New features
This Trellix Intrusion Prevention System release includes the following new features:
Trellix Operating System on Manager Appliance
This release of 11.1 introduces the Manager appliance running on the Trellix operating system. The Manager Appliance runs on a pre-installed, hardened Trellix operating system and comes pre-loaded with the Manager software. You can deploy this Linux-based Manager as virtual machines in your ESX, KVM, and Nutanix servers.
The IPS Manager physical appliance now uses refreshed hardware that offers improved storage and performance. This enhancement provides better support for a large volume of alerts.
The Manager appliance uses a 1U rackmount unit, and the size is defined by its standard rack unit height and physical dimensions.
Trellix OS hardware specifications
Parameter | Description |
|---|---|
Regulatory Model Name | SYS-121C-TN10R |
Model | Trellix Intrusion Prevention System Manager |
Device Type | Manager for NS-Series sensors |
Form Factor | 1U |
Dimensions | 23.5 inches (Depth) x 17.2 inches (Width) x 1.7 inches (Height) |
Weight | 11.8 Kg |
Power | 100 - 127VAC / 50-60Hz 200 - 240VAC / 50-60Hz |
Typical Power Consumption | 150W |
Maximum Power Consumption | 300W |
Temperature | Operating Temperature: 10°C to 35°C |
Non-Operating Temperature: -30°C to 60°C | |
CPU | Supports 1X Intel (R) Xenon (R) Silver 4510 2.4 Ghz 12C 1 per system |
Hard Drive | 3.2 TB Enterprise class NVMe drive PCIe Gen4x4 2 per system |
DVD ROM | None |
DIMM | 64 GB DDR5 5600 MHz |
LAN Ports | 2 x 10 Gbe, RJ45 |
USB Ports | 2 x USB 2.0 Type-A ports on front panel and 2 x USB 3.0 ports Type-A ports on back panel |
Video | DB-15 HD VGA on the back panel |
Serial Port | DB9 on the back panel |
For hardware-related information, see Trellix Intrusion Prevention System Manager Appliance Hardware Guide.
Migrating the Manager appliance from 11.1 Update 9 version to 11.1 Update 10 (Trellix OS) version
You must follow the warnings below and perform the mandatory actions before and after migration.
This upgrade migrates MLOS to Trellix OS. It is intended for IPS Manager physical appliances only.
Warning
This is not a regular upgrade. The entire DISK will be FORMATTED, and a fresh Trellix OS will be imaged onto the disk. All data will be lost, including Network configurations, backups, and any local appliance customization or hardening.
MANDATORY ACTIONS BEFORE MIGRATION:
Documentation Review: You must carefully read the mandatory steps under the "Migration Procedures" section in the MLOS to Trellix OS migration document.
The latest available Signature Set must be applied to the MLOS appliance.
Backup: Ensure the "All Table Backup" from MLOS is taken, along with necessary file backups, and moved to an external disk.
Customization: All customization done on this setup must be carefully documented, as they need to be repeated post-migration.
MANDATORY ACTIONS POST MIGRATION:
The "All Table Backup" must be manually restored on the setup.
The list of files specified in the "Migration Procedures" section must be replaced.
Ensure the latest available Signature Set is present in the appliance. Please reach out to the support team if you need assistance.
For more information, see Migrating from 11.1 Update 9 MLOS Manager Appliance to 11.1 Update 10 Trellix OS Manager Appliance in Trellix Intrusion Prevention System Manager Appliance Hardware Guide.
For VM instances deployment, refer to Prepare for 11.1 Update 10 Trellix OS Manager fresh virtual machine instance deployment in Trellix Intrusion Prevention System 11.1.x Installation Guide.
For simplicity of usage and security, with this release, Manager shell commands with the Trellix operating system are introduced. The shell commands allow you to configure and view the Manager configuration and network information. For more information, see Trellix OS Manager Shell Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhanced protection with STIX-based threat intelligence feeds
Starting with this release of 11.1, Trellix IPS enables you to leverage external threat intelligence data from third-party providers to strengthen your network defenses. You can import JSON-based STIX files from third-party providers to Manager and Central Manager and use the included Indicators of Compromise (IoCs) to proactively monitor and block malicious activity on your network.
Trellix IPS supports importing the following IoC types from STIX files - IPv4 and IPv6 endpoints, IPv4 and IPv6 CIDRs, Domains, URLs, and file hashes (MD5 and SHA-256). Sensors use the IoC types to inspect and block the network traffic as per configuration -
IPv4/IPv6 endpoints and CIDRs: Traffic is blocked, and alerts are forwarded to the syslog server configured for firewall access rule logging.
Domains, URLs, and file hashes: Traffic is blocked (per IPS/ Advanced Malware policy), and an alert is generated in the Attack Log.
Configuring threat feeds in Trellix IPS: Perform the following steps to configure and use threat feeds in Trellix IPS.
1. Configure threat feed in the Manager | On the Policy → <Admin Domain Name> → Threat Intelligence → Feed Configuration page:
|
2. Configure Sensor alert logging for threat feeds based on IoC types |
|
For more information, see STIX-based threat intelligence feed support for enhanced protection in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhancements
This Trellix Intrusion Prevention System release includes the following enhancements:
Extending IPv6 support in Trellix IPS
With this release of 11.1, IPv6 support has been extended across Trellix IPS components, such as IPS Manager, Central Manager, IPS Sensors, and their functionalities. This enhancement enables significant management, threat detection, analysis, and administrative capabilities within IPv6 network environments.
You can access IPS Manager and Central Manager web-based user interfaces (UI) via IPv6 addresses. This is applicable to Windows-based Manager and Manager appliance with Trellix operating system.
You can assign IPv6 addresses to IPS Sensors. This is applicable to all NS-series and virtual Sensor models.
IPv6 support has been extended to Managers and Central Managers in MDR pair, and Sensors in stack setup (applicable only to NS9500 and NS9600) and Sensors in fail-over configuration.
You can now configure IPv6 geolocation-based firewall rules. However, when you configure IPv6 firewall rules, you must configure one field (Source Address or Destination Address) as a country, and the other as a country along with any other rule object, such as IPv6 Endpoint or IPv6 Network to ensure IPv6 geolocation-based traffic detection.
Important
Configuration of IPv6 geolocation-based firewall policy in an environment in which you have a Manager with 11.1 Update 10 version and Sensor(s) running on 11.1 Update 9 or lower is not supported. Policies containing IPv6 GeoDB rules must not be applied to these Sensors, as it might result in signature set push failure.
Integration with Trellix Network Investigator is supported in IPv6 environment.
IPv6-compatible features and functionalities in Trellix IPS | |
|---|---|
Inbound and outbound SSL decryption | Database maintenance - backup, pruning, and tuning, alert archival |
Firewall policies | Trellix IPS custom attack definitions and Snort signatures |
Jumbo frame parsing | Inspection policies |
Layer 7 data collection (except SMB and DCERPC) | Malware policies (compatible Malware engines - Threat feed / Local Block List, IVX and PDF) |
IPv6 proxy server configuration | IPv6 email server configuration |
IPv6 Active directory and trusted domain controller configuration | IPv6 TFTP server configuration |
NMS clients | IPv6 SCP server configuration |
Connection limiting policies | CA migration with IPv6 address |
HTTP2 traffic inspection | HTTP POST |
Event logging for public GTI certificate bundle downloads
Starting with this release 11.1, the Manager now logs events when it downloads client certificate bundles for public GTI IP and URL reputation from the Trellix IPS Update Server. You can review these events on the Manager → <Admin Domain Name> → Troubleshooting → Logs → User Activities tab to verify if the download was successful or failed.
For more information, see Configuring Trellix Global Threat Intelligence server for URL and IP Reputation in Manager in Trellix Intrusion Prevention System 11.1.x Product Guide.
Increased default value for alert suppression window
Until the 11.1 Update 10 release, the default value for alert suppression window was 120 seconds. Starting with the 11.1 Update 10 release, the default value is 24 hours. You can configure this value in seconds, minutes, or hours.
This enhancement is not supported for NS7100, NS7200, NS7300, NS9100, NS9200, and NS9300 Sensors.
Terminology updates in the UI
Navigation Path | Prior to 11.1.7.154 | 11.1.7.154 and later |
|---|---|---|
Policy → <Admin Domain Name> → Policy Types → Advanced Malware | Malware engine is named as Allow and Block Lists. | Malware engine is renamed to Threat feed / Local Block List. |
Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions | The option available: Outbound SSL Decryption Exclusions. | The option is renamed to SSL Decryption Exclusions. |
IPS CLI enhancements
The following Sensor CLI commands are included:
Normal Mode
Command | Description |
|---|---|
| This CLI command displays the current configuration settings for alert throttling. |
| This CLI command displays operational statistics for alert throttling, including various counters for resource allocation failures. |
The following Sensor CLI commands are updated:
Normal Mode
Command | Description |
|---|---|
| This CLI command now shows malware statistics of the IOC threat feed engine. |
Debug Mode
Command | Description |
|---|---|
| This CLI command enables users to lookup the geographical location for a specified IPv4 or IPv6 address. It replaces the |
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.14, which includes additional security against new vulnerabilities and bug fixes.
OpenSSH security update
Starting with this release, the OpenSSH package on Sensor is patched to include the fix associated with CVE-2025-32728.