Trellix Endpoint Security (ENS) for Linux Threat Prevention and Firewall now functions appropriately in SELinux policy confined mode.
SELinux is a kernel security module that allows enforcement of access controls that are loaded at the start of a system. You can use SELinux to confine programs and services as well as access to files, network, IPC, and other processes.
Note
For the ENSL process to be confined after installing the ENSL-Selinux rpm, the Trellix Agent (TA) SELinux RPM must be installed and TA must be running in confined mode.
SELinux RPM provides SELinux policies to confine any service installed by Trellix Endpoint Security (ENS) for Linux. When you install Trellix Endpoint Security (ENS) for Linux along with Trellix Endpoint Security (ENS) for Linux SELinux RPM, the Trellix Endpoint Security (ENS) for Linux processes run in SELinux confinement. When installed, the SELinux modules create contexts for Trellix Endpoint Security (ENS) for Linux processes, binaries, configuration files, log files, etc.