You can configure controlled live mode by using the appliance Web UI or CLI:
Controlled live mode enables the Email Security - Server appliance to Configuring controlled live mode using the CLI detect malware that requires remote objects. Controlled live mode monitors and manages communication between remote hosts and the suspicious binary under analysis. MVX sends and receives this traffic on the live ether1 or ether2 interface.
To configure controlled live mode, you configure network settings for the live ether1 or ether2 interface and then validate end-to-end connectivity between the live ether1 or ether2 interface and the Internet. If the local network accesses the Internet through a proxy server, you also specify the proxy server access details.
Important
To prevent the exposure of IP addresses and other information about your network, Trellix recommends that you configure the live ether1 or ether2 interface on a different domain from the main network traffic.
Controlled live mode is disabled by default. You enable the feature separately from configuring the feature settings.
Important
Do not enable controlled live mode until you have configured the feature settings and validated end-to-end connectivity between the live ether1 or ether2 interface and the Internet.
Important
If the live ether1 data interface is required, you must configure network settings with the same IP address, mask, default gateway, and name server used for the ether1 management interface.
Important
By default, traffic on the live ether2 interface is not allowed to reach hosts as defined in RFC 1918 or other hosts in the network range of the external IPv4 address for the live ether2 interface. Trellix recommends that you do not disable the analysis live filters so that malware objects cannot reach the local network.
If the name server and the HTTP proxy server for the live ether2 interface reside in a private subnet, use the
no analysis live filter dest-addr private dropcommand and theno analysis live filter dest-addr external-ip dropcommand to prevent the system from dropping packets on the live ether2 interface, and to prevent the packets from reaching the private destination addresses or the external IPv4 destination addresses of the live interface.
Important
If the appliance is deployed in SPAN/TAP mode, you must use ether2 for the live interface.
For more information, see Enabling or disabling controlled live mode.