Network Security 11.x System Administration Guide

Prev Next

Advanced targeted attacks use the Internet as a primary threat vector to compromise key systems, perform reconnaissance on existing defenses, establish long-term control and access to networked systems, and extract data. The Trellix Network Security appliance stops Web-based attacks that traditional and next-generation firewalls (NGFW), IPS, AV, and Web gateways miss. The Network Security appliance protects against zero-day Web exploits and multi-protocol callbacks to keep sensitive data and systems safe.

Deployment modes

You can deploy the Network Security appliance on your network in either inline mode or out-of-band mode. Each mode provides various options and offers specific costs and benefits. Trellix strongly recommends using one of the inline deployment modes. An appliance deployed inline can automatically block attacks and callbacks to Command and Control (CnC) servers. With inline deployment, recovering from a malware attack is faster and less resource-intensive. For information about the deploying the Network Security appliance in your network, see the Network Security Hardware Administration Guide for your appliance model and Operational Mode Configuration .

Network Security product editions and SmartVision

On Network Security appliances licensed in release 8.1.2 or later, SmartVision technology is available in two product editions of the appliance: Classic and SmartVision. Network Security appliances licensed before Release 8.1.2 can enable SmartVision in the Classic product edition of the appliance.

  • Classic product edition―a Network Security appliance with a Classic Edition appliance license provides the full range of SmartVision features and standard Network Security appliance features. This type of SmartVision appliance can be a SmartVision-enabled Network Security sensor or a SmartVision-enabled Network Security integrated appliance.

    Note

    You can convert the Classic product edition into the SmartVision product edition using the following CLI command, smartvision sv-mode enable. Use the no version of the command to convert it back to Classic edition.

    Conversion will require a manual appliance reboot.

  • SmartVision product edition―A SmartVision Edition sensor (which is a component of the Trellix Network Security, SmartVision Edition solution) is a Network Security hardware or virtual appliance with a SmartVision Edition FIREEYE_APPLIANCE license. This type of SmartVision appliance offers a basic, lighter version of the full-featured Classic NX appliance.

The Network Security appliance product edition is determined by its FIREEYE_APPLIANCE license and not by the software image installed. You can view the edition in the appliance license details and in other areas of the Network Security Web UI and CLI and, for managed Network Security appliances, in the Central Management System Web UI and CLI.

For more information about using the SmartVision features, see the Network Security SmartVision Feature Guide. For an overview of the differences between the Classic and SmartVision product editions of Network Security appliances, contact your Trellix sales representative.

Network Security high availability

Two Network Security appliances connected to a Central Management System appliance can be configured as a high-availability pair for detection redundancy. The Network Security pair operates in active-active mode. In active-active mode, both appliances are ready to receive and process all traffic. The two appliances in the pair communicate with each other continuously over a dedicated control link and a dedicated data link. The control link is used to exchange control messages. The data link is used to replicate the network traffic from the monitoring ports of one appliance to the other appliance.

Both appliances actively monitor the state of the network. The data link maintains exactly the same state between both appliances—every packet received on the monitoring ports is replicated to the peer appliance through the data port. Traffic received on the monitoring ports generates active alerts that are aggregated to the Central Management System appliance and displayed in the Web UI. Traffic received on the data ports generates standby alerts that are not aggregated or displayed. If one appliance fails, detection activity fails over to the peer appliance, which creates all new events and submissions as "active."

For details, see the Network Security High Availability Guide.

IVX Cluster deployment

A standard (or integrated) appliance performs both monitoring and analysis. Trellix Distributed Network Security separates these two functions. Appliances that function as sensors extract objects and URLs from the traffic they monitor, and send submissions to an IVX cluster for inspection and analysis. A sensor and an integrated appliance have identical features and detection efficacy.

An appliance running in MVX hybrid mode can send submissions to an IVX cluster, but only when a predefined capacity threshold is reached. This offloads the analysis function from the appliance to the IVX cluster, which prevents delays and reduced efficacy when volume and other processing demands are high. When the capacity falls below this threshold, the appliance resumes sending submissions to its on-board analysis engine.

Sensors can be managed by the Central Management System appliance that manages the IVX cluster or by another Central Management System appliance. The sensors can also be standalone appliances that are not managed by a Central Management System appliance.

Hybrid appliances must be managed by the Central Management System appliance that manages the IVX cluster. They cannot be standalone appliances.

The IVX cluster contains compute nodes, which are Intelligent Virtual Execution - Server appliances with MVX analysis engines. Compute nodes are designated as brokers. The brokers receive the submissions from the sensors and manage them in a queue that is distributed across the brokers in the cluster. The compute nodes pull submissions from the queue, perform the analysis, and send the verdict to the sensors through the brokers.

The sensors generate alerts based on the verdict. A managed sensor sends the alerts to its managing Central Management System appliance, which aggregates the alerts and displays them on a single interface. A standalone sensor displays its own alerts.

In an IVX Smart Grid deployment, the cluster is hosted on-premises in the customer network. In a Cloud MVX deployment, the cluster is hosted in the Trellix cloud.

For a list of the appliances that can function as sensors or hybrid appliances and for deployment details, see the Distributed Network Security IVX Smart Grid Guide and Distributed Network Security Cloud MVX Guide.

Auto Enable/Disable of Broker role in MVX Cluster operations

From 11.x, Intelligent Virtual Execution - Server system now automatically enables or disables the broker role when a user creates or deletes a cluster through CLI. This simplifies workflows, reduces manual steps, and minimizes configuration errors during cluster lifecycle management.

CLI command to create a Cluster

mvx cluster <cluster-name>

This automatically enables the broker once the node is ready.

CLI command to delete a Cluster

no mvx cluster <cluster-name>

This automatically disables the broker before deleting the cluster.

Management path

Network Security appliances can download security content and software updates from the Trellix Dynamic Threat Intelligence (DTI) network. With a two-way content license, the appliance can also upload threat intelligence information to the DTI network.

Standalone Network Security appliances that receive DTI updates

The Central Management System appliance and standalone appliances use the ether1 port to communicate with the DTI network. In the default configuration, where you receive updates from the DTI network (cloud.fireeye.com), allow outbound access to all IP addresses on the following ports:

  • DNS (UDP/53)

  • HTTPS (TCP/443)

Management interface ether1 requires a static IP address or reserved DHCP address and subnet mask.

Environments that restrict outbound access to certain IP addresses

If your security policy requires that you restrict outbound access to certain IP addresses, you cannot use the DTI network. Instead, point to staticcloud.fireeye.com for DTI updates, and allow access to the *incapdns.net domain.

For appliances that get threat intelligence from the DTI cloud, you need to enable access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location.

To configure and access staticcloud.fireeye.com:

  1. Enable CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enter the following command from the appliance CLI:

    hostname (config) # fenet dti source default DTI
  3. Save your configuration.

    hostname (config) # write mem
  4. Add IP addresses to the firewall. See https://fireeyecommunity.force.com/CustomerCommunity/s/article/000001543.

To allow access to *incapdns.net:

  1. Add the block of IP addresses found at https://incapsula.zendesk.com/hc/en-us/articles/200627570-Restricting-direct-access-to-your-website-Incapsula-s-IP-addresses- to the firewall.

  2. Allow access to the *.incapdns.net domain at the proxy device.

To allow access to the AWS cloud for threat intelligence:

  1. Go to https://dnschecker.org/#A/context.fireeye.com to determine the IP addresses for your location.

  2. See the AWS IP address range documentation for information about whitelisting the IP addressses.

Network Security appliances with domain-based proxy ACL rules

If your configuration includes domain-based proxy ACL rules, allow access to *.fireeye.com.

Network Security appliances connected to the Central Management System appliance

For Network Security appliances connected to the Central Management System appliance, use only a static IP address and subnet mask. The appliance should use the ether1 port to communicate with the Central Management System appliance.

Note

Do not use ZeroConf on the primary interface.

To enable IPv6 routing for the management network, use the Configuration Wizard or see the CLI Command Reference for information about the ipv6 enable command, interface ipv6 command, or the configuration jump-start command.

Integrated CM communications protocol and port configurations

Establish SSH connectivity between the Central Management System appliance and each managed Network Security appliance. For details about port and protocol configuration, see the Hardware Administration Guide.

Central Management System integration

The Central Management System appliance is an easy-to-deploy, network-based platform that serves as both a security event storehouse and a central management device for Trellix appliances. The Central Management System Web UI or CLI is used to configure, manage, and upgrade its managed devices.

For objects that are determined to be malicious, the managed Network Security appliance automatically generates rules in real time. The auto-generated rules are automatically passed to the Central Management System appliance for distribution to all other managed appliances. The "Submit to MAS" Central Management System feature allows analysts to select an incident on any managed appliance and submit it to a managed Malware Analysis appliance for further forensics.

The connection between the managed appliance and the Central Management System appliance can be initiated by either the appliance (a client-initiated connection) or the Central Management System appliance (a server-initiated connection). For information about client-initiated connections, see Requesting management by a Central Management appliance . For information about server-initiated connections, and about accepting a client-initiated connection request, see the Central Management System Administration Guide.

By default, a managed appliance uses the Central Management System platform as its source server for software downloads from the DTI network. In this configuration, both management and DTI network traffic use a single port. You can change this configuration, as described in Changing the address type for DTI network service requests .

Important

If the Network Security appliance is managed by the Central Management System appliance, you should generally avoid changing shared configuration settings from the appliance Web UI or CLI. If you do so, the changes could be overwritten by commands and actions issued from the Central Management System appliance. Trellix recommends that you configure managed appliances using the Central Management System Web UI. For information about using the Central Management System Web UI to configure managed appliances, see the "Configuring Managed Appliances" section of the Central Management System Administration Guide.

Note

See CM integration for additional information and implementation details.

FIPS 140-2 and common criteria compliance

Use the Compliance Settings page to configure compliance features on the Network Security appliance.

Note

The Intelligent Virtual Execution - Server appliance has a CLI and a Web UI. The recommended method for this configuration on a Intelligent Virtual Execution - Server appliance is through the Central Management System Web UI.

You can instead use the following CLI commands to configure compliance features on the appliance:

  • compliance apply standard

  • compliance declassify zeroize

  • compliance options

  • show compliance

  • show compliance options

  • show compliance standard

For details, see the FIPS 140-2 and Common Criteria Addendum and the CLI Command Reference.