Specify Trellix GTI and Sandboxing settings for the server.
In Trellix ePO - On-prem, select Menu → Policy → Policy Catalog.
Select Trellix Threat Intelligence Exchange Server Management x.x.x → TIE Server Settings , then select a policy name or an action.
You can create a policy using My Default as a template, or copy an existing policy and change it as needed.
On the General page, complete these options:
Proxy Settings for Internet — If you use a web proxy for Internet access and it requires authentication, enter the proxy information.
Product Improvement Program — Allow Trellix to collect anonymous data about certificates, file paths, and hashes. This data helps Trellix learn about threats and prioritize what is allowed or blocked.
On the Trellix Global Threat Intelligence tab, enable Trellix GTI to get file reputation.
Trellix GTI is used if the TIE server does not have reputation information for a file, or if the server is unavailable.
On the Sandboxing tab, enable Intelligent Sandbox or Intelligent Virtual Execution (IVX) to send file information for further evaluation.
In the Intelligent Sandbox or IVX section, enter the server name and access credentials, available servers, timeout settings, polling settings, and the file types.
You can enable certificate validation in the communication between the TIE server and Sandboxing. See KB87692 for details before enabling Enforce Certificate Validation.
On the Skyhigh Secure Web Gateway tab, accept or ignore incoming reports sent to the TIE server about potential web threats.
On the External Reputation Provider tab, enable an external provider for Adaptive Threat Protection to determine whether to accept the reputations.
On the Server Configuration tab, configure the logging level of the server, enable collecting information of Trellix DXL traffic, enable or disable collecting metrics and modify the sampling period for collecting performance metrics.
Select Menu → Configuration → Server Settings → Threat Intelligence Exchange Server. The VirusTotal service certificates are validated. If you experience network filtering restrictions, click Edit to disable Skip VirusTotal certificate validations, then click Save.
You can configure the type of files that the TIE server recognizes and processes when accessing the TIE server through Skyhigh Secure Web Gateway and Intelligent Sandbox. You can add or remove file types from the list.