This section describes new features in the Trellix Network Security release 10.0.0.
As Trellix continues our exciting evolution, our customers will begin to see our solutions reflect our new name and brand. In this release, we have updated the Network Security Web UI with the Trellix logo and name. This rebranding change requires no effort from you.
You can now import a CSV file to configure IPS rules based on specific categories using the Import Rules button on the IPS Configure page. You can make bulk changes by selecting all-high severity IPS rules in CSV file rather than selecting rules manually one at a time in UI.
All the supported artifacts are now generated for malware-object and riskware-object alerts if the display of static information for malicious and non-malicious files and URLs on the Network Security appliance Web UI is enabled. From this release, the display of static information is enabled by default.
You can now configure the HA port-pair while creating the NX-HA pair.
The NX 10500V has been introduced to achieve 8.5 Gbps throughput.
The Web UI provides geo-location information for all alerts and visually displays where the attacks originated.
You can now integrate your Network Security appliance with Helix through the Network Security Web UI.
The HelixConnect client is automatically enabled when the Helix mode is enabled on the appliance. The appliance also automatically registers with Helix through the HelixConnect client. The HelixConnect client can be independently enabled or disabled even when the Helix mode is disabled.
For information about establishing connectivity with the HelixConnect client and enabling the functionality it offers, see theHelix Integration Guide.
You can now configure datastreaming to Splunk servers.
Metadata streaming through an HTTP proxy is now supported.
The Network Security appliance Web UI has adopted the MUSE design for UX improvements.
Network Security appliances now have Domain Generation Algorithms (DGA) detection capabilities.
A new Bott alert category, Domain Match, has been added. Bott IOC domain alerts will be associated with this category.
The signature id for all IOC domain alerts is 93000001. This sig-id can be used to apply policy exception over domain match alerts.
You can now set the number of days to retain data in the database settings using the Network Security appliance Web UI.
Data will be purged after the retention period. You can change the frequency and time of the data purge.
IPMI on the Network Security 6th generation appliances are now compatible with IPv6 management network.
Supports HTTP/2 protocol. Added SSL Interception support for HTTPS/2 traffic.
Improved file blocking using the Global cache.
Enhanced blocking capability by adding support for bad domain blocking for DNS, HTTP and SSL traffic.
The Health Services tab allows you to configure health monitoring parameters for all the available health services on the appliance.
A list of new AWS M6i instance types are supported in this release for Network Security instance. For more information refer to the Trellix Device Deployment Guide.
You can now restore a backup database belonging to a different appliance model of the same release version. This feature is useful when upgrading from one appliance model to another.
You can now configure the homenet IP address for Snort rules during the initial configuration of the Network Security appliance using the Configuration wizard.
IPS Policies can now be applied to the management interface. This will enable the ICAP module to detect IPS signatures.
The existing FIPS and CC high-security cipher lists have been updated. For more details, refer to Network Security User Guide.
Added support for easier deployment of NX behind a AWS Gateway Load Balancer.
Added support for SSL protocol anomaly detection capability to detect weak SSL protocol usage on the network.
Supports event-based full Packet Capture for the malware callback and infection match alert.
Added High Availability support for all x600 Network Security appliances.
Support added for file extraction and submission to on-prem Intelligent Virtual Execution - Server cluster for the Evidence Collector edition.
Enhanced object extraction from dynamic HTML pages using Headless Chrome.
Upgrade to release version 10.0.0 will not be supported on 4th generation appliances and NX 10550.
All the supported formats for Rsyslog notifications are now displayed in the Network Security Web UI.
The HTTP events generated on the appliance can now be sent to the HTTP Event Collector (HEC) on a Splunk Enterprise instance.
The malware artifacts data downloaded as a zip file for any specified alert includes OS Change Graph data.
SSLi throughput has been improved for NX 5500 and NX 6500 appliances.
The "auditor" user can now create, delete, and upload log-archives from the CLI.
The factory default certificate generation key size is changed to 3072 bits.
The Service Health Statistics Trend widget on the Network Security appliance Web UI dashboard highlights the health level of the most critical service in each category tile.
The Service Health Statistics Trend widget on the Network Security appliance Web UI dashboard includes the IPS event filter, which shows the health status for recently filtered IPS events. If a signature ID is filtered more than 20 times in a 5-minute period, the health status for the IPS event filter will show 'Warning'.
You can now delete both the completed packet capture instances and the running packet capture instances using the Delete and Delete All options. When you delete a packet capture, both the PCAP data and the packet-capture configuration data are deleted.
The Monitored Traffic widget on the Network Security appliance Web UI dashboard now has the option to view the network traffic rate for a specific interface.
Alert type 'Riskware-Object' has been added for the report type 'Riskware Details' for both Static and Scheduled Reports in the Reports option on the Network Security Web UI.
The FAUDE URL screenshot is now generated along with other artifacts after successful submission.
Log-management functionality has been improved.
If you download security content from the DTI Offline Update Portal, you now use the SCNET-8.0 channel of the portal.
You can now download artifacts data corresponding to the specified artifact types (if available for the specified UUID) as a zip file using the API.
Added support for RHEL7.6 for KVM Network Security virtual.
Added batching support for L7metadata for Network Investigator.
Added additional health monitoring modules for unsupported SFP and per port QinQ.