Network ports and URL allow list

Prev Next

Trellix EDR uses specific network ports to connect to DXL broker, DXL client and Trellix EDR client.

Note

Make sure your network settings are configured correctly and SSL traffic inspection is disabled on URL or IP address.

URL allow list

You must allow access to Trellix EDR URLs.

URL

UI URLs:

  • US-West data center — https://ui.soc.trellix.com

  • US-East data center — https://ui.soc.us-east-1.trellix.com

  • Frankfurt data center — https://ui.soc.eu-central-1.trellix.com

  • Canada data center — https://ui.soc.ca-central-1.trellix.com

  • Asia Pacific South data center — https://ui.soc.ap-south-1.trellix.com

API URLs:

  • US-West data center — https://api.soc.trellix.com/cloudproxy/databus/produce

  • US-East data center — https://api.soc.us-east-1.trellix.com/cloudproxy/databus/produce

  • Frankfurt data center — https://api.soc.eu-central-1.trellix.com/cloudproxy/databus/produce

  • Canada data center — https://api.soc.ca-central-1.trellix.com/cloudproxy/databus/produce

  • Asia Pacific South data center — https://api.soc.ap-south-1.trellix.com/cloudproxy/databus/produce

Note

Grant access to the URL for all DXL brokers where trace submission to the cloud is enabled.

Common URLs:

  • https://iam.cloud.trellix.com/iam/v1.0

  • https://iam-rs.cloud.trellix.com/iam-registration-service/v1.1

  • https://uam.api.trellix.com/prod/api/v1

  • https://content.endpoint.ccs-trellix.com

Important

For ports and URLs needed for ePO - SaaS communication, see KB90878.

Common paths for ePO - On-premand ePO - SaaS implementations

Source

Destination

Port

Description

URL

Browsers

Trellix EDR workspace

TCP 443

Access Trellix EDR interface

  • https://ui.soc.trellix.com

    Note

    The URL changes for each tenant data center location. For details, see URL allow list section.

  • https://*.oktacdn.com

  • https://mcafeecloud.okta.com

  • https://auth.ui.trellix.com

  • https://login.auth.ui.trellix.com

Endpoint —Trellix Agent

Enterprise DNS server

TCP/UDP 53

Resolution of Trellix GTI URLs.

  • tie.gti.trellix.com

  • tieserver.rest.gti.trellix.com

Endpoint — Trellix EDR Agent

Trellix EDR workspace

TCP 443

Snapshots (default route, and recommended one)

https://api.soc.trellix.com/

Note

The URL changes for each tenant data center location. For details, see URL allow list section.

All components

Enterprise NTP server

TCP 123

Network time synchronization

Administrator workstation

Trellix ePolicy Orchestrator - On-premises

TCP 8443

Required only during the Trellix EDR service installation to configure Trellix Agent.

Administrator workstation

ePO - SaaS

TCP 443

Endpoint — Phoenix Agent

Trellix EDR workspace

TCP 443

Snapshot Agent, it detects proxy settings automatically.

https://api.soc.trellix.com/

Note

The URL changes for each tenant data center location. For details, see URL allow list section.



Specific paths - Implementation with ePO - On-prem

Source

Destination

Port

Description

URL

Endpoint — Trellix Agent

ePO - On-prem

TCP 80

TCP 443

Policies download, Trellix system logs upload.

ePO - On-prem /Endpoint (Trellix Agent)

Endpoint (Trellix Agent)

TCP 8081

Trellix Agent wake-up call /SADR/Peer-to-Peer/Relay. See Trellix Agent KB66797.

ePO - On-prem /Endpoint (Trellix Agent)

Endpoint (Trellix Agent)

UDP 8082

Super agent/agent update broadcast, Peer-to-Peer server discovery, RelayServer discovery.

Endpoint (Trellix Agent)

Endpoint (Trellix Agent)

UDP 8083

RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open.

Endpoint (Trellix Agent)

ePO - On-prem /AH/Repos /Endpoint (Trellix Agent ) SADR

ICMP

Ping or Subnet distance calculation

Endpoint (Trellix Agent 5.6 or DXL client)

DXL broker

TCP 8883

DXL messaging

DXL broker

Trellix EDR workspace

TCP 443

Send information to Trellix EDR workspace:

  • Trace data from Endpoints /Trellix EDR client.

  • Real-time search responses from Endpoints /Trellix EDR client.

https://api.soc.trellix.com/cloudproxy/databus/produce

Note

The URL changes for each tenant data center location. For details, see URL allow list section.

ePO - On-prem

IAM

TCP 443

Authentication

  • https://iam.cloud.trellix.com

  • https://iam-rs.cloud.trellix.com

  • https://tps.manage.trellix.com/

DXL broker

IAM

TCP 443

Authentication

  • https://iam.cloud.trellix.com

  • https://iam-rs.cloud.trellix.com

Trellix Endpoint

IAM

TCP 443

Authentication

  • https://iam.cloud.trellix.com

  • https://iam-rs.cloud.trellix.com

ePO - On-prem

IAM

TCP 443

Authentication

  • https://iam.cloud.trellix.com

  • https://iam-rs.cloud.trellix.com

ePO - On-prem

Trellix EDR workspace

TCP 443

Queries and responses used in investigations (examples, queries to ePO - On-prem events and queries to SIEM).

As of today, bridge for DXL cloud to on-premises (real-time queries and remediations). This will change in future versions of DXL. Alternate route for Snapshots.

https://api.soc.trellix.com/

Note

The URL changes for each tenant data center location. For details, see URL allow list section.

ePO - On-prem

Endpoint (Trellix EDR client)

Configurable by default 8088 and 8089

Alternate route for snapshots (not by default, not recommended).

DXL broker

ePO - On-prem

TCP 443

Policies download, Trellix system logs upload.

ePO - On-prem

DXL broker

TCP 8081

Trellix Agent wake-up call. See Trellix Agent KB66797.



Specific paths — Implementation with ePO - SaaS

Source

Destination

Port

Description

URL

Endpoint — Trellix Agent

ePO - SaaS

TCP 80

Policies download, Trellix Agent system logs upload.

POD specific Implementation — ah-<pod>.manage.trellix.com. Only one URL per POD.

Currently:

  • ah-usw001.manage.trellix.com

  • ah-usw002.manage.trellix.com

Trellix Agent handlers

TCP 443

ePO - SaaS

Endpoint (Trellix Agent)

TCP 8081

Trellix Agent wakeup call/ SADR (not supported) /Peer-to-Peer/ Relay. See Trellix Agent KB66797.

TCP 8082

Peer-to-peer server discovery, RelayServer discovery.

TCP 8083

RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open.

Endpoint — (Trellix Agent 5.6 or DXL client)

ePO - SaaS

TCP 443

DXL messaging (ICMP is not supported) and real-time search queries.

POD specific implementation — dxl-<pod>.manage.trellix.com. Only one URL per POD.

Currently:

  • dxl-usw001.manage.trellix.com

  • dxl-usw002.manage.trellix.com

Endpoint — (Trellix Agent 5.6 or DXL client)

Trellix EDR workspace

TCP 443

Send information to Trellix EDR workspace:

  • Trace data from Endpoints /Trellix EDR client.

  • Real-time search responses from Endpoints /Trellix EDR client.