DTI client
For compliance, HTTPS communication with Trellix Dynamic Threat Intelligence (DTI) servers must use certificate verification, FIPS 140-3 mode TLS 1.0 or better, compliant cipher lists, and “single-port” communication between a Threat Prevention Platform (TPP), such as an EX Series, FX Series, or NX Series platform, and a Central Management System. Single-port communication means that all HTTPS calls between a Central Management System and a managed TPP are tunneled over a FIPS-compliant secure and validated SSH channel, so Central Management System certificate verification is not required. TPPs that communicate with the DTI directly must perform Trellix service certificate verification.
Standards
FIPS 140-3, CC-NDcPP
CLI configuration commands
fenet ssl min-version tls1
fenet ssl cipher-list {fips | fips-high-security | cc-ndpp | cc-ndpp-high-security | fips-and-cc-ndpp | fips-and-cc-ndpp-high-security}
Central Management System proxy server only:
fenet dti proxy check-certificate
fenet dti proxy ssl cert-verify
TPP only:
fenet dti source type CMS address-type cms-singleport
CLI show command
show fenet
DTI HTTP proxy service
For compliance, the HTTP proxy for DTI must be disabled.
Standards
FIPS 140-3, CC-NDcPP
CLI configuration command
no fenet proxy enable
CLI show command
show fenet