D

Prev Next

DTI client

For compliance, HTTPS communication with Trellix Dynamic Threat Intelligence (DTI) servers must use certificate verification, FIPS 140-3 mode TLS 1.0 or better, compliant cipher lists, and “single-port” communication between a Threat Prevention Platform (TPP), such as an EX Series, FX Series, or NX Series platform, and a Central Management System. Single-port communication means that all HTTPS calls between a Central Management System and a managed TPP are tunneled over a FIPS-compliant secure and validated SSH channel, so Central Management System certificate verification is not required. TPPs that communicate with the DTI directly must perform Trellix service certificate verification.

Standards

FIPS 140-3, CC-NDcPP

CLI configuration commands

fenet ssl min-version tls1

fenet ssl cipher-list {fips | fips-high-security | cc-ndpp | cc-ndpp-high-security | fips-and-cc-ndpp | fips-and-cc-ndpp-high-security}

Central Management System proxy server only:

fenet dti proxy check-certificate

fenet dti proxy ssl cert-verify

TPP only:

fenet dti source type CMS address-type cms-singleport

CLI show command

show fenet

DTI HTTP proxy service

For compliance, the HTTP proxy for DTI must be disabled.

Standards

FIPS 140-3, CC-NDcPP

CLI configuration command

no fenet proxy enable

CLI show command

show fenet