Send link up and down and cold and warm start traps, from Trellix ESM and each device. Retrieve Management Information Base (MIB)-II system and interface tables, and allow discovery of Trellix ESM through an SNMP walk.
Caution
SNMP is intended to check health every 5–15 minutes. More frequent checking can result in lost responses.
SNMPv3 is supported with NoAuthNoPriv, AuthNoPriv, and AuthPriv options, using MD5 or Secure Hash Algorithm (SHA) for authentication and Data Encryption Standard (DES) or Advanced Encryption Standard (AES) for encryption. MD5 and DES are not available in FIPS compliance mode.
SNMP requests can be made to Trellix ESM for Trellix ESM and Trellix Enterprise Security Manager - Event Receiver, health information. SNMPv3 traps can be sent to Trellix ESM to add to the block list of one or more of its managed devices. You can also configure all devices to send link traps and boot traps to destinations of your choosing.
The MIB defines object groups for:
Alerts — Trellix ESM can generate and send alert traps using Event Forwarding. A Trellix Enterprise Security Manager - Event Receiver can receive alert traps by configuring a Trellix SNMP data source.
Flows — A Trellix Enterprise Security Manager - Event Receiver can receive flow traps by configuring an SNMP data source.
Trellix ESM Health Requests —Trellix ESM can receive and respond to health requests for itself and the devices it manages.
Block List — Trellix ESM can receive traps defining entries for block lists and quarantine lists, which it then applies to the devices that it manages.
The Trellix MIB also defines textual conventions (enumerated types) for values including:
The action performed when an alert was received
Flow direction and state
Data source types
Block list actions