New features
This section describes new features in release 11.0.1.
Trellix IVX Private Cloud
Important
Technical Preview: This feature is provided strictly for Technical Preview purposes. It is not GA (Generally Available) and is not ready for production use.
SUPPORT: Trellix welcomes any and all customer feedback regarding this new capability during the Technical Preview. Critical issues may be addressed at Trellix’s discretion; however, Technical Preview features are provided without formal support, maintenance, patches, or bug fixes. Standard support commitments apply only when the feature becomes General Availability.
RISKS: As a Technical Preview, this feature may include defects, security vulnerabilities, or performance issues. It is provided “as-is” during the evaluation period, and Trellix does not provide warranties, guarantees, or commitments regarding its performance or suitability. Customers should evaluate it in non-production environments and are encouraged to share feedback to help guide future improvements.
COMPLIANCE: Trellix IVX Private Cloud is undergoing preparation for formal industry and regulatory compliance certification. These certifications are targeted for the General Availability (GA) release and do not apply to the current Technical Preview version.
The Trellix IVX Private Cloud solution is deployed within your own AWS cloud infrastructure to align with your specific operational and security requirements. Deployment and management are handled using an AWS CDK (Cloud Development Kit) and CodePipeline process. This method allows you to deploy, configure, update, and upgrade the Trellix Cloud IVX solution within your environment, ensuring seamless integration with your existing infrastructure. This gives you control and customization for seamless infrastructure integration.
This solution provides multiple dedicated integration interfaces such as APIs, Amazon S3, and ICAP—to ensure seamless connectivity with your existing systems. These integrations allow automated data exchange and streamline security operations. By automating data exchange with Trellix Cloud IVX, it allows to:
Automate threat analysis
Enhance detection and response workflows
Gain actionable insights to strengthen your overall security posture.
For more information on how to configure and use IVX Private Cloud, see our Deployment Guide.
Virtual IP support for IVX cluster — IVX Server now introduces a Virtual IP to create a High Availability (HA) environment for your cluster. This feature enables automatic failover, which significantly reduces downtime and ensures file analysis continues with no or minimal file loss. If the active broker node fails, another broker automatically takes its place using the same VIP address to continue operations without manual intervention.
Syslog integration for IVX notifications — You can now integrate the IVX appliance with a remote syslog server to automatically forward malicious and riskware notifications when a file analysis is complete. This feature helps SOC teams centralize alerts and streamline threat monitoring within their existing security tools.
Interactive malware analysis with VNC — You can now enable a Virtual Network Computing (VNC) session when submitting a sample through the Web UI to view and interact with it in real-time during analysis in the virtual environment.
The show mvx submission CLI is now updated to show the data for entire cluster.
Enhancements
REQMOD now supports uploading up to 5 files in a single submission request, and the entire request is blocked if any one of the files is found to be malicious.
icap-service block-mode verdict-timeout <seconds> — This command sets the maximum time (in seconds) that the ICAP service will hold a connection while waiting for analysis verdict. The value ranges from 0-300 seconds and the default value is 300.
Setting the value to 0 means the ICAP service immediately releases the connection without waiting for the analysis verdict. It still submits the file for analysis, but the user's connection is not blocked.
IVX Server now allows users to download PDF report for all the completed analysis from Web UI.
In integrated virtual systems, the show version command now displays the maximum number of licensed and configured virtual machines currently running.
Warning message in show version output for Virtual VX — After upgrading a Virtual VX appliance, a new warning message will appear in the output of the show version command. This message is expected and can be safely ignored. The warning displays as follows:
NOTICE: Wrong License: Your FIREEYE_APPLIANCE license is missing the Max Running VMs attribute! Please contact customer support. Maximum running VMs: VMs licensed: n/a (please install an MVX-integrated appliance license) VMs configured: 16The show mvx submission tenant-id <id> CLI command is now deprecated.
Resolved Issues
The following issues were resolved in the 11.0.1 release.
Tracking number | Summary |
|---|---|
COM-63130 | Removed the diffie-hellman-group14-sha1 Key Exchange (KEX) cipher from our supported CC and FIPS cipher lists. |
COM-63634 | Fixes the issue where the /data partition fills up, triggering disk space warnings and potential system failures. |
COM-63528 | Resolved an issue where the AX appliance's management interface (ether1) was incorrectly attempting to establish connections for sandbox analysis. |
COM-63527 | Fixes the issue where the sandbox analysis traffic was incorrectly originating from the management interface (ether1) instead of the designated live interface (ether2). |
VX-3201 | Fixes the issue where live mode submissions were incorrectly labeled as 'sandbox' on the Running page of the UI. |
VX-3251 | Fixes the issue where the IVX UI took an excessive amount of time to load during login, and certain tabs were missing upon logging in. |
VX-3254 | Fixes the issue where the IVX UI was not displaying all generated alerts. |
VX-3256 | Fixes the issue where the IVX UI attempted to reach out to external CDNs and load JavaScript libraries over the network during the login process. |
VX-3258 | Fixes the issue were the file submission was not working for an Analyst user. |
VX-3260 | Fixes the issue where the number of alerts displayed in the UI differs in count when switching between themes. |
VX-3283 | Fixes the issue where the SWG to IVX connection incorrectly displayed an Error 500 for some Secure Web Gateway (SWG) submissions. |
VX-3295 | Fixes the issue where the show mvx submission CLI command, along with other MVX CLI and JSON outputs, incorrectly used the label Sensor ID. This label has been corrected to the more accurate submitter/submitter_name. |
VX-3359 | Fixes the issue where IVX could not process files submitted with non-UTF-8 characters in their name on the ICAP interface. |
VX-3368 | Fixes the issue where the VX appliance incorrectly stopped extracting inner sample files from an archive after 245 files, ignoring the configured 'maximum number of attachments per archive' limit. The appliance now correctly extracts all files up to the set limit, for example, 500. |
VX-3509 | Fixes the issue where users were unable to connect to VNC when using a Fully Qualified Domain Name (FQDN) or hostname. |
Known issues
The following issues are known in the 11.0.1 release.
Tracking number | Summary |
|---|---|
COM-63635 | Compliance mode appliances are logging too much noise with SSL_ERROR_WANT_READ informational status. |
COM-30656 | Negation symbol '!' is not working before the hostname or the username in deny user list. |
VX-3324 | The number of records displayed in the UI appears to shift or not properly counted at the boundary of a user's local time zone. |
VX-3370 | The IVX appliance does not support certificate-based authentication, as the sign-in certificate option is not available. |
VX-3502 | When submitting a sample, the default application option sometimes fails to appear in the selection menu. |
VX-3579 | If the VNC icon is clicked immediately after a file is submitted for analysis, the resulting VNC window may intermittently display a blank white screen. |
Additional information
Upgrade support
The 11.0.1 release requires a reboot for the update to take effect. You can upgrade your appliance to 11.0.1 from release 9.1.x or later.
Note
You can upgrade appliances to 11.0.1 only if they are standalone nodes. For information on upgrading MVX clusters (MVX Smart Grid), see Upgrading MVX Clusters.
Note
After an upgrade to version 11.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the Download the security content bundle section.
Important
When upgrading an X500 running in FIPS/CC compliance mode to version 11.0.1, you must reapply the compliance mode immediately after the upgrade. Use the CLI command
compliance apply standard <standard name>and save the configuration using the CLIwrite memory.After reapplying compliance mode, ensure that any necessary compliance options overrides are reasserted as needed. In rare instances, the appliance may become unresponsive before compliance can be applied. If this occurs, the appliance may need to be power cycled.
Upgrading MVX clusters
IVX clusters running 11.0.0 can be directly upgraded to 11.0.1 using the CMS cluster UI page.
Direct upgrade of MVX clusters (MVX Smart Grid) from 9.1.x or 10.0.x release to 11.0.x is not supported. See the Upgrading IVX Clusters to Version 11.0.x section for more information. For instructions on upgrading the appliance through IVX command line, refer to Upgrading the appliance using the CLI.
Note
You cannot upgrade clusters directly from versions 9.1.x or 10.0.x to 11.0.x. To upgrade, you must first dismantle the cluster and then upgrade each IVX standalone node individually to version 11.0.x.
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.1.
If you download 11.0.1 security content from the DTI Offline Update Portal, use the SCNET-9.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the
Trellix DTI Offline Update Portal User Guide
.
YARA rules supported versions
Before you upgrade an appliance to the 11.0.1 release, modify any custom YARA rules to YARA 4.5.0. For details about YARA 4.5.0, see YARA's Documentation, Release 4.5.0 by Victor Alvarez.