To ensure access to IVX Cloud services, you must allow specific URLs and IP addresses in the network firewall settings.
The following tables provide the Trellix URLs and ports required for Trellix ePO - SaaS managed devices to function properly. Ensure that these URLs are allowed through your firewall to prevent service interruptions. If SSL/TLS inspection is enabled on your proxy or firewall, you must disable or exclude it for all traffic to the listed URLs to allow proper communication.
Note
All the domains and URLs are accessed through HTTPS (port 443) unless explicitly specified.
IVX Cloud APIs
Component | Description | US Domain | EU Domain | APJ Domain |
|---|---|---|---|---|
Core APIs | IVX Cloud Core APIs Endpoint | feapi.marketplace.apps.fireeye.com | eu-central-api.daas.trellix.com | apj-api.ivx-cloud.trellix.com |
Webhooks | Integrations Web-hook API Endpoint | dod-webhook.marketplace.apps.fireeye.com | eu-central-webhook.daas.trellix.com | apj-webhook.ivx-cloud.trellix.com |
Config | API for settings and configuration | dod-config.marketplace.apps.fireeye.com | eu-central-config.daas.trellix.com | apj-config.ivx-cloud.trellix.com |
Public Reports | Public reports generated from IVX Cloud Portal is published here. | public-feapi.marketplace.apps.fireeye.com | eu-central-public-api.daas.trellix.com | apj-public-report.ivx-cloud.trellix.com |
Internal APIs | These internal APIs are invoked while working with the Core APIs. These APIs are required for other APIs to work properly (including IVX Cloud Portal). | internal-feapi.marketplace.apps.fireeye.com | eu-central-internal-api.daas.trellix.com | apj-internal-api.ivx-cloud.trellix.com |
Presigned URLs (used only by TIE) | Presigned URLs for submission | dod-prod-presigned-files-upload.s3.amazonaws.com | s3.eu-central-1.amazonaws.com | s3.ap-northeast-1.amazonaws.com |
IVX Cloud portal
Okta login
Component | Description | US Domain | EU Domain | APJ Domain |
|---|---|---|---|---|
IVX Cloud Portal Domain | IVX Cloud Core APIs Endpoint | dod-portal.marketplace.apps.fireeye.com | eu-central-portal.daas.trellix.com | apj-portal.ivx-cloud.trellix.com |
Okta Login Domain | Domain used to authenticate using Okta | login.trellix.com | login.trellix.com | login.trellix.com |
Trellix IAM (TIAM) login
Component | Description | US Domain | EU Domain | APJ Domain |
|---|---|---|---|---|
IVX Cloud Portal Domain | IVX Cloud Core APIs Endpoint | daas.trellix.com | eu.daas.trellix.com | apj.ivx-cloud.trellix.com |
TIAM Domains | These domains can be accessed as part of TIAM Authentication |
|
|
|
Portal domain dependencies
These domains are accessed with IVX Cloud Portal irrespective of the login method.
In addition to other dependencies, make sure to exclude www.trellix.com for all regions.
Static files from AWS
Fetches static file content from AWS.
US Domain | EU Domain | APJ Domain |
|---|---|---|
|
|
|
APIs (AWS APIs)
US Domain | EU Domain | APJ Domain |
|---|---|---|
*.execute-api.us-east-1.amazonaws.com | *.execute-api.eu-central-1.amazonaws.com | *.execute-api.ap-northeast-1.amazonaws.com |
VNC Connect
Domain to establish VNC connection.
US Domain | EU Domain | APJ Domain |
|---|---|---|
wss://feapi.marketplace.apps.fireeye.com | wss://eu-central-api.daas.trellix.com | wss://apj-api.ivx-cloud.trellix.com |
Muse (Muse library)
US Domain | EU Domain | APJ Domain |
|---|---|---|
cdn-prod.odyssey.design.fireeye.com | cdn-prod.odyssey.design.fireeye.com | cdn-prod.odyssey.design.fireeye.com |
Libraries
Domain to access other libraries which are required for IVX Cloud portal.
US Domain | EU Domain | APJ Domain |
|---|---|---|
|
|
|
Allowed IP addresses
To prevent connectivity issues, allow traffic to the following IP addresses:
Region | Public IP |
|---|---|
us-east-1 | 3.228.166.75, 18.235.74.44, 52.205.84.232 |
eu-central-1 | 35.157.227.2, 3.123.242.225 |
ap-northeast-1 | 52.196.159.251, 35.76.246.181 |