New features
This Trellix Intrusion Prevention System release includes the following new features:
New performance monitoring capabilities
With the 11.1 Update 9 release, you can now monitor the Packets usage and Inspection Time from Performance Charts. You can access them through Device → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Performance Charts. This functionality is supported on IPS-VM600, IPS-VM600-SSL, IPS-VM5000, and IPS-VM5000-SSL Sensors.
Packets tab details:
You can view the number of packets transferred within a specified time frame. By default, the system displays device-level packet data. To access port-specific data, select Port from the available drop-down menu.
You can customize your view of network packets by selecting or deselecting any of the five available size ranges: Total, 0-64, 65-127, 128-255, and 256-511. By default, all ranges are displayed. For any chosen interface, the system displays the number of packets in the format: <Device Name>, <Number> packets of <packet size range>, and time in MMM DD HH:MM:SS YYYY.
Inspection Time tab details:
You can monitor the total inspection time, along with the inspection time contributed by each of the top 5 contributors. By default, the system does not display the top five contributors to this delay. To enable the visibility of these top five contributors, select the Top 5 Contributors checkbox.
For any chosen interface, the system displays the inspection time in the format: <Device Name>, <time in microseconds> Inspection Time <contributor details>, and time in MMM DD HH:MM:SS YYYY.
For more information, see Performance metrics in Trellix Intrusion Prevention System 11.1.x Product Guide.
OpenID Connect (OIDC)-based Identity Provider (IdP) authentication in the Manager
Starting with this release, the Manager supports user authentication through an OpenID Connect (OIDC)-based Identity Provider (IdP) to enhance security and streamline the user login experience with Single Sign-On (SSO) capabilities. This allows users to log in to the Manager with their IdP credentials, including Multi-Factor Authentication (MFA) if enabled. Supported IdPs are Okta, Microsoft Entra, and Google IdP.
Before configuring IdP authentication in the Manager, ensure the following requirements are met:
The Manager client application must be registered with the IdP. This process provides the necessary Client ID and Client Secret keys required for the IdP server configuration in the Manager.
Note
You need to have access to IdP with required privileges to register the IPS Manager client application. Or else, contact your IdP system administrator and request for the registration.
Users must have an active account with the required IdP and be assigned appropriate user profile and user policy by their IdP system administrator so that they can access the Manager using IdP credentials.
A proxy server must be configured in the Manager for internet access.
Enabling IdP authentication is a two-step process:
Configure IdP Server(s) in Manager using the Manager → <Admin Domain Name> → Setup → GUI Access → IdP Authentication page.
Add a user with ODIC as Authentication Type, specifying their IdP User Name, email address (which must match the one configured in IdP), and assigning them a role (barring No Role)
If Allow IdP access only? option is enabled during the IdP server configuration, users are directly authenticated by the configured IdP on accessing the Manager. Otherwise, they can choose between the local Manager login and IdP-based login. For more information, refer to Leveraging OIDC for IdP Authentication in the Manager in Trellix Intrusion Prevention System 11.1.x Product Guide.
New alert and audit notifications in syslog messages
From this 11.1 release, a new token $IV_MANAGER_DETAILS$ is introduced to display the hostname and IP addresses of the Manager. You can access it from Manager → <Admin Domain Name> → Setup → Notification → IPS Events → Syslog and Manager → <Admin Domain Name> → Setup → Notification → User Activity → Syslog. For an MDR setup, it further specifies if the Manager is "primary" or "secondary".
For more information, see Add a Syslog notification profile to forward alerts and Forward audit information to Syslog Server in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhancements
This Trellix Intrusion Prevention System release includes the following enhancements:
Enhanced throughput monitoring capabilities
Starting with this 11.1 release, the unit used for plotting the device throughput charts is Mbps. This functionality is supported on IPS-VM600, IPS-VM600-SSL, IPS-VM5000, and IPS-VM5000-SSL Sensors. The Maximum, Average, or Minimum summarized data are replaced with the Average and Peak throughput usage at both device and port levels. The data update frequency has improved from every 3 minutes to every 30 seconds.
For more information, see Performance metrics in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhanced SNMP scalability
From this 11.1 release, while adding NMS users and IP addresses from Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Remote Access → NMS, you can add a maximum of 50 users, IPv4, and IPv6 addresses.
For more information, see Management of NMS users in Trellix Intrusion Prevention System 11.1.x Installation Guide.
Enhanced fault notifications in syslog messages
From this 11.1 release, $IV_DEVICE_NAME$ will also display the hostname and IP addresses of the Manager. You can access it from Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog. For an MDR setup, it further specifies if the Manager is "primary" or "secondary".
For more information, see Forward faults to a Syslog server in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhanced security for User Accounts
Starting with the 11.1 Update 9 release, all information displayed in the user details panel is encrypted. This signifies that sensitive user data, including personal information and account credentials, is now protected through encryption, thereby strengthening user privacy and overall security.
For more information, see How to view user account information in Trellix Intrusion Prevention System 11.1.x Product Guide.
Terminology updates in the UI
Navigation Path | Prior to 11.1.7.136 | 11.1.7.136 and later |
|---|---|---|
At domain level: Devices → <Admin Domain Name> → Global → IPS Device Settings → IVX Integration → Enable IVX Integration → Enable IVX Cloud At device level: Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → IVX Integration → Enable IVX Integration → Enable IVX Cloud | The hostname for IVX Cloud service is preconfigured and is not editable. | You can enter the hostname for IVX Cloud service manually. |
Manager → <Admin Domain Name> → Integration → GTI | Go to Endpoint/URL Reputation and view Public GTI Endpoint/URL Reputation Queries, the link is displayed as https://nsp.repl.gti.trellix.com. | Go to Endpoint/URL Reputation and view Public GTI Endpoint/URL Reputation Queries, the link is displayed as https://ips.repm.gti.trellix.com. |
IPS CLI enhancements
The following Sensor CLI commands are updated:
Debug Mode
Command | Description |
|---|---|
| Several counters have been added to identify specific errors and statistics related to exporting data to the Trellix Network Investigator (NI), such as the following:
|
| Some of the counters that have been added are the following:
|
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.11, which includes additional security against new vulnerabilities and bug fixes.
Apache Tomcat server upgrade
With this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.104. This server update provides a collection of security fixes.