Management path

Prev Next

Email Security - Server appliances can download security content and software updates from the Trellix Dynamic Threat Intelligence (DTI) network. With a two-way content license, the appliance can also upload threat intelligence information to the DTI network.

Standalone Email Security - Server appliances that receive DTI updates

The Central Management System appliance and standalone appliances use the ether1 port to communicate with the DTI network. In the default configuration, where you receive updates from the DTI network (cloud.fireeye.com), allow outbound access to all IP addresses on the following ports:

  • DNS (UDP/53)

  • HTTPS (TCP/443)

Management interface ether1 requires a static IP address or reserved DHCP address and subnet mask.

Environments that restrict outbound access to certain IP addresses

If your security policy requires that you restrict outbound access to certain IP addresses, you cannot use the DTI network. Instead, point to staticcloud.fireeye.com for DTI updates, and allow access to the *incapdns.net domain.

For appliances that get threat intelligence from the DTI cloud, you need to enable access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location.

To configure and access staticcloud.fireeye.com:
  1. Enable CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enter the following command from the appliance CLI:

    hostname (config) # fenet dti source default DTI
  3. Save your configuration.

    hostname (config) # write mem
  4. Add IP addresses to the firewall. See https://fireeyecommunity.force.com/CustomerCommunity/s/article/000001543.

To allow access to *incapdns.net:
  1. Add the block of IP addresses found at https://incapsula.zendesk.com/hc/en-us/articles/200627570-Restricting-direct-access-to-your-website-Incapsula-s-IP-addresses- to the firewall.

  2. Allow access to the *.incapdns.net domain at the proxy device.

To allow access to the AWS cloud for threat intelligence:
  1. Go to https://dnschecker.org/#A/context.fireeye.com to determine the IP addresses for your location.

  2. See the AWS IP address range documentation for information about whitelisting the IP addressses.

Email Security - Server appliances with domain-based proxy ACL rules

If your configuration includes domain-based proxy ACL rules, allow access to *.fireeye.com.

Email Security - Server appliances connected to the Central Management System appliance

For Email Security - Server appliances connected to the Central Management System appliance, use only a static IP address and subnet mask. The appliance should use the ether1 port to communicate with the Central Management System appliance.

Note

Do not use ZeroConf on the primary interface.

To enable IPv6 routing for the management network, use the Configuration Wizard or see the CLI Command Reference for information about the ipv6 enable command, interface ipv6 command, or the configuration jump-start command.

Integrated CM communications protocol and port configurations

Establish SSH connectivity between the Central Management System appliance and each managed Email Security - Server appliance. For details about port and protocol configuration, see the Hardware Administration Guide.