nspupdate.trellix.com | IPS updates (can also be downloaded out-of-band and applied manually) |
| 443 TCP | Manager | nsp.repl.gti.trellix.com | Trellix GTI botnet detectors update; GTI participation information |
| 443 TCP | Sensor | To view the latest hostnames/URLs, see KB65496 | Gateway Anti-Malware engine (GAM) downloads |
| 443 TCP | Manager | Not yet available | IPS Manager Product Registration and Activation |
| 443 TCP | Manager | Not yet available | IPS Manager Product Registration and Activation |
| 443 TCP | Manager | Not yet available | IPS Manager Product Registration and Activation |
Third-party communications
In addition to the communication channels between the components of Trellix IPS, other communications can take place with third-party systems. These third-party systems include external syslog servers, SNMP monitoring systems, and authentication services.
| Port/Protocol | Source | Destination | Purpose |
|---|---|---|---|
| 25 TCP | Manager | $smtp-mta-server | Email notifications |
| 49 TCP | Sensor | $tacacs+-server | TACACS+ based authentication to Sensor for command-line interface |
| 69 UDP | Sensor | $tftp-server | TFTP server used for loadimage/netboot to install/update Sensor software |
| 162 UDP | Manager | $snmp-server | SNMP trap notifications |
| 389 TCP | Manager | $ldap-server | LDAP-based authentication to IPS Manager for GUI client |
| 514 TCP/UDP | Manager | $syslog-server | Notifications via syslog, standard UDP, or optionally TCP |
| 636 TCP | Manager | $ldaps-server | LDAPS-based authentication to IPS Manager for GUI client |
| 1812 UDP | Manager | $radius-server | RADIUS-based authentication to IPS Manager for GUI client |
Ports used for Network Threat Behavior Analysis (NTBA) communications
NTBA Appliances are similar to Sensors. However, they provide functionality focused on analyzing network flows which support overall analysis
| Port | Source | Destination | Purpose |
|---|---|---|---|
| 22 TCP | Any | NTBA | SSH connection for command-line access to Sensor |
| 22 TCP | NTBA | $netflow-exporter | Router ACL channel |
| 53 UDP | NTBA | $dns-server | DNS queries |
| 80 TCP | NTBA | tunnel.web.trustedsource.org list.smartfilter.com | GTO database download |
| 111 TCP/UDP | NTBA | $backup-server | NFS (optional) portmapper, for backups |
| 137 UDP | NTBA | <any> | NetBIOS lookups |
| 161 UDP | NTBA | $netflow-exporter | SNMP queries (2c/3) |
| 443 TCP | NTBA | tunnel.web.trustedsource.org | Trellix GTI IP reputation query |
| 443 TCP | NTBA | tau-usa.mcafee.com | Gateway Anti-Malware engine (GAM) downloads |
| 443 TCP | NTBA | tau.mcafee.com | Antimalware downloads |
| 445 TCP | NTBA | $backup-server | CIFS backups (optional) |
| 2049 TCP | NTBA | $backup-server | NFS (optional) for backups |
| 8444 TCP | NTBA | ePO | For certificate signing |
| 8501 TCP | NTBA | Manager | Install/control channel |
| 8502 TCP | NTBA | Manager | Alert channel |
| 8504 TCP | NTBA | Manager | File transfer channel |
| 8505 TCP | Sensor | NTBA | IPS channel (SSL AES-128 SHA-1) |
| 9008 UDP | EIA | NTBA | EIA service (DTLS) |
| 9996 UDP | $netflowexporter | NTBA | NetFlow channel |
Note
Some of the ports and protocols listed are optional; their use depends on your specific configuration.
Ports used for ePolicy Orchestrator communications
| Port | Source | Destination | Comments |
|---|---|---|---|
| 3306 TCP | ePO | Manager | [Manager to ePO integration] Database connection to enable Maanger-related dashboards in ePO console |
| 8443 TCP | Manager | ePO | [ePO to Manager integration] Manager pull/query of host information from ePO; requires Trellix IPS extension installation on ePO |
| 8501 TCP | ePO | Manager | [HIPS] Establish trust for HIPS push notifications |
| 8502 TCP | ePO | Manager | [HIPS] HIPS event push notifications |
| 8503 TCP | ePO | Manager | [HIPS] HIPS event push notifications |
Ports used for Trellix IPS Central Manager communications
| Port | Source | Destination | Comments |
|---|---|---|---|
| 443 TCP | Manager | Central Manager | Uses HTTPS protocol |
| 443 TCP | Central Manager | Manager | Uses HTTPS protocol |
Ports used for SIEM Enterprise Security Manager (ESM) communications
| Port | Source | Destination | Comments |
|---|---|---|---|
| 443 TCP | ESM | Manager | Access to Manager data |
| 3306 TCP | ESM | Manager | MariaDB queries |
Ports used for Trellix Intelligent Sandbox communications
| Port | Source | Destination | Comments |
|---|---|---|---|
| 443 TCP | Manager | Intelligent Sandbox | REST API communication |
| 8505 TCP | Sensor | Intelligent Sandbox | Communication channel for Sensor data |
Ports used for MVX communications
| Port | Source | Destination | Comments |
|---|---|---|---|
| 443 TCP | Manager | VX Appliance | MVX REST API communication |
| 443 TCP | Sensor | VX Appliance | MVX REST API communication |
Ports used for TIE/DXL communications
| Port | Source | Destination |
|---|---|---|
| 443 TCP | Sensor | ePO |
| 8081 TCP | ePO | Sensor |
| 8443 TCP | Sensor | ePO |
| 8883 TCP | Sensor | DXL Broker |
Note
If you have multiple DXL brokers, the Sensor connects to each of them on 8883 TCP. If the DXL broker is deployed on the ePO server, the Sensor connects to the ePO server on 8883 TCP.
Ports used for Logon Collector communications
| Port | Source | Destination | Comments |
|---|---|---|---|
| 61641 | Manager | MLC Server | JMS communications between the Logon Collector and Manager |
Ports used for Vulnerability Manager (MVM) communications
| Port | Source | Destination | Comments |
|---|---|---|---|
| 1433 TCP | Manager | MVM | Microsoft SQL Server connection for scheduled pull of scan results |
| 3801 TCP | Manager | MVM | Manager command channel for initiating on-demand scans (SSL encrypted propriety connection) |