New features
This Trellix Intrusion Prevention System release includes the following new features:
Configuring the NS9600 as a Suricata Sensor
This release of 11.1 introduces the NS9600 Sensor, which you can configure as a high-capacity Suricata Sensor. This Sensor supports high-performance environments and scales to 40,000 Suricata rules while inspecting up to 100 Gbps of network traffic.
You can configure the NS9600 Sensor as:
Standalone Suricata Sensor
Stack Suricata Sensor
Suricata Sensor is a standalone product that uses Suricata engines and does not support Trellix IPS functionality. Distinguish Suricata Sensor from the Trellix IPS Sensor, which provides integrated Suricata support.
NS9600 Sensors that are configured as Suricata Sensors provide a 60 Gbps throughput. It uses the same SKU licenses as the NS9600 Sensor to achieve a throughput of 60 Gbps. Suricata Sensors cannot be configured in a failover pair.
You can configure the Sensor as a Suricata Sensor using set sensor mode <suricata | suricata-stack> command.
For more information, see Configure Sensor information in Trellix Intrusion Prevention System NS9600 Sensor Hardware Guide.
When you are configuring the policies, you must define Sensor behavior using Ruleset and YAML Configuration files. To define Suricata policies, go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration.
For more information, see Configuring policies on NS9600 Suricata Sensor in Trellix Intrusion Prevention System 11.1.x Product Guide.
A list of APIs are also included to support Suricata configuration. For more information, see Suricata Sensor Resource in Trellix Intrusion Prevention System 11.1.x Manager API Reference Guide.
Enhancements
This Trellix Intrusion Prevention System release includes the following enhancements:
Enhanced interface modules support for NS9600 Sensor
Starting with this release of 11.1, the NS9600 Sensor model supports the following interface modules:
In G1, G2, and G3 slots (any combination of the interface modules can be used):
8-port SFP28/SFP+/SFP 25/10/1 Gigabit interface module
4-port QSFP28/QSFP+ 100/40 Gigabit interface module
For more information, see NS-series interface modules supported in NS9600 Sensor in Trellix Intrusion Prevention System NS9600 Sensor Hardware Guide.
Enhanced interface modules support for NS7600 Sensor
Starting with this release of 11.1, the NS7600 Sensor model supports the following interface modules:
In G1 and G2 slots:
8-port SFP28/SFP+/SFP 25/10/1 Gigabit interface module (SR/LR 25G and 10G; SX/LX Fiber and Copper 1G Transceivers)
In G3 slot:
8-port SFP28/SFP+/SFP 25/10/1 Gigabit interface module (only 10G and 1G operation) (SR/LR 10G; SX/LX Fiber and Copper 1G Transceivers)
For more information, see NS-series interface modules supported in NS7600 Sensor in Trellix Intrusion Prevention System NS7600 Sensor Hardware Guide.
Enhanced license support for NS7600 in failover
Starting with this release, the NS7600 Sensor provides a 20 Gbps throughput when configured in failover mode. The license SKUs NS76X20ECE-AT and MSP-NS76FO20-OT allow the Sensor to achieve the required throughput.
For more information, see License requirement for NS7600 Sensors in Trellix Intrusion Prevention System NS7600 Sensor Hardware Guide.
Enhanced STIX threat intelligence feeds with TAXII integration
Starting with this release, Trellix IPS supports automated integration with TAXII servers to continuously retrieve STIX-formatted Indicators of Compromise (IoCs) over HTTPS. This enhancement coexists with the existing manual STIX file upload method.The IPS Manager acts as a TAXII client, using a scheduler-driven pull mechanism to fetch threat indicators from the server's collection endpoints. To optimize performance, the system enforces IoC feed limits based on individual sensor capacity
Configuring threat feeds in Trellix IPS: Perform the following steps to configure and use threat feeds in Trellix IPS.
1. Configure threat feed in the Manager | On the Policy → <Admin Domain Name> → Threat Intelligence → Feed Configuration page:
|
2. Configure Sensor alert logging for threat feeds based on IoC types |
|
For more information, see STIX-based threat intelligence feed support for enhanced protection in Trellix Intrusion Prevention System 11.1.x Product Guide.
Extending IPv6 support in Trellix IPS
With this release of 11.1, IPv6 support has been further extended across Trellix IPS infrastructure and threat intelligence services. This enhancement enables significant management, threat detection, analysis, and administrative capabilities within IPv6 network environments.
Support has been extended to IPv6 URL endpoints for public GTI File Reputation services and public GTI Endpoint/URL Reputation services.
You can now use IPv6 addresses or hostnames when adding broker nodes to an IVX cluster.
The Manager now supports integration with Trellix ePO server using IPv6 server addresses, allowing for successful connection tests and data retrieval in IPv6 environments.
The Manager can now block Firewall policies combining IPv6 rule objects and Geolocation from being pushed to Sensors running versions earlier than 11.1M10.
Trellix IPS and Trellix NI integration support for alert, flow, and metadata
Starting with this release of 11.1, Trellix IPS integrated with Trellix NI supports IPv6 addresses for alert data, metadata, and netflow data for ICMP, UDP, and TCP protocols.
For more information, see Integration with Trellix Network Investigator in Trellix Intrusion Prevention System 11.1.x Integration Guide.
IPS CLI enhancements
The following Sensor CLI commands are included:
Normal Mode
Command | Description |
|---|---|
| This command is used to display the current status for Suricata engines on the Suricata Sensor. |
| This command is used to display the current statistics for Suricata engines on the Suricata Sensor. |
| This command configures bonding between the Management and Response ports. |
| This command clears the current statistics for Suricata engines on the Suricata Sensor. |
| This command is used to display the debug log statistics for Suricata engines on the Suricata Sensor. |
The following Sensor CLI commands are updated:
Normal Mode
Command | Description |
|---|---|
| This CLI command allows you to configure the NS9600 Sensor as a standalone Suricata Sensor or a stacked Suricata Sensor. |
Debug Mode
Command | Description |
|---|---|
| This CLI command is updated to include TCP, ICMP, and UDP IPv4 and IPv6 counters for alert, flow, and metadata. |