Intelligent Virtual Execution - Server 10.0.1 Release Notes

Prev Next

New features and changes

This section describes new features or enhancements in the Intelligent Virtual Execution - Server 10.0.1 release.

IVX introduces new API:

  • Submit URL request for analysis

Enhances the following existing APIs:

  • Submit malware object for analysis request

  • Submission results request based on format 2.0

New, modified and deprecated CLI commands

New commands

  • New CLI to reset all DTI services credentials

    • fenet dti credentials reset factory-default

      Resets credentials of all the existing DTI services to factory settings.

Resolved issues

The following issues were resolved in the Intelligent Virtual Execution - Server 10.0.1 release.

Tracking number

Summary

COM-31382

Fixes an issue by adding mechanism to clean up outdated triage packages.

COM-31481

Fixes an issue that, by default, upgraded all the Intelligent Virtual Execution - Server appliance applications to the high-security factory default cipher-lists.

VX-1499

The default SSH port on IVX cannot be changed. This issue is resolved.

VX-2558

The timestamp of "show mvx submission uuid <uuid>" did not match the timezone configured on the appliance. This issue is resolved.

Known issues

The following issues are known in the Intelligent Virtual Execution - Server 10.0.1 release.

Tracking number

Summary

VX-2615

Enabling broker role on new or upgraded cluster appliances takes cluster to degraded state. Cluster stabilizes in 10 minutes with autorecovery.

Upgrade support

The Trellix Intelligent Virtual Execution - Server 10.0.1 release requires a reboot for the update to take effect. You can upgrade your IVX appliance to 10.0.1 from release 9.0.0 or later.

Note

You can upgrade Intelligent Virtual Execution - Server appliances to 10.0.1 only if they are standalone nodes. For information on upgrading MVX clusters (MVX Smart Grid), see Upgrading MVX Clusters on the next page.

IPMI and BIOS firmware updates are required for the VX 5500 model. See the section "Upgrading IPMI 3.11 and BIOS 1.9 Firmware for Specific Platforms" below.

Note

After an upgrade to version 10.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Upgrading MVX clusters

Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 10.0.1 is not supported. Follow the procedure in this Community article to upgrade your MVX clusters.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.1.

Downloading content from the DTI offline update portal

If you download Intelligent Virtual Execution - Server 10.0.1 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the

Trellix DTI Offline Update Portal User Guide

.

Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms

The VX 5500 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-21016, COM-25601)

For detailed instructions about upgrading IPMI, see the

System Administration Guide

.

To upgrade IPMI to version 3.11:

Note

IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.

Do not shut down or remove power from the appliance during the upgrade.

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # ipmi firmware update latest

  3. Confirm the upgrade:

    hostname (config) # show ipmi

If the upgrade fails, try the steps again.

If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:

  1. Stop the reload process:

    hostname (config) # reload halt

  2. Disconnect all power cables for 2 minutes.

  3. After 2 minutes, reconnect power cables and restart the appliance.

To upgrade the BIOS to version 1.9:
  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # system bios firmware update latest

    Note

    Do not shut down or remove power from the appliance during the upgrade.

  3. Confirm the upgrade:

    hostname (config) # show system bios

  4. Stop the reload process:

    hostname (config) # reload halt

  5. Disconnect all power cables for 2 minutes.

  6. After 2 minutes, reconnect power cables and restart the appliance.

YARA rules supported versions

Before you upgrade an Intelligent Virtual Execution - Server appliance to the 10.0.1 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.