About Trellix license keys

Prev Next

License keys are required for system operation. The Network Security appliance requires these license keys:

License key

Description

FIREEYE_APPLIANCE

Required to register your system and use the product features.

CONTENT_UPDATES

Allows your system to access the Dynamic Threat Intelligence (DTI) network, which provides the latest intelligence on advanced cyber attacks and malware callback destinations.

This enables Trellix products to proactively recognize new threats and block attacks.

The two-way sharing license provides your appliance with malware intelligence from the DTI network and shares data about malware analyzed by your appliance.

The one-way sharing license provides your appliance with malware intelligence, but no information is submitted to the DTI cloud.

  • You can use the analysis one-way-override enable command to override the one-way sharing CONTENT_UPDATES license on your appliance and send requests to unity.fireeye.com.

  • By default, FAUDE and Global Cache local intel feeds allow appliances to improve detection without overriding their one-way sharing CONTENT_UPDATES license and without directly accessing FAUDE or the Global Cache. For details and for information about disabling and re-enabling the feeds, see the User Guide for the appliance.

Important

See About support and content license sharing combinations .

Note

When you use a one-way license, locally generated intel is shared across all appliances attached to the Central Management System appliance.

FIREEYE_SUPPORT

Allows your system to receive software image updates and the latest guest images and depending on your sharing option, upload telemetry and statistics to the DTI cloud.

The two-way sharing license allows the appliance to upload telemetry and statistics to the DTI cloud for Trellix to monitor. The one-way sharing license does not upload telemetry and statistics to the DTI cloud.

Important

See About support and content license sharing combinations .

CLOUD_MVX

Allows sensors to submit to the Trellix Cloud MVX or a Private Cloud MVX.

The following licenses are optional:

Note

The functionality provided by optional licenses is disabled if the FIREEYE_APPLIANCE license is invalid.

License key

Description

ATI

Allows your appliance to use Advanced Threat Intelligence features.

Not supported on the Network Security SmartVision product edition.

MD_ACCESS

Allows Trellix products to connect to the Managed Defense VPN. Without this license, Managed Defense cannot manage the server.

AV_ENGINE_SOPHOS

Allows your appliance to use the integrated Sophos Engine to scan submitted malware samples.

DA_HANCOM

Allows your appliance to perform dynamic analysis of Hancom Office files.

If licenses have expired or will expire within 30 days, warnings are displayed on the Appliance License Settings page. For details, see Viewing license notifications using the Web UI.