Integrate Trellix Intelligent Virtual Execution ( IVX )

Prev Next

Before integrating Trellix IVX with other products, you must configure the cluster and enable the broker role on the cluster node. This applies to both single and multiple IVX nodes.

Integrating Trellix IVX with Skyhigh Secure Web Gateway

 

This integration supports:

  • SWG version 12.2.0 or later.

  • IVX version 10.0.x-bona or later.

Trellix recommends you to follow the migration guidelines before integration.

You can perform the following in Skyhigh SWG:

  1. Configure the file size limit for Trellix IVX.

  2. Configure Trellix IVX.

Integrating Trellix IVX with Trellix Threat Intelligence Exchange (TIE)

This integration supports:

  • Trellix ePO On-prem 5.10.0 (Build 2428) Update 14 and above.

  • Trellix DXL version 6.0.3.990.5 and above.

  • Trellix TIE version 4.5.0.

  • Trellix ENS version 10.7 Update 15 and above.

You can perform the following in Trellix TIE:

  1. Configure Trellix TIE to submit file samples to Trellix IVX.

  2. Configure Trellix IVX.

  3. Verify the status of integration on Trellix ePO.

    1. On Trellix ePO, go to Server SettingsTIE Server Topology.

    2. Click on your TIE server. You will see IVX Connection as OK. If TIS is also integrated to the same TIE server, TIS connection is displayed.

      Note

      When IVX and TIS are integrated with the same TIE Server, files are sent to both sandboxes.

  4. Check the TIE reputation on Trellix ePO where you can see the list of files submitted for analysis and its response from the sandbox.

Integrating Trellix IVX with Intrusion Prevention System (IPS)

Before you begin:

You can perform the following in Trellix IPS:

  1. Configure Trellix IPS to submit file samples to Trellix IVX.

    1. Enable VX engine for a sensor.

    2. Configure malware policies for VX scan.

    3. Assign configuration changes to sensor.

      1. On the Devices tab, go to Devices and select the sensor name.

      2. Select the Configuration & Signature Set checkbox.

      3. Click Deploy.

        IPS_manager.png


      4. Check the connectivity from the sensor. Login to Sensor CLI and execute the following command:

        intruShell@vNSP_65> show mvx status

        MVX engine connection status: Connected
        MVX engine curl-verbose: Disabled 
        
      5. Check IVX configuration from sensor. Login to Sensor CLI and execute the following command:

        intruShell@vNSP_65> show mvx config

        VX Configuration:
        IP Address type: IPv4
        Server IPv4: 10.253.220.26
        Connection config: ENABLED
        MVX UserName: admin
        Certificate validation: DISABLED
        Authentication Status: Connected
        Proxy for MVX Communication: DISABLED 
        
  2. View analysis results for the detected malware in Trellix IPS and Trellix IVX.

    1. Check Sensor CLI commands to view information related to IVX migration.

    2. Check the submission on IVX.

      show mvx submission

      commandline1.png


    3. Check the sample result on IVX.

      show mvx submission uuid 63af2c19-8fab-4dcd-b3c2-b81859491029

      cmdline.png
    4. On the Analysis tab, click on the View engine-specific details and download the full analysis report.

      IPA_analysis.png