Reputation source and communication
Application Control works with Trellix GTI to fetch reputation information for files.
Application Control supports reputation-based execution. When you run a file at an endpoint, the software fetches its reputation to determine whether to allow or ban the file execution. The settings configured for your enterprise determine the reputation values that are allowed and banned.
Reputation source
Based on the configuration, the software regularly synchronizes with:
Trellix GTI server – Trellix GTI is a cloud-based service that functions as a reputation source. Application Control periodically synchronizes with the Trellix GTI server to fetch ratings for executable files. The Fetch File Details from Trellix GTI Server task is internal task that run automatically several times a day to fetch Trellix GTI ratings for executable files.
Communication with Trellix GTI
Here is how Application Control communicates with the Trellix GTI server.
Trellix GTI– Application Control communicates directly with the Trellix GTI server. But, if a proxy server is configured in your setup, Application Control uses it to communicate with the Trellix GTI server. The proxy server is configured on the Menu → Configuration → Server Settings → Proxy Settings page.
TACC extension 8.2.6 started supporting TLS Protocol version 1.2 for Trellix GTI. This is done by updating Trellix GTI server URL along with all the underlying Trellix GTI APIs.
Firewall URL and ports needed for GTI communication:
URL | Ports |
|---|---|
tacclinux.rest.gti.trellix.com | 443 |