The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

New features

This Trellix Intrusion Prevention System release does not include any new features.

Enhancements

This Trellix Intrusion Prevention System release includes the following enhancements:

Trellix IPS and Trellix NI integration support for alert, flow, and metadata

Starting with this release of 11.1, Trellix IPS integrated with Trellix NI supports IPv6 addresses for alert data, metadata, and netflow data for ICMP, UDP, and TCP protocols.

For more information, see Integration with Trellix Network Investigator in Trellix Intrusion Prevention System 11.1.x Integration Guide.

Enhanced STIX threat intelligence feeds with TAXII integration

Starting with this release, Trellix IPS supports automated integration with TAXII servers to continuously retrieve STIX-formatted Indicators of Compromise (IoCs) over HTTPS. This enhancement coexists with the existing manual STIX file upload method.The IPS Manager acts as a TAXII client, using a scheduler-driven pull mechanism to fetch threat indicators from the server's collection endpoints. To optimize performance, the system enforces IoC feed limits based on individual sensor capacity

Configuring threat feeds in Trellix IPS: Perform the following steps to configure and use threat feeds in Trellix IPS.

1. Configure threat feed in the Manager

On the Policy → <Admin Domain Name> → Threat Intelligence → Feed Configuration page:

  1. Create and import a feed: Create a new feed configuration on the Configure Feed tab:

    • Create a threat feed using file import: Upload the STIX-formatted JSON file containing the IoCs and import the IoC types based on your network requirements.

    • Create an automated threat feed using TAXII server: Configure the TAXII server and schedule the collection of threat feeds to automatically fetch STIX-formatted IoCs based on your network requirements.

  2. Customize the IoC values: Upon saving the threat feed, you can view and exclude one or more imported IoC values for each IoC type from the IoC Values tab. The excluded values appear on the Exclusions tab.

  3. Assign the feed to Sensors: After the configuration of the threat feed, you must assign it to one or more Sensors from the Device Assignments tab.

2. Configure Sensor alert logging for threat feeds based on IoC types

  • IPv4/IPv6 endpoints and CIDRs: Configure a syslog server using the Firewall Access Logging Page in the Manager to log the alert messages.

  • Domains, URLs: Add or update an inspection policy and do the following -

    • Enable Layer 7 Data Collection in the required direction on the Traffic Inspection tab.

    • Enable URL Reputation Analysis from the GTI Reputation Services tab, and assign the policy to the required Sensor(s).

  • File Hash: Create an advanced malware policy, select the required file types for Threat feed / Local Block List malware engine, and assign the policy to the required Sensor(s).

For more information, see STIX-based threat intelligence feed support for enhanced protection in Trellix Intrusion Prevention System 11.1.x Product Guide.

Extending IPv6 support in Trellix IPS

With this release of 11.1, IPv6 support has been further extended across Trellix IPS infrastructure and threat intelligence services. This enhancement enables significant management, threat detection, analysis, and administrative capabilities within IPv6 network environments.

  • Support has been extended to IPv6 URL endpoints for public GTI File Reputation services and public GTI Endpoint/URL Reputation services.

  • You can now use IPv6 addresses or hostnames when adding broker nodes to an IVX cluster.

  • The Manager now supports integration with Trellix ePO server using IPv6 server addresses, allowing for successful connection tests and data retrieval in IPv6 environments.

  • The Manager can now block Firewall policies combining IPv6 rule objects and Geolocation from being pushed to Sensors running versions earlier than 11.1M10.

IPS CLI enhancements

Debug Mode

Command

Description

ninetflowstat

This CLI command is updated to include TCP, ICMP, and UDP IPv4 and IPv6 counters for alert, flow, and metadata.