Network Security 10.0.1 Release Notes

Prev Next

This is the latest release of Trellix Network Security.

New features and changes

This section describes new features in the Trellix Network Security release 10.0.1.

  • General enhancement:

    • ICAP available on the evidence collector:

      You can now use ICAP on the evidence collector. The Web UI option for ICAP will not be available in this release.

  • ISTag hash value updated:

    ISTag field is part of ICAP response header. In earlier releases, the ISTag field value was a string containing appliance ID and NX software version. Now, the ISTAG value is changed to MD5SUM hash.

    The new ISTag hash generation syntax:

    appliance_id:<appliance_ID>-release_version:<version>-sc_version:<version>-gi_version:<version>

New, modified and deprecated CLI commands

The CLI command in this section was added in this release.

  • New CLI to reset all DTI services credentials

    • fenet dti credentials reset factory-default

      Resets credentials of all the existing DTI services to factory settings.

Resolved issues

The following issues were resolved in the Trellix Network Security 10.0.1 release.

Tracking number

Summary

COM-30410

Fixes an issue by removing the password present in the API response for CMS appliances.

COM-30687

The 10.0.1 appliance has upgraded Apache httpd to 2.4.56 to address a known vulnerability (CVE-2022-36760) for products including Malware Analysis, Central Management SystemEmail Security — Server, File Protect, Network Security, and Intelligent Virtual Execution - Server.

COM-31382

Fixes an issue by adding mechanism to clean up outdated triage packages.

COM-31477

Fixes an issue where the localsig auto-extend feature was disabled by default, resulting in the removal of localsig rules upon reaching the TTL value.

COM-31481

Fixes an issue that, by default, upgraded all the Network Security appliance applications to the high-security factory default cipher-lists.

COM-31650

Fixes an issue that prevented the "show alerts type all detail concise timeframe <>" CLI from displaying alert details.

WEBMPS-26697

Fixes missing data issue in the dashboard report for file analysis statistics widget.

WEBMPS-26810

The bandwidth graph is not appearing in the Monitored Traffic widget on the Web UI dashboard for NX1500 and vNX1500 appliances and the CLI show network stats interface pether is not generating the expected output.

WEBMPS-26904

Fixes the issue where commbroker SSL module was not receiving any events. because of handshake failure and unsupported ciphers.

WEBMPS-26910

A SSLi connection context leak was observed when the server connection was closed in the SYN_SENT state causing the connection reset on the client. This issue is fixed.

WEBMPS-26926

Upgrade to BONA fails when customer has IPS policy exception configured on 8.x or earlier release. This issue is fixed.

WEBMPS-26933

Fixes incorrect submission rates in the health status.

WEBMPS-27006

Fixes an issue where the "Monitored traffic" widget did not display graph data in sync with the set timezone.

WEBMPS-27020

Fixes appearance of health warning even after applying QINQ.

WEBMPS-27063

Fixes wrong attacker IP address reported by a Network Security appliance when 3rd party feed is added based on the Source IP address.

Known Issues

The following issues are known in the Trellix Network Security 10.0.1 release.

Tracking number

Summary

COM-30639

Application accepts special characters as user inputs.

COM-30655

The database backup process takes a long time when the alert purge is in progress.

Workaround: Schedule the database backup and purge processes at different times.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-30659

Alert details might be missing from the report generated during alert purging.

COM-31165

gisettings API is not restricting the maximum number of inputs for a field as 10.

EMPS-17220

There could be websocket connection breaks between the headless chrome and python library due to issues with headless chrome. This will be reconciled automatically and connection would be reestablished.

WEBMPS-24391

In a virtual Network Security appliance on Hyper-V, modifying the MTU value affects inline traffic. The traffic is reinstated when fe_fastpath_mgr is restarted.

WEBMPS-24484

IPS alerts for brute force login attempts do not include the appID, although the appID is detected.

WEBMPS-24541

The CLI does not return any errors when you add a duplicate of an existing configuration for Whitelist and Homenet IP, or when you delete a configuration that does not exist.

WEBMPS-26159

The Network Security appliance cannot stream data to the Splunk server via a proxy when SSL is enabled on the Splunk server.

WEBMPS-27033

Intermittent drops of internal FUME packets have been observed on the appliance.

WEBMPS-27147

Link flapping due to datapath process crash

Link flapping occurs due to a crash in the datapath process and requires immediate attention to restore network stability and prevent further disruptions. Contact Trellix support directly to get the appropriate guidance and solutions for this issue.

Disable SAML in a Helix environment

SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Network Security appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.

For more information, see the

Helix Integration Guide for Trellix devices

.

  • In the Software Requirements section, see “HelixConnect Client Software Requirements”.

  • In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.

Upgrade support

The Trellix Network Security 10.0.1 release requires a reboot for the update to take effect. You can upgrade your NX appliance to 10.0.1 from release 9.0.0 or later.

IPMI and BIOS firmware updates are required for the Network Security 2550 model. See the section "Upgrading IPMI 3.11 and BIOS 1.9 Firmware for Specific Platforms" below.

Note

After an upgrade to version 10.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Caution

If your Network Security appliance is running in CC-NDcPP compliance mode and the Web Server CA certificate (or one of the supplemental CA trust certificates added to the configuration) expires, the configuration database will fail to commit when the appliance is rebooted, resulting in a nonrecoverable error. If this happens, reset the appliance to factory default settings.

Note

  • Submissions from Network Security configured in hybrid mode will no longer be sent to Cloud MVX.

  • Network Security appliances configured in hybrid mode will offload overflow submissions to the connected on-prem cluster.

Migrating inline policy exceptions and IPS policy exceptions

For Network Security appliances configured with inline policy exceptions or IPS policy exceptions, the upgrade process automatically migrates the existing policy exceptions to the alert policy exceptions format introduced in release 9.0.2.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.1.

Downloading content from the DTI offline update portal

If you download Network Security 10.0 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the

Trellix DTI Offline Update Portal User Guide

.

Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms

The NX 2550 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-21016, COM-25601)

For detailed instructions about upgrading IPMI, see the

System Administration Guide

.

To upgrade IPMI to version 3.11:

Note

IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.

Do not shut down or remove power from the appliance during the upgrade.

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # ipmi firmware update latest

  3. Confirm the upgrade:

    hostname (config) # show ipmi

If the upgrade fails, try the steps again.

If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:

  1. Stop the reload process:

    hostname (config) # reload halt

  2. Disconnect all power cables for 2 minutes.

  3. After 2 minutes, reconnect power cables and restart the appliance.

To upgrade the BIOS to version 1.9:
  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # system bios firmware update latest

    Note

    Do not shut down or remove power from the appliance during the upgrade.

  3. Confirm the upgrade:

    hostname (config) # show system bios

  4. Stop the reload process:

    hostname (config) # reload halt

  5. Disconnect all power cables for 2 minutes.

  6. After 2 minutes, reconnect power cables and restart the appliance.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Network Security appliance to the 10.0.0 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.

Enabling access to intel content

Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.

Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.