Network Security and Email Security — Server appliances

Prev Next

Important

There are two versions of IAM. If the URL you use to access the IAM UI ends with fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends with trellix.com, see the Trellix IAM Guide for information regarding IAM.

Task

Information

Done

Verify that the customer ID on the appliance matches the ID in the IAM Web UI.

  1. Run the show version command in the appliance CLI and locate the Customer ID field.

  2. Log into your Trellix Cloud Account and click My Settings > My Organization. Locate the Oracle Customer ID field on the Organization Settings page.

Standalone appliances: Prevent the appliance from automatically connecting to the Trellix Helix-enabled cloud Central Management System appliance (if any).

Run the no cmc client enable command from the appliance CLI.

See Preventing connections to a cloud Central Management appliance.

Enable Trellix Helix mode on each appliance.

Run the helix mode on-premises command to enable Trellix Helix and allow Single Sign-On (SSO).

Run the helix mode on-premises with-sso command to enable Trellix Helix and enforce SSO.

See Enabling Helix Mode.

Central Management System-connected appliances: Ensure that alerts and health statistics are streamed directly to Trellix Helix and not through the Trellix Helix-enabled Central Management System appliance.

Run the show datastreaming helix command on each connected appliance and verify that the Helix data-streaming enabled field is yes.

Run the show helix health-stats status command on each connected appliance and verify that the Enabled field is yes.

Run the no fenet dti helix service override command on each appliance.

See Sending alerts and health status directly from appliances.

Configure the HelixConnect Client on each appliance.

The HelixConnect Client is enabled automatically when Trellix Helix mode is enabled, but additional steps may be required.

See Establishing HelixConnect connectivity.

If your appliances use an HTTP proxy for outbound communication: Enable the appliances to communicate with Trellix Helix through the proxy.

Run the helix proxy preference fenet-proxy command on the appliance.

See Enabling HTTP proxy communication.

Configure which alerts should trigger email notifications from Trellix Helix. Otherwise, you could be overwhelmed by notifications, especially if you push prior alerts as described in Verification.

  1. Log into the Trellix Helix Web UI.

  2. From the Helix menu in the upper right corner, select Helix Settings.

  3. Under Notifications, move the ON/OFF switch to ON, and then specify the alert levels that should trigger notifications. (To disable all notifications, move the ON/OFF switch to OFF.)

Email Security — Server appliances only: Add the Trellix Helix sender address to the Allowed List on the appliance. Otherwise, additional Email Security — Server analysis will be performed on malicious links that might be included in Trellix Helix email notifications.

  1. Locate the Trellix Helix sender address in your onboarding email.

  2. Run the email-analysis allowed-list sender-email-address <helix-sender-email-address> command on the appliance.