Management path

Prev Next

Malware Analysis appliances can download security content and software updates from the Trellix Dynamic Threat Intelligence (DTI) network. With a two-way content license, the appliance can also upload threat intelligence information to the DTI network.

Standalone Malware Analysis appliances that receive DTI updates

The Central Management System appliance and standalone appliances use the ether1 port to communicate with the DTI network. In the default configuration, where you receive updates from the DTI network (cloud.fireeye.com), allow outbound access to all IP addresses on the following ports:

  • DNS (UDP/53)

  • HTTPS (TCP/443)

Management interface ether1 requires a static IP address or reserved DHCP address and subnet mask.

Malware Analysis appliances with domain-based proxy ACL rules

If your configuration includes domain-based proxy ACL rules, allow access to *.fireeye.com.

Malware Analysis appliances connected to the Central Management System appliance

For Malware Analysis appliances connected to the Central Management System appliance, use only a static IP address and subnet mask. The appliance should use the ether1 port to communicate with the Central Management System appliance.

Note

Do not use ZeroConf on the primary interface.

To enable IPv6 routing for the management network, use the Configuration Wizard or see the CLI Command Reference for information about the ipv6 enable command, interface ipv6 command, or the configuration jump-start command.

Integrated CM communications protocol and port configurations

Establish SSH connectivity between the Central Management System appliance and each managed Malware Analysis appliance. For details about port and protocol configuration, see the Hardware Administration Guide.