The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure the TIE server policy

Prev Next

Specify Trellix GTI and Sandboxing settings for the server.

  1. In ePO - On-prem, select MenuPolicyPolicy Catalog.

  2. Select Trellix Threat Intelligence Exchange Server Management 4.x.xTIE Server Settings , then select a policy name or an action.

    You can create a policy using My Default as a template, or copy an existing policy and change it as needed.

  3. On the General page, complete these options:

    • Proxy Settings for Internet — If you use a web proxy for Internet access and it requires authentication, enter the proxy information.

    • TIE IPv6 Mode — Enable this option to use the IPv6 network mode. If you choose this option, ensure your network is compatible with IPv6 networking.

      Important

      You must run the Apply TIESERVER Tags to TIE Servers Server Task after enabling and disabling the TIE IPv6 Mode.

    • Product Improvement Program — Allow Trellix to collect anonymous data about certificates, file paths, and hashes. This data helps Trellix learn about threats and prioritize what is allowed or blocked.

    Note

    When the global IPv6 policy is enabled, communication to Trellix GTI and IVX Cloud occurs over IPv6.

  4. On the Trellix Global Threat Intelligence tab, enable Trellix GTI to get file reputation.

    Trellix GTI is used if the TIE server does not have reputation information for a file, or if the server is unavailable.

  5. On the Sandboxing tab, enable Intelligent Sandbox, Intelligent Virtual Execution (IVX) or IVX Cloud to send file information for further evaluation.

    Note

    Any TIE server is allowed to submit file samples for sandboxing, as there are no restrictions.

    Enter the additional details to enable the sandboxing servers. For more details see, Submitting files to Sandboxing servers in the product Guide.

    You can enable certificate validation in the communication between the TIE server and Sandboxing. See KB87692 for details before enabling Enforce Certificate Validation.

  6. On the Skyhigh Secure Web Gateway tab, accept or ignore incoming reports sent to the TIE server about potential web threats.

  7. On the External Reputation Provider tab, enable an external provider for Adaptive Threat Protection to determine whether to accept the reputations.

  8. On the Server Configuration tab, configure the logging level of the server, enable collecting information of DXL traffic, enable or disable collecting metrics and modify the sampling period for collecting performance metrics.

  9. Select MenuConfigurationServer SettingsThreat Intelligence Exchange Server. The VirusTotal service certificates are validated. If you experience network filtering restrictions, click Edit to disable Skip VirusTotal certificate validations, then click Save.

    You can configure the type of files that the TIE server recognizes and processes when accessing the TIE server through Skyhigh Secure Web Gateway and Intelligent Sandbox. You can add or remove file types from the list.