(This topic applies to Trellix DLP - SaaS.) Before deploying Trellix DLP Discover – SaaS software, you must configure the network, define administrators, and deploy the needed software.
Task
-
Configure any intermediary firewalls or policy-enforcing devices to allow the specified ports for network communication.
All listed protocols use TCP only, unless noted otherwise. For information about ports that communicate with Trellix ePO - SaaS, see KB66797.
Trellix DLP Discover – SaaS default ports Port, protocol Use - 137, 138, 139 — NetBIOS
- 445 — SMB
CIFS scans 80, 443 — HTTP and HTTPS Trellix ePO - SaaS server communication and evidence copy operations
53 — DNS (UDP) DNS queries - 1801 — TCP
- 135, 2101*, 2103*, 2105 — RPC
- 1801, 3527 — UDP
For more information, see Microsoft KB article 178517.
Note
MSMQ uses these ports only for internal communication. Nothing needs to be opened on the network firewall, but the local or host firewall needs to allow these communications.
Microsoft Message Queuing (MSMQ) - Create users and roles for administrative assignments.