New features and changes
This section describes new features or enhancements in the Central Management System 10.0.2 release.
NX/EX correlation and distributed correlation between CMS peers are permanently disabled in this release.
The triage bundle and log archive password is changed to Trellix Customer Support Archive.
New, modified and deprecated CLI commands
Central Management System 10.0.2 deprecated commands.
sh datastreaming submissiondatastreaming submission enabledatastreaming submission non-malicious enable
Central Management System 10.0.2 modified commands.
The distributed correlation section is removed from the following CLI output:
show cms peer-serviceshow cms peer <peer name>
Resolved issues
The following issues were resolved in the Central Management System 10.0.2 release.
Tracking number | Summary |
|---|---|
CMS-16745 | Fixes an issue where CMS was incorrectly identified as dvchost instead of the Email Security - Cloud integration. |
CMS-17133 | Fixes an issue where the current running submission on the Central Management System Web UI Analysis page is not displayed as a child of a completed submission. |
CMS-17150 | Fixes an issue with CMS cache. |
CMS-17181 | Fixes an issue on CMS 10.0.1 where clicking the "See here for more info." link in the "Want to improve detection?" notification performs no action. |
CMS-17185 | Fixes an issue where the Network Security Domain whitelist under the General tab is displayed in CMS appliance settings. |
CMS-17200 | Fixes an issue where the CVE values are correctly displayed on IPS events main page for IPS events with same |
CMS-17206 | Fixes an issue where hitting back to IPS events clears date and time filters in IPS event search. |
CMS -17212 | Fixes an issue where a managed appliance, such as NX, could not reconnect to CMS after a client-initiated connection was interrupted. |
CMS-17228 | Fixes an issue where the data streaming to the 3rd party Splunk was not working on the Central Management System appliance. |
CMS-17243 | Fixes an issue where the Central Management System appliance was unable to import CA chain certificate. |
CMS-17255 | Fixes an issue where the WebUI was unable to load SSL Intercept Whitelist Categories list when the appliance was upgraded v10.0.0. |
CMS-17258 | Fixes an issue where the dvchost value changes after an upgrade. |
CMS-17275 | Fixes an issue with Alert Notification when email retry failed. |
CMS-17281 | Fixes an issue that caused the appliance to reboot while generating log archives in version 10.0.1. |
CMS-32363 | Fixes an issue where 'Search Emails > Processed Emails' and 'Search Emails > Queued Emails' are not displaying in the CMS 10.0.1 Web UI. |
CMS-32387 | Fixes an issue where sensor deletion was stuck from the Central Management System. |
COM-30655 | Fixes the issue of prolonged processing of database backup when alert purge is in progress. |
COM-30659 | Fixes the issue of missing alert details in the report generated during alert purging. |
COM-31551 | Fixes an issue with log archives creation. |
COM-31673 | Java libraries are upgraded to address CVEs. |
COM-62147 | Fixes an issue where the WebUI email search only recognizes dates and does not honor hours and minutes. |
COM-62169 | Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx. |
COM-62263 | Fixes an issue where enabling NTP affects backup, reset, and restore functionality due to restrictions on the timezone changes. |
COM-62368 | Fixes an issue where adding a root CA was failing in rare cases. |
Known issues
The following issues are known in the Central Management System 10.0.2 release.
Tracking number | Summary |
|---|---|
CMS-17198 | CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases. |
CMS-17224 | 'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab. |
CMS-15046 | File transfer from managed appliances fails sometimes when the maximum system limit for concurrent transfers is reached. |
CMS-15792 | The MVX-correlated IPS alerts are not deleted in the Central Management System appliance after the cleanup. |
CMS-17093 | The alert hyperlink in a quarantined message for riskware doesn't redirect to the corresponding riskware alert. |
CMS-17136 | ETP alert URLs from notifications redirect to the dashboard page due to an error encountered while redirecting the alert link. |
CMS-17207 | Email Quarantine does not display percentage values when all EX appliances are selected. |
CMS-17218 | The WEBUI does not update the user login count if the user logs in using CLI concurrently. |
CMS-17220 | The success message for 'Advanced Rules' disappears quickly from the UI. |
CMS-17221 | The drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs. |
CMS-32360 | The Retroactive Alert badge appears on the Alerts page but is not displayed on the "Malicious Emails" page. |
CMS-32390 | Inconsistent email counts observed after upgrading to version 10.0.1. |
CMS-32410 | The 'show guest-images download' CLI incorrectly displays the message "% Error calculating size of partial download." when pushing guest-images to managed EX from the 'Update Sensors' tab. |
CMS-32420 | Inbound SSL-related changes are not reflected on the CMS, and the SSL configuration through the CMS is broken. |
CMS-32481 | The '3rd Party Feed' tab displays 'Allowed Lists' and 'Blocked Lists' for managed NX. These two tabs should be disregarded. |
CMS-32482 | IPS policy sync configurations and sync jobs are not retained after the CMS upgrade; the master policy must be reconfigured post-upgrade. |
COM-30655 | The database backup process takes a long time when the alert purge is in progress. Workaround: Schedule the database backup and purge processes at different times. |
COM-30656 | Negation symbol '!' is not working before the hostname or the username in deny user list. |
COM-30659 | Alert details might be missing from the report generated during alert purging. |
WEBUI-29843 | Users are unable to select the Email Security group on Queued Emails and Processed Emails. |
Upgrade support
The Trellix Central Management System 10.0.2 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 10.0.2 from release 9.0.0 or later.
IPMI and BIOS firmware updates are required for the CM 4500 model. See the following section "Upgrading IPMI 3.11 and BIOS 1.9 Firmware for Specific Platforms".
Note
After an upgrade to version 10.0.2, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Upgrading MVX clusters
Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 10.0.2 is not supported. Follow the procedure in this Community article to upgrade your MVX clusters.
Note
To upgrade 9.1.x MVX clusters, you must first upgrade the CMS to version 10.0.2.
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.2.
Downloading content from the DTI offline update portal
If you download Central Management 10.0.2 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.