Limitations

Prev Next

This topic covers the following information:

Limitations on all SmartVision appliances

The following limitations apply to SmartVision appliances, SmartVision-enabled Network Security sensors, and SmartVision-enabled integrated appliances

  • DHCP ― DHCP is not supported on the submission interface unless the management interface is ether1. Sensors communicate with the cloud broker and with each other through the submission interface using SSH over SSL (port 443). The default submission interface is ether1.

  • Jumbo frames ― Jumbo frames are not supported on SmartVision appliances.

  • High availability ― SmartVision is not supported on Network Security appliances that are configured as a high-availability pair.

  • Data exfiltration ― Data exfiltration is not supported for IPv6 traffic.

  • SmartVision alert notifications ― Distribution of SmartVision alerts using Trellix event notification methods (syslog messages, SMTP email, SNMP traps, and HTTP posts to Web servers) is disabled by default and must be explicitly enabled. See Configuring network event notifications.

  • Reports ― SmartVision Alert reports are available in PDF format only, and they can be generated, scheduled, downloaded, or deleted using the Web UI only.

  • SMB protocols ― SmartVision analyzes files transferred over SMB v1 and v2 protocols only.

  • Malware Object events ― If a SmartVision appliance detects malware binaries, it generates a Malware Object alert. Malware Object alerts are listed in the Hosts list and Alerts list. To download the MVX analysis record for a malicious binary, expand the entry in the Host Details page and click Download malware binary.

    Note

    Because SmartVision appliances analyze SMB traffic only, the protocol header field (proto_hdr) in the MVX analysis record is empty. The corresponding protocol header field (Proto Header) in the Web UI is empty also.

  • Average EPS ― Before you deploy a Classic edition appliance to a production environment, make sure that the average events per second (EPS) measured on the appliance does not exceed the recommended maximum EPS.

    See Average EPS and recommended maximum EPS and Checking the average EPS using the CLI.

    Important

    If the average EPS measured on your Classic edition appliance exceeds the recommended maximum EPS for that model, the appliance may fail to detect some post-exploitation attacker activities. Contact Trellix Technical Support.

Limitations regarding IPv6 and cloud MVX

In a cloud MVX deployment, IPv6 is not supported on the management or submission interface of the following appliance types:

  • SmartVision Edition sensors, available in the following models:

    • NX 2500 operating as a sensor

    • NX 5500 operating as a sensor

    • NX 6500 operating as a sensor

    • NX 2550V

    • NX 6500V

  • SmartVision-enabled Network Security hardware appliances operating as sensors

  • SmartVision-enabled Network Security virtual appliances

Limitations specific to SmartVision edition appliances

The following limitations apply to SmartVision edition appliances:

  • TAP mode ― SmartVision edition appliances must be deployed out-of-band using a TAP device, and TAP operational mode is enforced by the product edition license. The FIREEYE_APPLIANCE license details for the Edition appliance specify Op Mode: tap (ok).

    SmartVision is supported on Classic Edition appliances deployed in any operational mode.

  • Custom rules ― Custom rules files cannot be uploaded to SmartVision Edition appliances.

  • Callback activities ― Edition appliances do not track callback activities, which include signature matches and communications between an infected host and a Command and Control (CnC) server.

    • The dashboard What’s Happening panel does not count or link to Malware Callback alerts in the Alerts list.

    • The dashboard Critical Malware Detection panel does not count Malware Callback alerts.

    • The dashboard does not include a Callback Events panel.

    • The Alerts > Alerts page does not include a Callback Activities view.

    • The Callback Server Report is not available on SmartVision Edition appliances.

  • Malware Object events ― On SmartVision Edition appliances, information about Malware Object download events is based on malware objects detected in Web traffic transferred over SMB protocols in the core of the network (workstation to workstation or workstation to data center).

    This is reflected in several areas:

    • The number of Malware Guard alerts counted in the What’s Happening panel of the dashboard.

    • The number of Malware Object alerts counted in the What’s Happening and Critical Malware Events panels of the dashboard.

    • The Malware Object alerts listed in the Alerts list.

  • Web Infection events ― Web Infection events and DNS-related events are not detected, and therefore are not reflected in dashboard or listed in any alerts lists.

  • Riskware events ― If riskware detection is enabled on a SmartVision Edition appliance, the appliance can detect riskware in Malware Object download events but not in Malware Callback or Web Infection events.

  • FUME ― On Edition appliances, the suspicious objects that Trellix Unified Multiflow Engine (FUME) sends to the virtual machine (VM) to detect multiflow attacks are limited to .exe and .dll files over SMB and SMB 2.

  • Trellix event notifications―Use the Edition appliance Web UI to view and configure Trellix event notifications for Malware Object alerts and Riskware Object alerts only. Use the CLI to view and configure these settings for events.

  • Alert suppression― Edition appliances cannot be configured to suppress the Malware Object alerts or Web Infection alerts that you believe to be false positives.

  • Trellix event notifications ― Use the SmartVision Edition appliance Web UI to view and configure Trellix event notifications for Malware Object and Riskware Object alerts. Use the CLI to view and configure these settings for events.

  • Alert suppression ― SmartVision Edition appliances cannot be configured to suppress the Malware Object alerts or Web Infection alerts that you believe to be false positives.

  • IPS events ― SmartVision Edition appliances do not detect IPS events

    • You cannot view or manage IPS alerts on a SmartVision Edition appliance, and there are no IPS reports to generate on a SmartVision Edition appliance.

    • The dashboard does not display an IPS Trend panel.

    • Alerts in the Hosts list and Alerts list are not marked with IPS badges.

    • SmartVision Edition appliances do not detect ping sweep reconnaissance activity or port scan reconnaissance or brute force activity.

  • Forensic analysis integration ― You cannot integrate a SmartVision Edition appliance with packet analyzer applications (such as Solera Networks, RSA NetWitness, and TrellixPacket Capture Network Forensics Platform) that perform full packet capture and analysis for specific target and source IP addresses.

  • Splunk Enterprise integration ― You cannot integrate a SmartVision Edition appliance with a Splunk Enterprise server. SmartVision Edition appliances do not support the Layer 7 Metadata Event Exporter feature, nor the l7metadata-export CLI commands.

  • Internet Content Adaptation Protocol (ICAP) server―You cannot configure a SmartVision Edition appliance to act as an ICAP server.

  • Bot-tracker features

    • File inspection ― SmartVision Edition appliances do not calculate statistics for MD5 or SHA‑256 hashes detected in inline blocking, TAP blocking, and TCP out-of-band blocking events. The [no] bottracker enable and [no] bottracker {fi‑md5 | fi‑sha‑256} enable commands are not supported.

    • Snort-matching packet flows ― SmartVision Edition appliances do not save packets in a flow that matches Snort rules. The [no] bottracker trace‑save enable command is not supported.

    • Signature matching and statistics ― SmartVision Edition appliances do not support the show bottracker {sigmatch | stats} command.

  • IOC custom feeds ― Central Management System appliances do not distribute indicators of compromise (IOCs) to managed SmartVision Edition appliances. The Central Management System command [no] custom content enable [on lms <NXhostname>] does not support managed SmartVision Edition appliances.

Limitations specific to virtual appliances

  • Network interfaces ― The number of network interfaces on a virtual appliance cannot be changed. If the hosting server lacks sufficient physical NICs to accommodate all of the monitoring interfaces, you can use VLAN tagging, assign unused interfaces to a virtual switch that is not bound to a physical NIC, or add physical NICs to the server.

  • Storage policies ― Changing storage policy and adding partitions is not supported.

  • Snapshots ― Storage snapshots are not supported. Content is encoded and decoded on each virtual appliance, and will not be decoded correctly on the snapshot.

Limitations specific to managed appliances

  • If a managed appliance communicates with the Central Management System appliance using the default single-port address type, do not change the active DTI source. Single-port communication requires the managing Central Management System appliance as the DTI source.