Before integrating Trellix IVX with other products, you must configure the cluster and enable the broker role on the cluster node. This applies to both single and multiple IVX nodes.
Integrating Trellix IVX with Skyhigh Secure Web Gateway
This integration supports:
SWG version 12.2.0 or later.
IVX version 10.0.x-bona or later.
Trellix recommends you to follow the migration guidelines before integration.
You can perform the following in Skyhigh SWG:
Integrating Trellix IVX with Trellix Threat Intelligence Exchange (TIE)
This integration supports:
Trellix ePO On-prem 5.10.0 (Build 2428) Update 14 and above.
Trellix DXL version 6.0.3.990.5 and above.
Trellix TIE version 4.5.0.
Trellix ENS version 10.7 Update 15 and above.
You can perform the following in Trellix TIE:
Configure Trellix TIE to submit file samples to Trellix IVX.
Verify the status of integration on Trellix ePO.
On Trellix ePO, go to → .
Click on your TIE server. You will see IVX Connection as OK. If TIS is also integrated to the same TIE server, TIS connection is displayed.
Note
When IVX and TIS are integrated with the same TIE Server, files are sent to both sandboxes.
Check the TIE reputation on Trellix ePO where you can see the list of files submitted for analysis and its response from the sandbox.
Integrating Trellix IVX with Intrusion Prevention System (IPS)
IVX multi-broker support is available for the following versions:
Trellix IPS Manager / Central Manager — 11.1.7.71
Trellix NS-series Sensors — 11.1.5.72
Trellix Virtual IPS Sensor — 11.1.7.72
You can perform the following in Trellix IPS:
Configure Trellix IPS to submit file samples to Trellix IVX.
Assign configuration changes to sensor.
On the Devices tab, go to Devices and select the sensor name.
Select the Configuration & Signature Set checkbox.
Click Deploy.

Check the connectivity from the sensor. Login to Sensor CLI and execute the following command:
intruShell@vNSP_65>
show mvx statusMVX engine connection status: Connected MVX engine curl-verbose: Disabled
Check IVX configuration from sensor. Login to Sensor CLI and execute the following command:
intruShell@vNSP_65>
show mvx configVX Configuration: IP Address type: IPv4 Server IPv4: 10.253.220.26 Connection config: ENABLED MVX UserName: admin Certificate validation: DISABLED Authentication Status: Connected Proxy for MVX Communication: DISABLED
View analysis results for the detected malware in Trellix IPS and Trellix IVX.
Check Sensor CLI commands to view information related to IVX migration.
Check the submission on IVX.
show mvx submission
Check the sample result on IVX.
show mvx submission uuid 63af2c19-8fab-4dcd-b3c2-b81859491029
On the Analysis tab, click on the View engine-specific details and download the full analysis report.
