Note
Release 10.0.4 is the current release after 10.0.2 for Network Security.
Resolved issues
The following issues were resolved in the Trellix Network Security 10.0.4 release.
Tracking number | Summary |
|---|---|
COM-31727 | To mitigate the Terrapin Vulnerability (CVE-2023-48795), the chacha20 cipher is removed from our high-security list for non-FIPS/non-CC customers using the high-security list. Now, the Trellix platform is not vulnerable to Terrapin Vulnerability (CVE-2023-48795) with default configuration. We plan to upgrade to the latest stable version of OpenSSH in the upcoming 11.0 major release to further harden and resolve the vulnerable option related to the Terrapin Vulnerability. |
COM-62557 | To further harden the security of our products, we have upgraded Apache HTTPd to version 2.4.62, the latest stable release. |
COM-62574 | Fixes an issue where the sensor goes into unknown state after a reboot when submission metadata streaming is enabled. |
COM-62575 | Fixes an issue where the Helix Alert notification was not displayed. |
WEBMPS-53871 | Fixes a foxd process crash issue. |
WEBMPS-53916 | Fixes an issue where the Network Anomalies page fails to load selected data. |
WEBMPS-53958 | Fixes an issue where the disc filled up due to a directory cleanup failure. |
WEBMPS-53966 | Fixes an issue with OS image upgrade to v10.0.2 that occurred when previous Helix configurations contained invalid values. |
WEBMPS-54009 | Fixes a datapth process crash issue. |
WEBMPS-54010 | Fixes the YARA warning error 'Too much memory use' encountered on the appliance. |
WEBMPS-54012 | Fixes an issue where the maximum and minimum values of the SMB graph in the monitoring traffic widget show as 0. |
Known Issues
The following issues are known in the Trellix Network Security 10.0.4 release.
Tracking number | Summary |
|---|---|
CMS-32420 | The WebUI changes for SSL Inbound settings is not supported on 10.0.2 Central Management System. This will be addressed in next release. |
COM-30656 | Negation symbol '!' is not working before the hostname or the username in deny user list. |
COM-31165 | gisettings API is not restricting the maximum number of inputs for a field as 10. |
WEBMPS-24391 | In a virtual Network Security appliance on Hyper-V, modifying the MTU value affects inline traffic. The traffic is reinstated when fe_fastpath_mgr is restarted. |
WEBMPS-24484 | IPS alerts for brute force login attempts do not include the appID, although the appID is detected. |
WEBMPS-24541 | The CLI does not return any errors when you add a duplicate of an existing configuration for Whitelist and Homenet IP, or when you delete a configuration that does not exist. |
WEBMPS-26159 | The Network Security appliance cannot stream data to the Splunk server via a proxy when SSL is enabled on the Splunk server. |
WEBMPS-27033 | Intermittent drops of internal FUME packets have been observed on the appliance. |
Disable SAML in a Helix environment
SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Network Security appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.
For more information, see the
Helix Integration Guide for Trellix devices
.
In the Software Requirements section, see “HelixConnect Client Software Requirements”.
In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.
Upgrade support
The Trellix Network Security 10.0.4 release requires a reboot for the update to take effect. You can upgrade your NX appliance to 10.0.4 from release 9.0.0 or later.
Note
After an upgrade to version 10.0.4, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Caution
If your Network Security appliance is running in CC-NDcPP compliance mode and the Web Server CA certificate (or one of the supplemental CA trust certificates added to the configuration) expires, the configuration database will fail to commit when the appliance is rebooted, resulting in a nonrecoverable error. If this happens, reset the appliance to factory default settings.
Note
Submissions from Network Security configured in hybrid mode will no longer be sent to Cloud MVX.
Network Security appliances configured in hybrid mode will offload overflow submissions to the connected on-prem cluster.
Migrating inline policy exceptions and IPS policy exceptions
For Network Security appliances configured with inline policy exceptions or IPS policy exceptions, the upgrade process automatically migrates the existing policy exceptions to the alert policy exceptions format introduced in release 9.0.2.
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.
Downloading content from the DTI offline update portal
If you download Network Security 10.0 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the
Trellix DTI Offline Update Portal User Guide
.
YARA rules supported versions
YARA rules support version 4.3.2.
Important
Before you upgrade an Network Security appliance to the 10.0.4 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.
Enabling access to intel content
Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.
Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.