Define interface settings to determine how Trellix ESM connects to each device.
On the system navigation tree, select a device, then click the Properties icon
.Click the device's → option.
Set bypass Network Interface Card (NIC) so that the device passes all traffic, even if it is malicious. Devices in IDS mode do not have bypass capabilities, so their status is Normal Operation.
(Optional) Select to collect flows for traffic sent to and from the device.
If you have ELM SFTP Access user permission, you can view and download Trellix Enterprise Security Manager - Enterprise Log Manager log files stored for the devices. If you have Device Management permission, you can change the port to access these files in the ELM EDS SFTP field.
Note
Use this setting with one of the following FTP clients: WinSCP 5.11, Filezilla, CoreFTP LE, or FireFTP. Do not use these ports: 1, 22, 111, 161, 695, 1333, 1334, 10617, or 13666.
Type IP addresses, owned by your organization (HOME_NET), that determine the direction of the flow traffic that the device collects.
Select the interfaces to be used and enter the IP addresses for the IPv4 or IPv6 type. If you enter an IPv4 address, add the netmask address as well. If you enter an IPv6 address, include the netmask in the address or you receive an error.
To allow the device to be used from multiple networks (limited to MGT 1 <primary interface> and MGT 2 <first drop-down interface> only), add more interfaces.
To activate NIC bonding, select Management in the first field, then type the same IP address and netmask as the main NIC (first line on this dialog box).
Select whether to enable IPv6 mode.
Off — IPv6 mode is not enabled. The IPv6 fields are disabled.
Auto — IPv6 mode is enabled. Each host determines its address from the contents of received user advertisements. It uses the IEEE EUI-64 standard to define the network ID part of the address. The IPv6 fields are disabled.
Manual — IPv6 mode is enabled. The IPv6 fields are enabled.
Select the port through which the system allows access between Trellix ESM and the devices.
Click Setup beside Interfaces and then, make sure that the properties for all interfaces are same.
Note
A Trellix Enterprise Security Manager - Event Receiver (ERC) can host up to six interfaces and the Trellix ESM enables bonding mode option, if at least two of the interfaces have the same IP address.
In the Bonding Mode, enter a value in the range of 0-6.
Note
The ability to change bonding mode is supported only for standalone Receivers. It is not allowed in HA Receivers, RECELMs and the ERC that resides on a Trellix ESM combo box.
Enter the data as requested, then click Apply.
Note
All changes are pushed to the device and take effect immediately. Upon applying changes, the device reinitializes, causing all current sessions to be lost.
Define the advanced network settings for the selected device (fields vary based on the selected device).
Select the ICMP options.
Redirect — If selected, Trellix ESM ignores redirect messages.
Dest Unreachable — If selected, Trellix ESM generates a message when a packet can't be delivered to its destination for reasons other than congestion.
Enable Ping — If selected, Trellix ESM sends an Echo Reply message in response to an Echo Request message sent to an IPv6 multicast/anycast address.
To manage Trellix ESM devices remotely through an IPMI card when an IPMI NIC is plugged into a switch, add the IPMI settings.
Enable IPMI Settings — Select to have access to IPMI commands.
VLAN, IP address, Netmask, Gateway — Enter the settings to configure the network for the IPMI port.