Central Management System 10.0.2 Release Notes

Prev Next

New features and changes

This section describes new features or enhancements in the Central Management System 10.0.2 release.

  • NX/EX correlation and distributed correlation between CMS peers are permanently disabled in this release.

  • The triage bundle and log archive password is changed to Trellix Customer Support Archive.

New, modified and deprecated CLI commands

Central Management System 10.0.2 deprecated commands.

  • sh datastreaming submission

  • datastreaming submission enable

  • datastreaming submission non-malicious enable

Central Management System 10.0.2 modified commands.

The distributed correlation section is removed from the following CLI output:

  • show cms peer-service

  • show cms peer <peer name>

Resolved issues

The following issues were resolved in the Central Management System 10.0.2 release.

Tracking number

Summary

CMS-16745

Fixes an issue where CMS was incorrectly identified as dvchost instead of the Email Security - Cloud integration.

CMS-17133

Fixes an issue where the current running submission on the Central Management System Web UI Analysis page is not displayed as a child of a completed submission.

CMS-17150

Fixes an issue with CMS cache.

CMS-17181

Fixes an issue on CMS 10.0.1 where clicking the "See here for more info." link in the "Want to improve detection?" notification performs no action.

CMS-17185

Fixes an issue where the Network Security Domain whitelist under the General tab is displayed in CMS appliance settings.

CMS-17200

Fixes an issue where the CVE values are correctly displayed on IPS events main page for IPS events with same signature_iden and signature_rev.

CMS-17206

Fixes an issue where hitting back to IPS events clears date and time filters in IPS event search.

CMS -17212

Fixes an issue where a managed appliance, such as NX, could not reconnect to CMS after a client-initiated connection was interrupted.

CMS-17228

Fixes an issue where the data streaming to the 3rd party Splunk was not working on the Central Management System appliance.

CMS-17243

Fixes an issue where the Central Management System appliance was unable to import CA chain certificate.

CMS-17255

Fixes an issue where the WebUI was unable to load SSL Intercept Whitelist Categories list when the appliance was upgraded v10.0.0.

CMS-17258

Fixes an issue where the dvchost value changes after an upgrade.

CMS-17275

Fixes an issue with Alert Notification when email retry failed.

CMS-17281

Fixes an issue that caused the appliance to reboot while generating log archives in version 10.0.1.

CMS-32363

Fixes an issue where 'Search Emails > Processed Emails' and 'Search Emails > Queued Emails' are not displaying in the CMS 10.0.1 Web UI.

CMS-32387

Fixes an issue where sensor deletion was stuck from the Central Management System.

COM-30655

Fixes the issue of prolonged processing of database backup when alert purge is in progress.

COM-30659

Fixes the issue of missing alert details in the report generated during alert purging.

COM-31551

Fixes an issue with log archives creation.

COM-31673

Java libraries are upgraded to address CVEs.

COM-62147

Fixes an issue where the WebUI email search only recognizes dates and does not honor hours and minutes.

COM-62169

Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx.

COM-62263

Fixes an issue where enabling NTP affects backup, reset, and restore functionality due to restrictions on the timezone changes.

COM-62368

Fixes an issue where adding a root CA was failing in rare cases.

Known issues

The following issues are known in the Central Management System 10.0.2 release.

Tracking number

Summary

CMS-17198

CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases.

CMS-17224

'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab.

CMS-15046

File transfer from managed appliances fails sometimes when the maximum system limit for concurrent transfers is reached.

CMS-15792

The MVX-correlated IPS alerts are not deleted in the Central Management System appliance after the cleanup.

CMS-17093

The alert hyperlink in a quarantined message for riskware doesn't redirect to the corresponding riskware alert.

CMS-17136

ETP alert URLs from notifications redirect to the dashboard page due to an error encountered while redirecting the alert link.

CMS-17207

Email Quarantine does not display percentage values when all EX appliances are selected.

CMS-17218

The WEBUI does not update the user login count if the user logs in using CLI concurrently.

CMS-17220

The success message for 'Advanced Rules' disappears quickly from the UI.

CMS-17221

The drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs.

CMS-32360

The Retroactive Alert badge appears on the Alerts page but is not displayed on the "Malicious Emails" page.

CMS-32390

Inconsistent email counts observed after upgrading to version 10.0.1.

CMS-32410

The 'show guest-images download' CLI incorrectly displays the message "% Error calculating size of partial download." when pushing guest-images to managed EX from the 'Update Sensors' tab.

CMS-32420

Inbound SSL-related changes are not reflected on the CMS, and the SSL configuration through the CMS is broken.

CMS-32481

The '3rd Party Feed' tab displays 'Allowed Lists' and 'Blocked Lists' for managed NX. These two tabs should be disregarded.

CMS-32482

IPS policy sync configurations and sync jobs are not retained after the CMS upgrade; the master policy must be reconfigured post-upgrade.

COM-30655

The database backup process takes a long time when the alert purge is in progress.

Workaround: Schedule the database backup and purge processes at different times.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-30659

Alert details might be missing from the report generated during alert purging.

WEBUI-29843

Users are unable to select the Email Security group on Queued Emails and Processed Emails.

Upgrade support

The Trellix Central Management System 10.0.2 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 10.0.2 from release 9.0.0 or later.

IPMI and BIOS firmware updates are required for the CM 4500 model. See the following section "Upgrading IPMI 3.11 and BIOS 1.9 Firmware for Specific Platforms".

Note

After an upgrade to version 10.0.2, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Upgrading MVX clusters

Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 10.0.2 is not supported. Follow the procedure in this Community article to upgrade your MVX clusters.

Note

To upgrade 9.1.x MVX clusters, you must first upgrade the CMS to version 10.0.2.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.2.

Downloading content from the DTI offline update portal

If you download Central Management 10.0.2 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms

Enabling access to intel context