Specify Trellix GTI and Sandboxing settings for the server.
In ePO - On-prem, select Menu → Policy → Policy Catalog.
Select Trellix Threat Intelligence Exchange Server Management 4.x.x → TIE Server Settings , then select a policy name or an action.
You can create a policy using My Default as a template, or copy an existing policy and change it as needed.
On the General page, complete these options:
Proxy Settings for Internet — If you use a web proxy for Internet access and it requires authentication, enter the proxy information.
Product Improvement Program — Allow Trellix to collect anonymous data about certificates, file paths, and hashes. This data helps Trellix learn about threats and prioritize what is allowed or blocked.
On the Trellix Global Threat Intelligence tab, enable Trellix GTI to get file reputation.
Trellix GTI is used if the TIE server does not have reputation information for a file, or if the server is unavailable.
On the Sandboxing tab, enable Intelligent Sandbox, Intelligent Virtual Execution (IVX) or IVX Cloud to send file information for further evaluation.
Note
Any TIE server is allowed to submit file samples for sandboxing, as there are no restrictions.
Enter the additional details to enable the sandboxing servers. For more details see, Submitting files to Sandboxing servers in the product Guide.
You can enable certificate validation in the communication between the TIE server and Sandboxing. See KB87692 for details before enabling Enforce Certificate Validation.
On the Skyhigh Secure Web Gateway tab, accept or ignore incoming reports sent to the TIE server about potential web threats.
On the External Reputation Provider tab, enable an external provider for Adaptive Threat Protection to determine whether to accept the reputations.
On the Server Configuration tab, configure the logging level of the server, enable collecting information of DXL traffic, enable or disable collecting metrics and modify the sampling period for collecting performance metrics.
Select Menu → Configuration → Server Settings → Threat Intelligence Exchange Server. The VirusTotal service certificates are validated. If you experience network filtering restrictions, click Edit to disable Skip VirusTotal certificate validations, then click Save.
You can configure the type of files that the TIE server recognizes and processes when accessing the TIE server through Skyhigh Secure Web Gateway and Intelligent Sandbox. You can add or remove file types from the list.