Changing the active setting for a DTI service

Prev Next

Appliances send requests for DTI services to the following servers:

  • Dynamic Threat Intelligence (DTI)—The Trellix DTI server. The DTI server addresses follow:

    • staticcloud.fireeye.com (Download source and virtual service)

    • up-staticcloud.fireeye.com (Upload destination)

    • mil-staticcloud.fireeye.com (MIL service)

    • unity.fireeye.com (FAUDE and AV-Suite services)

    • Helix full URL (Helix service)

  • Content Delivery Network (CDN)—A content delivery network server. The server address is cloud.fireeye.com or download.fireeye.com.

  • The Central Management System appliance (CMS)—Available only to managed appliances. The address is the Central Management System address.

  • A custom DTI server, if configured—A custom DTI server used only for managed appliances in a Network Address Translation (NAT) deployment in which the appliance uses the non-default dual-port address type to communicate with the Central Management System appliance, and an accessible address needs to be configured for the Central Management System appliance. A custom DTI server is also used in a cache proxy deployment. The address is the accessible Central Management System address. For details, see Configuring and activating an accessible DTI server address .

Each appliance has an active setting and available options for each DTI service. By default, CMS is the active setting for all DTI services on managed appliances. This is the default global setting, which means all appliances that are managed by the Central Management System appliance use this setting. You can change the global setting on the Central Management System appliance, and you can override the global setting for individual managed appliances.

You can also change the active download source setting for standalone appliances and the Central Management System appliance.

Reasons for changing the active setting for a DTI service include:

  • More effective detection and remediation. Trellix recommends a direct connection to unity.fireeye.com to prevent FAUDE and AV-Suite service timeouts and errors.

  • Faster download speed. A CDN server is typically geographically closer to standalone appliances than the Trellix DTI server. The DTI or CDN server could be closer to managed appliances than the Central Management System appliance.

  • Decentralization —You can limit the amount of traffic passing through the Central Management System appliance when requests for one or more DTI services go directly to the DTI network.

  • Security. Your security policies could require you to download the software updates directly from the Trellix DTI server.

  • HTTP proxy. You can use an HTTP proxy as an intermediary between an appliance and the DTI network. In this scenario, managed appliances using the single-port address type must use DTI. Managed appliances using the dual-port address type can use either CMS or DTI. For details, see Using an HTTP proxy for DTI service requests.

  • Network address translation. When the Central Management System appliance is behind a NAT gateway, an accessible IP address that the managed appliances can reach could need to be configured as a custom DTI source. For details, see Configuring and activating an accessible DTI server address .

Prerequisites
  • Admin access.

  • Appliances are in "online" mode and connected to the DTI network, or in "proxy" mode and connected to a Central Management System appliance that is acting as a cache proxy for DTI updates.