This document is a guide to the Trellix implementation of the Federal Information Processing Standards (FIPS) 140-3 and Common Criteria Network Device Protection Profile (CC-NDcPP) for certain Trellix appliances.
In this document, the term appliance refers to the following suite of Trellix appliances; Central Management System (CMS), Email Security — Server (EX), File Protect (FX), Endpoint Security (HX) , Intelligent Virtual Execution - Server (IVX) and Network Security (NX). To view the latest software release for each appliance refer to their latest Release Notes.
The term compliance refers to the type of compliance standard that you want your appliances to comply with, FIPS 140-3 or CC-NDcPP, or both. Within each standard are two cipher lists, compliant-security and high-security.
Remote and direct access
For instructions on remotely accessing an appliance, see the "Configuring the appliance using the Web UI” and “Configuring the appliance using the CLI” sections in the User Guide for your appliance.
All of the functionality available through the remote command-line interface (CLI) is available through the local console.
LCD configuration is disabled.
Strong passwords
A strong password is at least 15 characters long with the following complexity:
At least one uppercase letter
At least one lowercase letter
At least one number
At least one special character
To configure strong passwords, see the “Configuring password validation policies” section in the System Administration Guide for your appliance.
LDAP server configuration
To configure an LDAP server, see the “Configuring an LDAP server” section in the System Administration Guide for your appliance.
Date and time settings
To set the date and time, see the “Setting date and time” section in the System Administration Guide for your appliance.
Timeout settings
To change the timeout and connection timeout settings, use the fenet session timeout command and the fenet connection-timeout command. Verify your changes for both types of timeout settings using the show fenet dti configuration all command. For details about these commands, refer to the CLI Reference.
Login messages
You can customize or remove the messages that appear when users log in to the appliance. You can configure three messages:
Remote Banner—Shown on the Web UI and SSH login pages.
Local Banner—Shown after the user name is entered in the CLI session.
Message of the Day—Shown after the user is authenticated and logged into the appliance CLI.
Refer to the “Customizing login messages” section in the System Administration Guide for your appliance.