The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

New features

This Trellix Intrusion Prevention System release does not include any new features.

Enhancements

This Trellix Intrusion Prevention System release includes the following enhancements:

Enhanced security measures for proxy-based SSL/TLS decryption

Starting with this release of 11.1, enhanced security measures have been implemented to bolster both inbound and outbound proxy-based SSL/TLS decryption. The new features include the following:

  • IPS-VM5000-SSL, IPS-VM600-SSL, and IPS-VM600-VSS-SSL Sensors are introduced for virtual and cloud deployments.

  • Support for jumbo frame parsing.

  • SSL decryption exclusions apply to both inbound and outbound SSL decryption.

  • Support for 4096-bit RSA and up to 521-bit ECDSA certificates.

Note

  • The re-signing CA certificate must be created for server authentication and added to the browser as a trusted authority without purpose limitations.

  • The "Outbound" Block Flow configuration will apply to "Inbound" and may block inbound flow if an internal web server uses expired/untrusted CA certificates. Thus, an exception rule with the specific internal web server IP should be added to allow inbound flow without decryption when block flow is configured.

  • Once Inbound proxy is enabled, all Inbound traffic will be decrypted; However, it is recommended to create a proxy rule for Inbound SSL decryption.

License requirements for proxy-based SSL decryption

Model

System license

SSL license

Virtual license

IPS-VM5000-SSL, IPS-VM600-SSL, and IPS-VM600-VSS-SSL Sensors

NA

NA

Requires one or more SSL-enabled virtual Sensor licenses (IPS-VM1000-SSL-CLD-SUB) depending on the Sensor or cluster capacity.

Example:

  • IPS-VM600-SSL - 1 unit of license

  • IPS-VM5000-SSL - 5 units of license

For more information, see Managing licenses for proxy based SSL decryption in Trellix Intrusion Prevention System 11.1.x Product Guide

Supported models and platforms

The following table lists the supported models and platforms for the proxy-based inbound and outbound SSL decryption:

Models

Platform

IPS-VM5000-SSL and IPS-VM600-SSL

ESX and KVM

IPS-VM600-VSS-SSL

AWS and Azure

Important

IPS-VM5000-SSL, IPS-VM600-SSL, and IPS-VM600-VSS-SSL Sensors are compatible with signature set version 11.10.28.4 and above.

A new command show ssl proxy is included to support the SSL enhancements.

For more information, see SSL decryption support for NS-series and Virtual IPS Sensors in Trellix Intrusion Prevention System 11.1.x Product Guide

Support for SMB and DCERPC layer 7 data collection and SmartVision attack related L7 metadata and alerts export to Trellix Network Investigator

Starting with this release of 11.1, Trellix IPS supports collecting layer 7 data for SMB (SMBv1 and SMBv2) and DCERPC protocols (over TCP). It also exports the SmartVision attack related L7 metadata related to these protocols from IPS Sensors and alerts from IPS Manager, when the integration between Trellix IPS and Trellix NI is enabled. The SmartVision alerts and L7 metadata collected for SMB and DCERPC protocol traffic and exported to NI further enhances its SmartVision capabilities for detecting malicious activities, such as malware lateral movement, data exfiltration, and beaconing.

Consider the following if you want to enable the detection and export of SmartVision attacks related L7 metadata and alerts related to SMB and DCERPC protocols to NI:

  • You need to use Manager and Sensor(s) running on 11.1 Update 8 and later, along with a compatible signature set (11.10.28.4 and above) that includes SMB and DCERPC related attack signatures.

  • Manager running on 11.1 Update 8 and later includes additional L7 data fields for SMB (under the netbios-ss section) and DCERPC protocols in the Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection page. These L7 fields related to SMB and DCERPC protocols are applicable only for Sensors running on 11.1 Update 8 version or later and can be customized accordingly.

    Note

    DCERPC L7 data collection is supported over TCP only.

  • When Trellix IPS and Trellix NI is integrated, Manager sends all relevant alert data (including SmartVision attacks) to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later send only SmartVision attack-related L7 metadata to NI.

For more information on layer 7 data collection, see Enable Layer 7 Data Collection for an interface or sub-interface in Trellix Intrusion Prevention System 11.1.x Product Guide.

For more information on SmartVision attacks, see Harnessing SmartVision attacks for effective threat detection and response in Trellix Intrusion Prevention System 11.1.x Product Guide.

Configuring and managing packet capture rules for member Sensors in the cloud cluster

Starting with this release of 11.1, you can configure and manage packet capture rules for member Sensors directly from the Devices tab.

  • Configure packet capture: Go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → MemberSensorname-node id → Troubleshooting → Packet Capturing → Capture Now.

  • Manage captured file: Go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → MemberSensorname-node id → Troubleshooting → Packet Capturing → PCAP Files.

You can also view the summary details for a selected member Sensor from the Devices tab. Go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → MemberSensorname-node id → Summary.

For more information, see View member Sensor summary details in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

Database pruning enhancements in the Manager

With this release of 11.1, a few enhancements have been made in the Trellix IPS Manager to speed up and optimize the task of database pruning. From this release onwards, the Manager creates and maintains a separate (active) partition for iv_alert_data, iv_alert, and iv_packetlog tables that stores alert and packet log data based on user configuration (that is, number of days or number of alerts configured). When the alert pruning activity is triggered (as per the configuration performed on Manager → <Admin Domain Name> → Maintenance → database Pruning → Alert Pruning page), all data is deleted at once, thus speeding up the database pruning process.

Support for script files for advanced malware detection

Starting with this release of 11.1, Trellix IPS supports script files to be scanned while configuring an advanced malware policy. It is available for configuration under the File Scanning Options section in the Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware page. To know the list of advanced malware file extensions supported by signature sets, refer to KB96988.

After configuring the advanced malware policy, you need to assign it to the required Sensor monitoring resources such as ports, interfaces, and sub-interfaces. You must do a configuration and signature set update for any changes in the policy to take effect.

For more information, see Add an Advanced Malware policy in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements around SSL key push failure in the Manager

Previously, the reason for SSL key push failure was undetermined. With this release of 11.1, a thorough analysis revealed that the failures were due to missing or corrupted certificates. Additionally, SSL key push would fail when a new shared secret key was issued. This enhancement provides a clear resolution in the Manager, displaying the reason for the SSL key push failure.

For more information, see Deploy pending changes to a device in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhanced support for latency troubleshooting

With this release of 11.1, Trellix IPS introduces a significant improvement to latency troubleshooting, providing a streamlined solution for diagnosing performance-related issues. It addresses common latency-related problems such as slow application response, packet drops, network slowdowns, and delayed file transfers/database operations.

You can use the latency-troubleshooting command to add, delete, list the configured commands, modify the frequency of execution, and collect logs from the trace in debug mode.

The following commands are available:

Parameter

Syntax

Description

start

latency-troubleshooting start

Start latency troubleshooting

status

latency-troubleshooting status

Check the current status of latency troubleshooting

stop

latency-troubleshooting stop

Stop latency troubleshooting

command

add

latency-troubleshooting command add <"idscli+COMMAND">

Add a command to the list

delete

latency-troubleshooting command delete <"idscli+INDEX">

Delete a command from the list

list

latency-troubleshooting command list

Lists all added commands

run

latency-troubleshooting run

Run latency troubleshooting once

set

frequency

latency-troubleshooting set frequency <number>

Modify the frequency of run

rollover_limit

latency-troubleshooting set rollover_limit <number>

Sets the number of logs to retain

For more information, see latency-troubleshooting in Trellix Intrusion Prevention System 11.1.x Product Guide

Terminology updates in the UI

Navigation Path

Prior to 11.1.7.121

11.1.7.121 and later

Devices → <Admin Domain Name> → Manager Management

The Synchronize Policies menu Policy tab shows the synchronization status for all the Managers added to your Central Manager.

The Policy tab from Devices → <Admin Domain Name> → Manager Management → Synchronization shows the synchronization status for all the Managers added to your Central Manager.

Devices → <Admin Domain Name> → Manager Management

The Synchronize Faults menu from Devices → <Admin Domain Name> → Manager Management → Synchronize Faults allows automatic synchronization of faults between the Managers and the Central Manager.

The Faults tab from Devices → <Admin Domain Name> → Manager Management → Synchronization allows automatic synchronization of faults between the Managers and the Central Manager.

Manager → <Admin Domain Name> → Users and Roles → Roles

On clicking plusicon.png icon to create a new role:

  1. Add a custom role page is displayed.

  2. Privileges field has two sections - Available and Assigned. You can use 11_1old-Arrow1.png or 11_1old-Arrow2.png icon to assign or unassign privileges for the role.

On clicking plusicon.png icon to create a new role:

  1. Role Details panel is displayed on the right side of the page.

  2. Privileges field includes a list of all privileges with checkboxes. You need to select the required checkbox(es) to select privilege(s) for the role.

Manager → <Admin Domain Name> → Setup → Central Manager

  1. All configurable fields come under the Central Manager section of the page.

  2. Click Finish to save the changes; or click Refresh.

  1. The Central Manager section includes the Status field and rest of the fields are available under Define Trust section of the page.

  2. Click Configure to save the changes.

Manager → <Admin Domain Name> → Setup → Proxy Server

One of the fields available is User Name.

The field is renamed to Login Name.

Manager → <Admin Domain Name> → Reporting → Preferences

The Preferences page includes the following:

  1. 3 sub pages - Header and Footer, Language, and Output Limits.

  2. While editing, in the Header for generated reports section of the Header and Footer page:

    1. Click the Edit Logo button that allows you to choose between Text, Image, and Trellix Logo (Default) for the right header section of the report.

    2. The right header section comes with a drop-down with [None] and Text.

The Preferences page includes the following:

  1. 3 tabs: Header & Footer, Language, and Output Limits.

  2. While editing, in the Header for generated reports section of Header & Footer tab of the Preferences page:

    1. You can directly choose between Text, Image, and Trellix Logo (Default) for the right header section of the report.

    2. The right header section comes with Header Right Detail field with a textbox to enter text.

Manager → <Admin Domain Name> → Reporting → Configuration Reports

During the configuration of any report:

  1. Configuration options of any report selected are displayed on the top of the page.

  2. Report output option is named as Output Format.

  3. When the report is configured, click Submit to generate the report.

  4. Click Previous-back.png to close the configuration options and come back to the reports page.

During the configuration of any report:

  1. Configuration options of any report selected are displayed in a window at the right side of the page.

  2. Report output option is renamed to Report Format.

  3. When the report is configured, click Run to generate the report.

  4. Click 11_1M8-closeicon.png to close configuration options window of a specific report.

Manager → <Admin Domain Name> → Integration → TLC

  1. Export to file link and Open TLC Console button is available in the Export Certificate section of the page.

  2. Import Certificate section includes New TLC Certificate, Current TLC Certificate, and Upload TLC Certificate fields.

  1. Export and Open TLC Console buttons are displayed on the lower left side of the page.

  2. New TLC Certificate, Current TLC Certificate, and Upload TLC Certificate fields appear in the page without any section header.

Manager → <Admin Domain Name> → Integration → HP Network Automation

A note regarding customized message appears in the Message Preference field.

A tooltip regarding customized message appears in the Message Preference field.

Apart from the terminology updates mentioned above, this release of Manager (11.1.7.121 and later) displays the following changes:

  1. The following pages have been removed, and consequently, all associated UI configuration options, buttons, and related dashboards have been removed from the other pages in the Manager:

    1. Network Forensics page (in Analysis → Network Forensics)

    2. Endpoint Executables page (in Analysis → Endpoint Executables)

    3. NTBA Quarantine Events page (in Manager → <Admin Domain Name> → Setup → Notification)

    4. Related dashboards that have been removed: Top Applications (NTBA), Top Destinations (NTBA), Top Endpoint Executables (NTBA), Top Files (NTBA), Top Sources (NTBA), and Top URLs (NTBA).

  2. The Reconnaissance Policy configuration report has been removed from Manager → <Admin Domain Name> → Reporting → Configuration Reports page.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

Apache Solr upgrade

Starting with this release, the IPS Manager uses Apache Solr version 8.11.4 that includes additional security against new vulnerabilities and bug fixes.

JDK upgrade

Starting with this release of 11.1, the IPS Manager uses JDK version 1.8u432-b06 which includes additional security against new vulnerabilities.

Apache Tomcat server upgrade

Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.102. This server update provides a collection of security fixes.