New features
This release of Trellix Intrusion Prevention System includes the following new feature:
Integration with Trellix Investigation Analysis
Trellix Investigation Analysis (IA) is a security analytics solution that allows the analysis of alerts and network metadata gathered from all devices connected to it. IA provides a high-level view of the network metadata gathered over customizable dashboards supporting multiple configurations. It thus enables users to have a metadata-based view of network activities and search indexed metadata from various network protocols, which allows them to zero down on threat information critical for performing further investigation.
Starting with this release of 11.1, Trellix IPS offers integration capability with IA appliances or IA cluster, and exports netflow records and Layer 7 metadata from IPS Sensors, and alert data from IPS Manager to IA as per the configuration and filter parameters set on the IA. The alert data, L7 metadata information, and flow records exported by Trellix IPS are displayed on the Dashboard of IA's Web UI which you can review and analyze further for the detection and analysis of network threats.
You need to perform the following steps to enable integration with Trellix IA:
Create Client Profile using the IA Command Line Interface (CLI). During the configuration of the Client Profile, you can setup specific alert severity threshold and enable protocols for L7 metadata information which you want to be exported to IA, as per your requirement.
Note
Currently, IPS Sensors support the export of L7 metadata related to HTTP, HTTPS, SMTP, and FTP protocols only to IA.
Create Client Group on the IA CLI which enables you to assign the required Client Profile to it. A hash token value of 32 bytes is also generated on the completion of Client Group configuration task on the IA CLI, which is used by Trellix IPS for authentication purpose.
Note
You can create up to 20 Client Profiles and 10 Client Groups on an IA appliance based on your requirement.
Configure the required Client Groups created on the IA CLI, which includes adding details such as Client Group name, IP address of the associated IA appliance, and the authentication hash token, in the Manager.
Enable the association of the Client Group configured in the Manager at the domain level or device level.
Note
You can configure multiple Client Groups in the Manager and enable their association per-domain or per-Sensor basis.
The following tabs are available for enabling IA integration in the Manager:
Navigation path | Description | |
|---|---|---|
At Global-level | Devices → <Admin Domain Name> → Global → IPS Device Settings → IA Integration → Client Group Configuration | To configure the Client Group details in the Manager |
Devices → <Admin Domain Name> → Global → IPS Device Settings → IA Integration → Client Group Association | To enable association of any Client Group for the admin domain as well as child domains
| |
At Device-level | Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → IA Integration → Client Group Association | To enable association of any Client Group per Sensor basis within any domain |
Note
You must configure the Client Group details in the Manager to enable its association at the domain or device level. You can configure any Client Group by using the Client Group Configuration tab available at the Global-level, or on the Client Group Association tabs available at both domain and device levels.
Following is the list of Sensor CLI commands that have been added in support of Trellix IA integration:
Debug Mode
Command | Description |
|---|---|
| This command displays IA feature status and communication status between Trellix IPS and Trellix IA, along with other configuration details related to IA integration. |
| This command displays counter specifics related to IA config and metadata export. |
| This command clears all the IA config and metadata statistics-related counters in the Sensor. |
| This command displays internal statistics specifics related to netflow and L7 metadata from datapath side. |
For more information on Trellix IA integration, refer to the section Integration with Trellix Investigation Analysis in Trellix Intrusion Prevention System 11.1.x Integration Guide.
Enhancements
This release of Trellix Intrusion Prevention System includes the following enhancements:
Syslog and SNMP server configuration
Previously, SNMP and Syslog notification profiles were configured separately through the IPS Events, Faults, and User Activity sections. Starting with this release, a Server Configuration page has been added under Manager → <Admin Domain Name> → Setup → Notification in the Manager and Central Manager. This page acts as a standard location to configure the server profiles. These server profiles can be used to configure the Syslog and SNMP notification profiles under IPS Events/Faults/User Activity.
Previously, users were provided with an option to configure Syslog servers for IPS Events and User Activity related notifications via UDP/TCP/TCP over SSL. However, Fault notifications were configured to be communicated only through UDP channel. Starting with this release, users can choose UDP/TCP/TCP over SSL while configuring Syslog server for Fault notifications.
While configuring SNMP notifications, users now have the option to choose SHA256 Authentication Type and AES256 Encryption Type for improved security.
Note
If you are upgrading the Manager to 11.1 Update 2 or later software versions, the Manager automatically lists any existing SNMP and Syslog servers under the respective tabs in this page. The server profile name is automatically assigned by the Manger in this format <Domain Name><event/fault/audit><profile number>. For example, you are upgrading the Manager from 11.1.7.3 to 11.1.7.41. The SNMP servers are configured for the admin domain named IPS-Denver and two child domains named IPS-Welton and IPS-Larimer. IPS-Denver has 3 existing profiles while IPS-Welton and IPS-Larimer have 2 existing profiles.
When you upgrade the Manager to 11.1.7.41 or later versions, this configuration is automatically mapped under the SNMP tab under each domain. User accessing the admin domain named IPS-Denver will be viewing the server profile names as IPS-Denverfault1, IPS-Denverfault2, and IPS-Denverfault3. User accessing the child domain IPS-Welton will be viewing 2 server profiles IPS-Weltonfault1 and IPS-Weltonfault2. Similarly, user accessing the child domain IPS-Larimer will be viewing 2 server profiles IPS-Larimerfault1 and IPS-Larimerfault2.
User accessing one domain will not be able to view the servers created in other domains.
In case user has used the same Syslog or SNMP server for IPS Events, Faults, and User Activity, three server profiles will created under the SNMP and Syslog tabs. Users can opt to delete the duplicate entries and have only one entry assigned to all the profiles. Before deleting the duplicate entries, ensure that the associated servers are not attached to any of the Syslog or SNMP notification profiles.
Note
Before upgrading the Manager to 11.1 Update 2 or later software versions, if user has created a Syslog server (under IPS Events page) at admin domain level and same server is used in child domains, post upgrade, the user sees profiles with the same name at both admin and child domain levels. In this case, if the user plans to remove one of the profiles from any of the domains and tries creating or updating a profile with the old name in the same domain or any other domain, an error is displayed stating the name is already in use.
For more information, refer to the section Configure SNMP and Syslog servers in Trellix Intrusion Prevention System 11.1.x Product Guide.
Signature set version validation during its download or manual import
The signature set's major version (i.e, its first two digits) should be equal to or higher than the IPS Manager's major version (i.e, its first two digits) for it to be compatible with the Manager. Starting with this release of 11.1, the Manager performs validation based on the signature set file's major version being equal to or higher than its major version and prevents the download or manual import of any incompatible signature set version that does not match the validation criteria. For example, any Manager running on version 11.1 Update 2 supports the download and deployment of signature set version 11.9.x.x, but not signature set version 10.8.x.x or 9.8.x.x.
For more information, refer to the section Signature sets in Trellix Intrusion Prevention System 11.1.x Product Guide.
Terminology updates in the UI
This release contains the following terminology updates in the Manager UI:
Option | Prior to 11.1.7.41 | 11.1.7.41 and later |
|---|---|---|
Syslog Server Configuration | To configure a Syslog Server profile under IPS Events, navigate to Manager → <Admin Domain Name> → Setup → Notification → IPS Events → Syslog. Under the Syslog Notification Profiles section, click
| To configure a Syslog Server profile, navigate to Manager → <Admin Domain Name> → Setup → Notification → Server Configuration and click Syslog tab.
Users can use these server profiles to configure the Syslog Notification Profiles under IPS Events/Faults/User Activity. |
To configure a Syslog Server profile under Faults, navigate to Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog. Add or update the server details and click Save. | The Server Configuration page acts as the standard page for configuring the Syslog and SNMP Server profiles. Hence, the terminology updates remain the same as above. | |
To configure a Syslog Server profile under User Activity, navigate to Manager → <Admin Domain Name> → Setup → Notification → User Activity → Syslog. Add or update the server details and click Apply. | The Server Configuration page acts as the standard page for configuring the Syslog and SNMP Server profiles. Hence, the terminology updates remain the same as above. | |
SNMP Server Configuration | To configure SNMP Server profile, navigate to Manager → <Admin Domain Name> → Setup → Notification → IPS Events/Faults/User Activity → SNMP. Under the SNMP Servers section, click
| To configure SNMP Server profile, navigate to Manager → <Admin Domain Name> → Setup → Notification → Server Configuration and click SNMP tab.
Users can use these server profiles to configure the SNMP Notification Profile under IPS Events/Faults/User Activity. |
Import a CSV file containing Domains | To import a CSV file, navigate to Manager → <Admin Domain Name> → Setup → Notification → IPS Events → SNMP, go to Other Actions menu and click Import. | To import a CSV file, navigate to Manager → <Admin Domain Name> → Setup → Notification → IPS Events → SNMP, go to Other Actions menu and click Import Custom. |
IPS CLI enhancements
Along with commands related to Trellix IA integration documented in the What's new section, the following Sensor CLI command is updated:
Debug Mode
Command | Description |
|---|---|
| Displays the datapath attack response related statistics. With this release, it also displays the number of attacks superseded by alert-correlation. |
For more information, see CLI Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.12 that includes additional security against new vulnerabilities.
JDK upgrade
Starting with this release of 11.1, the IPS Manager uses JDK version 8u362 that includes additional security against new vulnerabilities.

.png)
.jpg)