Network Security 10.0.4 Release Notes

Prev Next

Note

Release 10.0.4 is the current release after 10.0.2 for Network Security.

Resolved issues

The following issues were resolved in the Trellix Network Security 10.0.4 release.

Tracking number

Summary

COM-31727

To mitigate the Terrapin Vulnerability (CVE-2023-48795), the chacha20 cipher is removed from our high-security list for non-FIPS/non-CC customers using the high-security list. Now, the Trellix platform is not vulnerable to Terrapin Vulnerability (CVE-2023-48795) with default configuration. We plan to upgrade to the latest stable version of OpenSSH in the upcoming 11.0 major release to further harden and resolve the vulnerable option related to the Terrapin Vulnerability.

COM-62557

To further harden the security of our products, we have upgraded Apache HTTPd to version 2.4.62, the latest stable release.

COM-62574

Fixes an issue where the sensor goes into unknown state after a reboot when submission metadata streaming is enabled.

COM-62575

Fixes an issue where the Helix Alert notification was not displayed.

WEBMPS-53871

Fixes a foxd process crash issue.

WEBMPS-53916

Fixes an issue where the Network Anomalies page fails to load selected data.

WEBMPS-53958

Fixes an issue where the disc filled up due to a directory cleanup failure.

WEBMPS-53966

Fixes an issue with OS image upgrade to v10.0.2 that occurred when previous Helix configurations contained invalid values.

WEBMPS-54009

Fixes a datapth process crash issue.

WEBMPS-54010

Fixes the YARA warning error 'Too much memory use' encountered on the appliance.

WEBMPS-54012

Fixes an issue where the maximum and minimum values of the SMB graph in the monitoring traffic widget show as 0.

Known Issues

The following issues are known in the Trellix Network Security 10.0.4 release.

Tracking number

Summary

CMS-32420

The WebUI changes for SSL Inbound settings is not supported on 10.0.2 Central Management System. This will be addressed in next release.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-31165

gisettings API is not restricting the maximum number of inputs for a field as 10.

WEBMPS-24391

In a virtual Network Security appliance on Hyper-V, modifying the MTU value affects inline traffic. The traffic is reinstated when fe_fastpath_mgr is restarted.

WEBMPS-24484

IPS alerts for brute force login attempts do not include the appID, although the appID is detected.

WEBMPS-24541

The CLI does not return any errors when you add a duplicate of an existing configuration for Whitelist and Homenet IP, or when you delete a configuration that does not exist.

WEBMPS-26159

The Network Security appliance cannot stream data to the Splunk server via a proxy when SSL is enabled on the Splunk server.

WEBMPS-27033

Intermittent drops of internal FUME packets have been observed on the appliance.

Disable SAML in a Helix environment

SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Network Security appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.

For more information, see the

Helix Integration Guide for Trellix devices

.

  • In the Software Requirements section, see “HelixConnect Client Software Requirements”.

  • In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.

Upgrade support

The Trellix Network Security 10.0.4 release requires a reboot for the update to take effect. You can upgrade your NX appliance to 10.0.4 from release 9.0.0 or later.

Note

After an upgrade to version 10.0.4, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Caution

If your Network Security appliance is running in CC-NDcPP compliance mode and the Web Server CA certificate (or one of the supplemental CA trust certificates added to the configuration) expires, the configuration database will fail to commit when the appliance is rebooted, resulting in a nonrecoverable error. If this happens, reset the appliance to factory default settings.

Note

  • Submissions from Network Security configured in hybrid mode will no longer be sent to Cloud MVX.

  • Network Security appliances configured in hybrid mode will offload overflow submissions to the connected on-prem cluster.

Migrating inline policy exceptions and IPS policy exceptions

For Network Security appliances configured with inline policy exceptions or IPS policy exceptions, the upgrade process automatically migrates the existing policy exceptions to the alert policy exceptions format introduced in release 9.0.2.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.

Downloading content from the DTI offline update portal

If you download Network Security 10.0 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the

Trellix DTI Offline Update Portal User Guide

.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Network Security appliance to the 10.0.4 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.

Enabling access to intel content

Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.

Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.