Network requirements

Prev Next

Connectivity with Trellix's Dynamic Threat Intelligence (DTI) network (one-way or two-way sharing) is required.

HX appliances can download software updates (security content and system images) from the Trellix Dynamic Threat Intelligence (DTI) network. With a two-way content license, the appliance can also upload threat intelligence information to the DTI network. By default, Central Management System-managed appliances receive software updates from the DTI network through the Central Management System appliance.

Standalone Endpoint Security (HX) appliances that receive DTI updates

The Central Management System appliance and standalone (not managed by Central Management System) appliances use the ether1 port to communicate directly with the DTI network. In the default configuration, where you receive updates from the DTI network (cloud.fireeye.com), allow outbound access to all IP addresses on the following ports:

  • DNS (UDP/53)

  • HTTPS (TCP/443)

Management interface ether1 requires a static IP address or reserved DHCP address and subnet mask.

Domain-based proxy ACL rules

If your configuration includes domain-based proxy ACL rules, allow access to *.fireeye.com.

Trellix Endpoint Security (HX) malware definitions

The malware protection provided with Endpoint Security (HX) Series 4.0 and xAgent 26.21 (and later versions) use malware definitions to detect and identify files infected by malware. These malware definitions are downloaded by Trellix's Dynamic Threat Intelligence (DTI) cloud and the Endpoint Security (HX) server from avupdate.fireeye.com. However, if your security policy makes use of a firewall to restrict access to certain IP and web addresses, you need to configure your firewall rules to allow access to avupdate.fireeye.com. The IP addresses associated with avupdate.fireeye.com vary based on your environment. The following are some possible solutions.

  • Use DNS names instead of IP addresses in the firewall rules. The firewall rules will be automatically applied to the correct IP addresses as appropriate for avupdate.fireeye.com.

  • Do a DNS reverse lookup to identify the IP addresses used by avupdate.fireeye.com in your environment and then use those IP addresses in the firewall rules.

  • Use a caching proxy server to obtain the malware definition updates from avupdate.fireeye.com. Be sure your firewall rules allow access to *.fireeye.com.

Note

Trellix Endpoint Security (HX) uses HTTP over port 80 to deliver antivirus (AV) content. This allows you to use a caching proxy to distribute the contents of your download across your endpoints. The manifest for the content is signed with a 2048-bit RSA private key to prevent tampering. If the content is altered, validation of the content on the endpoint agent will fail and the content is discarded.