It is recommended that a desktop firewall operate on the Manager server. The following ports are required for Manager-Sensor communication.
Note
Ensure that there are no other open ports using a scanning tool.
Port | Source | Destination | Description | Comments |
|---|---|---|---|---|
443 | Client | Manager | HTTPS | Communication from client to Manager
|
443 | Manager | NTBA Appliance | Command Channel (TCP) | Manager to NTBA Appliance. Communication is bidirectional |
3306 | Internal | Manager | Manager Database (MySQL or MariaDB) | Internal to Manager; can be used externally to connect to the database |
4166 | Manager | Sensor | Command Channel (UDP) | Source port for IPv6 Manager to Sensor Communication (Manager Java 1.7u45 and later). Communication between Sensor and Manager is bidirectional. |
4167 | Manager | Sensor | Command Channel (UDP) | Source port for IPv4 Manager to Sensor Communication. Communication between Sensor and Manager is bidirectional. |
8005 | Internal | Manager | Tomcat Shutdown Port (TCP) | Tomcat uses this port to listen for shutdown hook |
8007 | Internal | Manager | Tomcat AJP 12 Port (TCP) | Internal to Manager |
8009 | Internal | Manager | Tomcat AJP 13 Port (TCP) | Internal to Manager |
8500 | Manager | Sensor | Command Channel (UDP) | Communication between Sensor and Manager is bidirectional |
8501 | Sensor | Manager | Install Port/Channel (TCP - Self-Signed) | Communication between Sensor and Manager is bidirectional |
8502 | Sensor | Manager | Alert Channel (Control Channel) (TCP - Self-Signed) | Communication between Sensor and Manager is bidirectional |
8503 | Sensor | Manager | Packet Log Channel (TCP - Self-Signed) | Communication between Sensor and Manager is bidirectional |
8504 | Sensor | Manager | File Transfer Channel (TCP) | Communication between Sensor and Manager is bidirectional |
8506 | Sensor | Manager | Install channel (TCP - CA-Signed) | Communication between Sensor and Manager is bidirectional |
8507 | Sensor | Manager | Alert channel (TCP - CA-Signed) | Communication between Sensor and Manager is bidirectional |
8508 | Sensor | Manager | Packet log channel (TCP - CA-Signed) | Communication between Sensor and Manager is bidirectional |
8509 | Sensor | Manager | Bulk file transfer channel for certificates (TCP - CA-Signed) | Communication between Sensor and Manager is bidirectional |
8510 | Sensor | Manager | Bulk file transfer channel for certificates (TCP - Self-Signed) | Communication between Sensor and Manager is bidirectional |
8551 | Internal | Manager | Lumos Nameserver (TCP) | Internal to Manager (RMI/IIOP) |
8552 | Internal | Manager | JONAS Nameserver (TCP) | Internal to Manager (RMI) |
Note
Ports 8501 to 8503, 8510 use SHA256 signed 2048-bit or 4096-bit key length Self-Signed certificates.
Ports 8506 to 8509 use SHA256 signed 2048-bit or 4096-bit key length CA-Signed certificates.
If you configure Email Notification or SNMP Forwarding on the Manager, and have a firewall between the Manager and SMTP or SNMP Server, allow the following ports:
Port | Description | Communication |
|---|---|---|
25 | SMTP port | Communication from Manager to SMTP server |
162 | SNMP forwarding | Communication from Manager to SNMP server |
Important
You must disable other web services before you install the Manager. The Manager server must integrate with the Apache server that's shipped with the Manager installation package. If other web services that use port 80 and 443 aren't disabled, the Manager installation fails. The failure happens because the Manager isn't able to run the Apache server.
Ports used for lookups and updates
Port | Source | Destination | Comments |
|---|---|---|---|
80 TCP | Manager | download.nai.com | For downloading Botnet Detectors |
443 TCP | Sensor | nsp.rest.gti.trellix.com | Trellix GTI File Reputation query |
443 TCP | Manager/Sensor | nsp.repl.gti.trellix.comlist.smartfilter.com | Trellix GTI IP/URL reputation query |
443 TCP | Manager (MLOS only) | download.nai.com | For downloading Antivirus DAT Signatures |
443 TCP | Manager | nspupdate.trellix.com | IPS updates (can also be downloaded out-of-band and applied manually) |
443 TCP | Manager | ips.repm.gti.trellix.com | Trellix GTI botnet detectors update; GTI participation information |
443 TCP | Manager | tau.skyhigh.cloud cdn.tau.skyhigh.cloud europe.tau.skyhigh.cloud usa.tau.skyhigh.cloud asia.tau.skyhigh.cloud For more information, see KB59342 | Gateway Anti-Malware engine (GAM) downloads |
443 TCP | Sensor | tau.skyhigh.cloud cdn.tau.skyhigh.cloud europe.tau.skyhigh.cloud usa.tau.skyhigh.cloud asia.tau.skyhigh.cloud For more information, see KB59342 | Gateway Anti-Malware engine (GAM) downloads |
443 TCP | Manager | iam.cloud.trellix.com iam-rs.cloud.trellix.com telemetry.trellix.com up-cloud.fireeye.com/fenet/notification | IPS Manager Product Registration, Activation, and Telemetry |
443 TCP | Manager/Sensor | feapi.marketplace.apps.fireeye.com | For IVX Cloud communication |
Third-party communications
In addition to the communication channels between the components of Trellix IPS, other communications can take place with third-party systems. These third-party systems include external syslog servers, SNMP monitoring systems, and authentication services.
Port/Protocol | Source | Destination | Purpose |
|---|---|---|---|
25 TCP | Manager | $smtp-mta-server | Email notifications |
49 TCP | Sensor | $tacacs+-server | TACACS+ based authentication to Sensor for command-line interface |
69 UDP | Sensor | $tftp-server | TFTP server used for loadimage/netboot to install/update Sensor software |
162 UDP | Manager | $snmp-server | SNMP trap notifications |
389 TCP | Manager | $ldap-server | LDAP-based authentication to IPS Manager for GUI client |
514 TCP/UDP | Manager | $syslog-server | Notifications via syslog, standard UDP, or optionally TCP |
636 TCP | Manager | $ldaps-server | LDAPS-based authentication to IPS Manager for GUI client |
1812 UDP | Manager | $radius-server | RADIUS-based authentication to IPS Manager for GUI client |
Ports used for Network Threat Behavior Analysis (NTBA) communications
NTBA Appliances are similar to Sensors. However, they provide functionality focused on analyzing network flows which support overall analysis
Port | Source | Destination | Purpose |
|---|---|---|---|
22 TCP | Any | NTBA | SSH connection for command-line access to Sensor |
22 TCP | NTBA | $netflow-exporter | Router ACL channel |
53 UDP | NTBA | $dns-server | DNS queries |
80 TCP | NTBA | tunnel.web.trustedsource.org list.smartfilter.com | GTO database download |
111 TCP/UDP | NTBA | $backup-server | NFS (optional) portmapper, for backups |
137 UDP | NTBA | <any> | NetBIOS lookups |
161 UDP | NTBA | $netflow-exporter | SNMP queries (2c/3) |
443 TCP | NTBA | tunnel.web.trustedsource.org | Trellix GTI IP reputation query |
443 TCP | NTBA | tau-usa.mcafee.com | Gateway Anti-Malware engine (GAM) downloads |
443 TCP | NTBA | tau.mcafee.com | Antimalware downloads |
445 TCP | NTBA | $backup-server | CIFS backups (optional) |
2049 TCP | NTBA | $backup-server | NFS (optional) for backups |
8444 TCP | NTBA | ePO | For certificate signing |
8501 TCP | NTBA | Manager | Install/control channel |
8502 TCP | NTBA | Manager | Alert channel |
8504 TCP | NTBA | Manager | File transfer channel |
8505 TCP | Sensor | NTBA | IPS channel (SSL AES-128 SHA-1) |
9008 UDP | EIA | NTBA | EIA service (DTLS) |
9996 UDP | $netflowexporter | NTBA | NetFlow channel |
Note
Some of the ports and protocols listed are optional; their use depends on your specific configuration.
Ports used for ePolicy Orchestrator communications
Port | Source | Destination | Comments |
|---|---|---|---|
3306 TCP | ePO | Manager | [Manager to ePO integration] Database connection to enable Maanger-related dashboards in ePO console |
8443 TCP | Manager | ePO | [ePO to Manager integration] Manager pull/query of host information from ePO; requires Trellix IPS extension installation on ePO |
Ports used for Trellix IPS Central Manager communications
Port | Source | Destination | Comments |
|---|---|---|---|
443 TCP | Manager | Central Manager | Uses HTTPS protocol |
443 TCP | Central Manager | Manager | Uses HTTPS protocol |
Ports used for SIEM Enterprise Security Manager (ESM) communications
Port | Source | Destination | Comments |
|---|---|---|---|
443 TCP | ESM | Manager | Access to Manager data |
3306 TCP | ESM | Manager | MariaDB queries |
Ports used for Trellix Intelligent Sandbox communications
Port | Source | Destination | Comments |
|---|---|---|---|
443 TCP | Manager | Intelligent Sandbox | REST API communication |
8505 TCP | Sensor | Intelligent Sandbox | Communication channel for Sensor data |
Ports used for IVX communications
Port | Source | Destination | Comments |
|---|---|---|---|
443 TCP | Manager | IVX/IVX Cloud | IVX REST API communication |
443 TCP | Sensor | IVX/IVX Cloud | IVX REST API communication |
Ports used for Trellix Network Investigator communications
Port | Source | Destination | Comments |
|---|---|---|---|
443 HTTPS | Manager | Network Investigator appliance or cluster | Export alerts to Network Investigator |
443 HTTPS | Sensor | Network Investigator appliance or cluster | Export flow and metadata to Network Investigator |
Ports used for TIE/DXL communications
Port | Source | Destination |
|---|---|---|
443 TCP | Sensor | ePO |
8081 TCP | ePO | Sensor |
8443 TCP | Sensor | ePO |
8883 TCP | Sensor | DXL Broker |
Note
If you have multiple DXL brokers, the Sensor connects to each of them on 8883 TCP. If the DXL broker is deployed on the ePO server, the Sensor connects to the ePO server on 8883 TCP.
Ports used for Trellix Logon Collector communications
Port | Source | Destination | Comments |
|---|---|---|---|
61641 | Manager | TLC Server | JMS communications between the Logon Collector and Manager |
Note
For more information on the ports and traffic destinations used by Trellix IPS, refer to KB59342.