Network Security 11.0.1 Release Notes

Prev Next

New features and changes

This section describes new features or enhancements in the Network Security 11.0.1 release.

  • Enhanced IPv6 Support for Network Segmentation

    Network Security now supports IPv6 for Layer 3 mode VRF and Namespace (NetNS)-based routing. This enhancement enables IPv6 traffic segmentation and forwarding in virtual routing environments. Monitor interfaces can now be configured with IPv6 addresses in addition to the existing support for IPv6 on management interfaces.

    Note

    IPv6 monitor interface support is exclusive to virtual and cloud deployments, including ESXi, KVM, Hyper-V, AWS, and Azure.

  • IPv6 Support for the following features:

    • IPv6 support for L7 metadata export

      Network Security now supports IPv6 for L7metadata export. This enables Network Security to send L7 metadata events to Splunk and NDR Console using IPv6 addresses. The support is extended across key network protocols: HTTPS, TCP, and UDP.

      Additionally, the Web UI for managing L7 metadata settings has been updated to fully support both IPv4 and IPv6 configurations. Access to these settings is now secured and managed through role-based access control.

    • IPv6 support for CommBroker

      The CommBroker service now supports IPv6, allowing system administrators to select interfaces with IPv6 addresses as input modules. This enhancement enables CommBroker to receive and forward events over an IPv6 network.

    • Improved IPv6 connectivity for TapSender

      The TapSender feature now supports IPv6, enabling TapSender to forward L7 metadata to Trellix Helix using IPv6 addresses. This enhancement ensures that metadata export is fully compatible with networks that utilize the IPv6 addressing standard.

    • HelixConnect IPv6 compatibility

      Enabled full compatibility of HelixConnect with NX operating in IPv6 mode, allowing reliable connections and data communication over IPv6 networks.

    • IPv6 support for beaconing module

      The NX beaconing module can now support and detect beaconing activity for IPv6 traffic.

    • IPv6 support for IOC feeds

      Enabled full IPv6 compatibility for IOC feeds. Now, IPv4 and IPv6 indicators can be ingested, processed, and utilized seamlessly within NX.

    • TACACS+ Support over IPv6

      Allowed configuration of TACACS+ servers using IPv6 addresses.

    • IPv6 deployment support

      Enhanced jumpstart experience to set up appliance with IPv6 only configuration.

    • Enhanced existing CLI commands to include support for IPv6

      • show submission src <ip_address>

      • show submission dst <ip_address>

      • show web-incident src <ip_address>

      • show web-incident dst <ip_address>

      • show workorders traces src <ip address>

      • show workorders traces dst <ip address>

        For more details, refer to the CLI Reference Guide.

  • MITRE ID Support and Enhancements

    To enhance threat investigation and response capabilities, multiple alert categories are now comprehensively mapped to specific MITRE IDs. The following alert categories now include MITRE ID mapping that appear as a "MITRE" badge on the WEBUI:

    • Multiple MITRE ID support for SmartVision Alerts - Enhanced SmartVision alerts to display multiple MITRE ID mapping on the WebUI Alerts page.

    • MITRE ID support for NX-IPS Events - All NX-IPS alerts now include MITRE ID mappings which is based on IPS rule categories.

    • MITRE ID support for IoC Alerts - IOC alerts for Domain, URL, and Hash type will now have MITRE mapping.

  • Expanded NDR Sensor Licensing

    The NDR Sensor is now supported on a wider range of NX models, including NX2600, NX3600, NX4600, NX5600, NX6600, and all virtual NX models. This expansion allows broader deployment of network detection and response capabilities across various hardware and virtual environments. Licensing remains a key driver for enabling NDR mode. Customers can activate the NDR Sensor on supported platforms by purchasing and applying the appropriate NDR feature license.

  • LDAP client update

    The LDAP client now supports the automatic fetching of Certificate Revocation Lists (CRLs), along with existing manual updates feature.

  • Synchronization with TAXII

    The TAXII client within the appliance is now correctly routed through the Fenet proxy (if configured), allowing for successful synchronization with the TAXII server.

Enhancements

  • Enhanced QR Code Detection Alerts

    Enhanced the QR code badge in the WebUI for malicious URLs extracted from QR codes. The badge now will be displayed on the Alerts tab for both parent and child alerts, when alerts are expanded, and as a filter option. This improvement provides clearer visibility into threats originating from QR codes.

  • New filter options in HTTP and flow protocols

    You can now filter events in HTTP protocol by request and response content lengths. In flow protocol, you can filter events by geo_location.

  • The appliance base components have been upgraded to fully support TLS 1.3 for management protocols, including the Web management interface. This enhancement enforces access rules when Web Client Certificate Authentication is enabled, client certificates are now required for all WSAPI calls, and there is no fallback to other authentication methods for Web Portal access.

  • The configuration jumpstart wizard now supports both pure IPv6 and dual-stack (IPv4/IPv6) configurations, enabling successful deployment in IPv6-only environments.

  • Log Manager updates

    The Upload option on the Log Manager page used to upload archived files has been removed.

  • FLOSS artifacts updates on eAlerts page

    On the eAlerts page, FLOSS will be shown in the Artifact column whether it is enabled or not. FLOSS artifacts are disabled by default. Disabled FLOSS artifacts will not be displayed in the following situations:

    • On expanding the alert details

    • Inside a triage bundle

    • On downloading artifacts from the API

    Use the following CLIs to configure FLOSS artifacts.

    • [no] analysis artifact floss enable: Enable or disable FLOSS artifact

    • show analysis artifact floss: Display FLOSS artifact

  • Bulk configuration on Health Services tab

    In the Health Services tab, you can select the newly added check box to enable or disable all services/notifications in bulk.

  • Support local time streaming for events

    The streamingd service now supports the configuration of event timestamps to reflect the local time zone set on the appliance, rather than the default Coordinated Universal Time (UTC).

    This enhancement enables system administrators to ensure event timestamps streamed via streamingd are consistent with timestamps on files submitted through the appliance. Use the following CLIs to configure the time zones:

    • datastreaming submission local-timestamp enable - Enable the streaming of event timestamps in the appliance's local time zone.

    • no datastreaming submission local-timestamp enable - Revert the streaming of event timestamps back to the default UTC format.

    • show datastreaming submission - View the status of this new "Streaming in Local Time" feature, use existing CLI.

Resolved issues

The following issues were resolved in the Trellix Network Security 11.0.1 release.

Tracking number

Summary

COM-63549

Resolved an issue that prevented users from logging in to the PKI/CAC server after upgrading to version 11.0.0.

COM-63513

Resolved an issue where an error response during login attempts exposed an internal system path.

COM-63246

Fixed an issue where service health statistics digest notifications were not being sent.

COM-63130

Removed the diffie-hellman-group14-sha1 Key Exchange (KEX) cipher from our supported CC and FIPS cipher lists.

COM-63711

Resolved an issue where the cs1 label in the CEF output was displaying incorrect information.

COM-63695

Resolved an issue where upgrading to v11.0.1 with CC/FIPS+CC enabled caused the appliance to incorrectly report "No" for overall compliance mode. The issue was due to the "LDAP CRL Autofetch" rule not being met.

COM-63703

Resolved an issue where upgrading a CC/FIPS+CC enabled cluster to Abbot-MR1 would incorrectly report a "No" for overall compliance mode. This was due to the "LDAP Certificate SAN RFC-6125" rule not being met.

COM-63415

Resolved an issue where logs were not being sent to Splunk after upgrading to version 11, particularly when the use-fenet-proxy option was disabled.

COM-63528

Resolved an issue where the AX appliance's management interface (ether1) was incorrectly attempting to establish connections for sandbox analysis.

COM-63390

Resolved an issue that caused slogin connections from CMS to other appliances to immediately disconnect after upgrading to version 11.0.0.

COM-63373

Fixed the vulnerability CVE-2022-27406 issue by updating the FreeType library

COM-62386

Fixes the issue where the appliance included a version of the python3 idna software module associated with CVE-2024-3651. The module is now updated to a non-vulnerable version. This proactively addresses the potential vulnerability even though the appliance did not use the specific vulnerable function.

COM-63502

Fixed the autocomplete issue where the autocomplete function is disabled on all password fields to prevent browsers from automatically saving and filling in sensitive data.

WEBMPS-54910

Fixed an issue where fragmented packets are being processed even after disabling fragmentation.

WEBMPS-54675

Resolved an issue in version 11.0.0 where the NX appliance ignored the SSLi network bypass configuration after upgrade. The appliance now correctly applies the SSLi bypass settings as configured.

WEBMPS-54603

Fixed an issue that caused delays when using the "Delete All" function to remove a large number of CIDR rules.

WEBMPS-54531

Fixed an issue in the CLI command show submission summary by <source/destination> where the output always incorrectly displayed "hours" regardless of the specified time unit.

WEBMPS-54608

Fixed an issue where the full hostname in a malware callback alert were being truncated in both the WebUI and the alert's XML file.

WEBMPS-54329

Fixed an issue where, in Tap mode, the URL was missing in alerts generated for file IOCs when the same flow also matched another signature configured with a block action.

WEBMPS-54710

Fixed an issue where "Healthmonitord" nodes was causing appliance slowness.

WEBMPS-25386

Fixed an issue that was causing an intermittent crash in a background process.

WEBMPS-54560

Fixed an issue where some key information was missing from rsyslog events for riskware infections. Syslog events will now include all relevant details, providing complete and accurate information for your security analysis.

WEBMPS-54685

Addressed an issue causing high memory consumption by a critical datapath process.

WEBUI-14964

Fixed the STIX feed upload functionality to accept only valid STIX 1.0 (XML) and STIX 2.0/2.1 (JSON) formats. The system no longer allows unsupported file formats to be uploaded.

WEBUI-29938

Fixed an issue where the QR Code badge was not displaying for detected alerts on the NX Alerts page.

Known Issues

The following issues are known in the Trellix Network Security 11.0.1 release.

Tracking number

Summary

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-31165

gisettings API is not restricting the maximum number of inputs for a field as 10.

COM-63612

Threat-info badges may not appear on alerts, even when the hash qualifies the bloom filter.

COM-63635

Compliance mode appliances are logging too much noise with SSL_ERROR_WANT_READ informational status.

WEBMPS-24391

In a virtual Network Security appliance on Hyper-V, modifying the MTU value affects inline traffic. The traffic is reinstated when fe_fastpath_mgr is restarted.

WEBMPS-24484

IPS alerts for brute force login attempts do not include the appID, although the appID is detected.

WEBMPS-24541

The CLI does not return any errors when you add a duplicate of an existing configuration for Whitelist and Homenet IP, or when you delete a configuration that does not exist.

Additional Information

Product compatibility

This Trellix Network Security release supports the following Trellix products:

  • HelixConnect client

  • Central Management appliance

Models not supported in this release

The following Network Security models are not supported in the release 11.0.1 and later releases.

  • NX 900

  • NX 1400

  • NX 2400

  • NX 10000

  • NX 4500Vec2nitro (cloud)

    Trellix recommends deploying the new cloud model and reconfiguring the routes.

  • NX 6500Vec2nitro (cloud)

    Trellix recommends deploying the new cloud model and reconfiguring the routes.

Disable SAML in a Helix environment

SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Network Security appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.

For more information, see the

Helix Integration Guide for Trellix devices

.

  • In the Software Requirements section, see “HelixConnect Client Software Requirements”.

  • In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.

Upgrade support

The Trellix Network Security 11.0.1 release requires a reboot for the update to take effect. You can upgrade your NX appliance to 11.0.1 from release 9.1.0 or later.

Note

After an upgrade to version 11.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

During this process there will be an impact in detection.

Note

  • Submissions from Network Security configured in hybrid mode will no longer be sent to Cloud MVX.

  • Network Security appliances configured in hybrid mode will offload overflow submissions to the connected on-prem cluster.

Important

When upgrading an X500 NX running in FIPS/CC compliance mode to version 11.0.1, you must reapply the compliance mode immediately after the upgrade. Use the CLI command compliance apply standard <standard name> and save the configuration using the CLI write memory.

After reapplying compliance mode, ensure that any necessary compliance options overrides are reasserted as needed. In rare instances, the appliance may become unresponsive before compliance can be applied. If this occurs, the appliance may need to be power cycled.

Migrating inline policy exceptions and IPS policy exceptions

For Network Security appliances configured with inline policy exceptions or IPS policy exceptions, the upgrade process automatically migrates the existing policy exceptions to the alert policy exceptions format introduced in release 9.0.2.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.1.

Downloading content from the DTI offline update portal

If you download Network Security 11.0.1 security content from the DTI Offline Update Portal, use the SCNET-9.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the

Trellix DTI Offline Update Portal User Guide

.

YARA rules supported versions

YARA rules support version 4.5.0.

Important

Before you upgrade a Network Security appliance to the 11.0.1 release, modify any custom YARA rules to YARA 4.5.0. For details about YARA 4.5.0, see YARA's Documentation, Release 4.5.0 by Victor Alvarez.

Enabling access to intel content

Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.

Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.