Email Security - Server appliances can download security content and software updates from the Trellix Dynamic Threat Intelligence (DTI) network. With a two-way content license, the appliance can also upload threat intelligence information to the DTI network.
Standalone Email Security - Server appliances that receive DTI updates
The Central Management System appliance and standalone appliances use the ether1 port to communicate with the DTI network. In the default configuration, where you receive updates from the DTI network (cloud.fireeye.com), allow outbound access to all IP addresses on the following ports:
DNS (UDP/53)
HTTPS (TCP/443)
Management interface ether1 requires a static IP address or reserved DHCP address and subnet mask.
Environments that restrict outbound access to certain IP addresses
If your security policy requires that you restrict outbound access to certain IP addresses, you cannot use the DTI network. Instead, point to staticcloud.fireeye.com for DTI updates, and allow access to the *incapdns.net domain.
For appliances that get threat intelligence from the DTI cloud, you need to enable access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location.
Enable CLI configuration mode.
hostname > enable hostname # configure terminal
Enter the following command from the appliance CLI:
hostname (config) # fenet dti source default DTI
Save your configuration.
hostname (config) # write mem
Add IP addresses to the firewall. See https://fireeyecommunity.force.com/CustomerCommunity/s/article/000001543.
Add the block of IP addresses found at https://incapsula.zendesk.com/hc/en-us/articles/200627570-Restricting-direct-access-to-your-website-Incapsula-s-IP-addresses- to the firewall.
Allow access to the *.incapdns.net domain at the proxy device.
Go to https://dnschecker.org/#A/context.fireeye.com to determine the IP addresses for your location.
See the AWS IP address range documentation for information about whitelisting the IP addressses.
Email Security - Server appliances with domain-based proxy ACL rules
If your configuration includes domain-based proxy ACL rules, allow access to *.fireeye.com.
Email Security - Server appliances connected to the Central Management System appliance
For Email Security - Server appliances connected to the Central Management System appliance, use only a static IP address and subnet mask. The appliance should use the ether1 port to communicate with the Central Management System appliance.
Note
Do not use ZeroConf on the primary interface.
To enable IPv6 routing for the management network, use the Configuration Wizard or see the CLI Command Reference for information about the ipv6 enable command, interface ipv6 command, or the configuration jump-start command.
Integrated CM communications protocol and port configurations
Establish SSH connectivity between the Central Management System appliance and each managed Email Security - Server appliance. For details about port and protocol configuration, see the Hardware Administration Guide.