Trellix EDR uses specific network ports to connect to DXL broker, DXL client and Trellix EDR client.
Note
Make sure your network settings are configured correctly and SSL traffic inspection is disabled on URL or IP address.
URL allow list
You must allow access to Trellix EDR URLs.
URL |
|---|
UI URLs:
|
API URLs:
|
Common URLs:
|
Important
For ports and URLs needed for ePO - SaaS communication, see KB90878.
Common paths for ePO - On-premand ePO - SaaS implementations
Source | Destination | Port | Description | URL |
|---|---|---|---|---|
Browsers | Trellix EDR workspace | TCP 443 | Access Trellix EDR interface |
|
Endpoint —Trellix Agent | Enterprise DNS server | TCP/UDP 53 | Resolution of Trellix GTI URLs. |
|
Endpoint — Trellix EDR Agent | Trellix EDR workspace | TCP 443 | Snapshots (default route, and recommended one) | https://api.soc.trellix.com/
|
All components | Enterprise NTP server | TCP 123 | Network time synchronization | |
Administrator workstation | Trellix ePolicy Orchestrator - On-premises | TCP 8443 | Required only during the Trellix EDR service installation to configure Trellix Agent. | |
Administrator workstation | ePO - SaaS | TCP 443 | ||
Endpoint — Phoenix Agent | Trellix EDR workspace | TCP 443 | Snapshot Agent, it detects proxy settings automatically. | https://api.soc.trellix.com/
|
Specific paths - Implementation with ePO - On-prem
Source | Destination | Port | Description | URL |
|---|---|---|---|---|
Endpoint — Trellix Agent | ePO - On-prem | TCP 80 TCP 443 | Policies download, Trellix system logs upload. | |
ePO - On-prem /Endpoint (Trellix Agent) | Endpoint (Trellix Agent) | TCP 8081 | Trellix Agent wake-up call /SADR/Peer-to-Peer/Relay. See Trellix Agent KB66797. | |
ePO - On-prem /Endpoint (Trellix Agent) | Endpoint (Trellix Agent) | UDP 8082 | Super agent/agent update broadcast, Peer-to-Peer server discovery, RelayServer discovery. | |
Endpoint (Trellix Agent) | Endpoint (Trellix Agent) | UDP 8083 | RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open. | |
Endpoint (Trellix Agent) | ePO - On-prem /AH/Repos /Endpoint (Trellix Agent ) SADR | ICMP | Ping or Subnet distance calculation | |
Endpoint (Trellix Agent 5.6 or DXL client) | DXL broker | TCP 8883 | DXL messaging | |
DXL broker | Trellix EDR workspace | TCP 443 | Send information to Trellix EDR workspace:
| https://api.soc.trellix.com/cloudproxy/databus/produce
|
ePO - On-prem | IAM | TCP 443 | Authentication |
|
DXL broker | IAM | TCP 443 | Authentication |
|
Trellix Endpoint | IAM | TCP 443 | Authentication |
|
ePO - On-prem | IAM | TCP 443 | Authentication |
|
ePO - On-prem | Trellix EDR workspace | TCP 443 | Queries and responses used in investigations (examples, queries to ePO - On-prem events and queries to SIEM). As of today, bridge for DXL cloud to on-premises (real-time queries and remediations). This will change in future versions of DXL. Alternate route for Snapshots. | https://api.soc.trellix.com/
|
ePO - On-prem | Endpoint (Trellix EDR client) | Configurable by default 8088 and 8089 | Alternate route for snapshots (not by default, not recommended). | |
DXL broker | ePO - On-prem | TCP 443 | Policies download, Trellix system logs upload. | |
ePO - On-prem | DXL broker | TCP 8081 | Trellix Agent wake-up call. See Trellix Agent KB66797. |
Specific paths — Implementation with ePO - SaaS
Source | Destination | Port | Description | URL |
|---|---|---|---|---|
Endpoint — Trellix Agent | ePO - SaaS | TCP 80 | Policies download, Trellix Agent system logs upload. | POD specific Implementation — ah-<pod>.manage.trellix.com. Only one URL per POD. Currently:
|
Trellix Agent handlers | TCP 443 | |||
ePO - SaaS | Endpoint (Trellix Agent) | TCP 8081 | Trellix Agent wakeup call/ SADR (not supported) /Peer-to-Peer/ Relay. See Trellix Agent KB66797. | |
TCP 8082 | Peer-to-peer server discovery, RelayServer discovery. | |||
TCP 8083 | RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open. | |||
Endpoint — (Trellix Agent 5.6 or DXL client) | ePO - SaaS | TCP 443 | DXL messaging (ICMP is not supported) and real-time search queries. | POD specific implementation — dxl-<pod>.manage.trellix.com. Only one URL per POD. Currently:
|
Endpoint — (Trellix Agent 5.6 or DXL client) | Trellix EDR workspace | TCP 443 | Send information to Trellix EDR workspace:
|