Overview

Prev Next

This document is a guide to the Trellix implementation of the Federal Information Processing Standards (FIPS) 140-3 and Common Criteria Network Device Protection Profile (CC-NDcPP) for certain Trellix appliances.

In this document, the term appliance refers to the following suite of Trellix appliances; Central Management System (CMS), Email Security — Server (EX), File Protect (FX), Endpoint Security (HX) , Intelligent Virtual Execution - Server (IVX) and Network Security (NX). To view the latest software release for each appliance refer to their latest Release Notes.

The term compliance refers to the type of compliance standard that you want your appliances to comply with, FIPS 140-3 or CC-NDcPP, or both. Within each standard are two cipher lists, compliant-security and high-security.

Remote and direct access

For instructions on remotely accessing an appliance, see the "Configuring the appliance using the Web UI” and “Configuring the appliance using the CLI” sections in the User Guide for your appliance.

All of the functionality available through the remote command-line interface (CLI) is available through the local console.

LCD configuration is disabled.

Strong passwords

A strong password is at least 15 characters long with the following complexity:

  • At least one uppercase letter

  • At least one lowercase letter

  • At least one number

  • At least one special character

To configure strong passwords, see the “Configuring password validation policies” section in the System Administration Guide for your appliance.

LDAP server configuration

To configure an LDAP server, see the “Configuring an LDAP server” section in the System Administration Guide for your appliance.

Date and time settings

To set the date and time, see the “Setting date and time” section in the System Administration Guide for your appliance.

Timeout settings

To change the timeout and connection timeout settings, use the fenet session timeout command and the fenet connection-timeout command. Verify your changes for both types of timeout settings using the show fenet dti configuration all command. For details about these commands, refer to the CLI Reference.

Login messages

You can customize or remove the messages that appear when users log in to the appliance. You can configure three messages:

  • Remote Banner—Shown on the Web UI and SSH login pages.

  • Local Banner—Shown after the user name is entered in the CLI session.

  • Message of the Day—Shown after the user is authenticated and logged into the appliance CLI.

Refer to the “Customizing login messages” section in the System Administration Guide for your appliance.