New features and changes

Prev Next

This section describes new features in the Trellix Network Security release 10.0.0.

Trellix rebranding updates

As Trellix continues our exciting evolution, our customers will begin to see our solutions reflect our new name and brand. In this release, we have updated the Network Security Web UI with the Trellix logo and name. This rebranding change requires no effort from you.

IPS enhancement for CSV import option on the IPS configure page

You can now import a CSV file to configure IPS rules based on specific categories using the Import Rules button on the IPS Configure page. You can make bulk changes by selecting all-high severity IPS rules in CSV file rather than selecting rules manually one at a time in UI.

Automated generation of artifacts

All the supported artifacts are now generated for malware-object and riskware-object alerts if the display of static information for malicious and non-malicious files and URLs on the Network Security appliance Web UI is enabled. From this release, the display of static information is enabled by default.

High Availability (HA) port pair

You can now configure the HA port-pair while creating the NX-HA pair.

Support for a new model on vmware ESXi platform

The NX 10500V has been introduced to achieve 8.5 Gbps throughput.

Geo-location integration for alerts

The Web UI provides geo-location information for all alerts and visually displays where the attacks originated.

Integration with Helix and HelixConnect

You can now integrate your Network Security appliance with Helix through the Network Security Web UI.

The HelixConnect client is automatically enabled when the Helix mode is enabled on the appliance. The appliance also automatically registers with Helix through the HelixConnect client. The HelixConnect client can be independently enabled or disabled even when the Helix mode is disabled.

For information about establishing connectivity with the HelixConnect client and enabling the functionality it offers, see theHelix Integration Guide.

Datastreaming submission data to third-party SIEM

You can now configure datastreaming to Splunk servers.

Metadata streaming through an HTTP proxy

Metadata streaming through an HTTP proxy is now supported.

MUSE Web UI improvements

The Network Security appliance Web UI has adopted the MUSE design for UX improvements.

DGA detection

Network Security appliances now have Domain Generation Algorithms (DGA) detection capabilities.

Alert policy exceptions are now supported for Domain Match alerts
  • A new Bott alert category, Domain Match, has been added. Bott IOC domain alerts will be associated with this category.

  • The signature id for all IOC domain alerts is 93000001. This sig-id can be used to apply policy exception over domain match alerts.

New data retention and purging policy

You can now set the number of days to retain data in the database settings using the Network Security appliance Web UI.

Data will be purged after the retention period. You can change the frequency and time of the data purge.

IPv6 support on the IPMI for x600 appliances

IPMI on the Network Security 6th generation appliances are now compatible with IPv6 management network.

HTTP/2 Support

Supports HTTP/2 protocol. Added SSL Interception support for HTTPS/2 traffic.

Enhanced Inline file blocking using Global Cache

Improved file blocking using the Global cache.

Domain blocking ability enhancements

Enhanced blocking capability by adding support for bad domain blocking for DNS, HTTP and SSL traffic.

The Health Services tab

The Health Services tab allows you to configure health monitoring parameters for all the available health services on the appliance.

Support for new AWS M6i instance types

A list of new AWS M6i instance types are supported in this release for Network Security instance. For more information refer to the Trellix Device Deployment Guide.

Restoring the database from a backup file

You can now restore a backup database belonging to a different appliance model of the same release version. This feature is useful when upgrading from one appliance model to another.

Configuring the homenet range during initial configuration

You can now configure the homenet IP address for Snort rules during the initial configuration of the Network Security appliance using the Configuration wizard.

IPS support for ICAP

IPS Policies can now be applied to the management interface. This will enable the ICAP module to detect IPS signatures.

List of ciphers modified

The existing FIPS and CC high-security cipher lists have been updated. For more details, refer to Network Security User Guide.

NX integration with AWS GWLB

Added support for easier deployment of NX behind a AWS Gateway Load Balancer.

Support SSL protocol anomaly detection

Added support for SSL protocol anomaly detection capability to detect weak SSL protocol usage on the network.

Event-based Packet Capture for malware callback and infection match alert

Supports event-based full Packet Capture for the malware callback and infection match alert.

High Availability support on x600 NX appliances

Added High Availability support for all x600 Network Security appliances.

Support file extraction and submission for the Evidence Collector Edition

Support added for file extraction and submission to on-prem Intelligent Virtual Execution - Server cluster for the Evidence Collector edition.

Detection enhancement

Enhanced object extraction from dynamic HTML pages using Headless Chrome.

Termination of support for x400 appliances and NX 10550 Platform

Upgrade to release version 10.0.0 will not be supported on 4th generation appliances and NX 10550.

Enhancements
  • All the supported formats for Rsyslog notifications are now displayed in the Network Security Web UI.

  • The HTTP events generated on the appliance can now be sent to the HTTP Event Collector (HEC) on a Splunk Enterprise instance.

  • The malware artifacts data downloaded as a zip file for any specified alert includes OS Change Graph data.

  • SSLi throughput has been improved for NX 5500 and NX 6500 appliances.

  • The "auditor" user can now create, delete, and upload log-archives from the CLI.

  • The factory default certificate generation key size is changed to 3072 bits.

  • The Service Health Statistics Trend widget on the Network Security appliance Web UI dashboard highlights the health level of the most critical service in each category tile.

  • The Service Health Statistics Trend widget on the Network Security appliance Web UI dashboard includes the IPS event filter, which shows the health status for recently filtered IPS events. If a signature ID is filtered more than 20 times in a 5-minute period, the health status for the IPS event filter will show 'Warning'.

  • You can now delete both the completed packet capture instances and the running packet capture instances using the Delete and Delete All options. When you delete a packet capture, both the PCAP data and the packet-capture configuration data are deleted.

  • The Monitored Traffic widget on the Network Security appliance Web UI dashboard now has the option to view the network traffic rate for a specific interface.

  • Alert type 'Riskware-Object' has been added for the report type 'Riskware Details' for both Static and Scheduled Reports in the Reports option on the Network Security Web UI.

  • The FAUDE URL screenshot is now generated along with other artifacts after successful submission.

  • Log-management functionality has been improved.

  • If you download security content from the DTI Offline Update Portal, you now use the SCNET-8.0 channel of the portal.

  • You can now download artifacts data corresponding to the specified artifact types (if available for the specified UUID) as a zip file using the API.

  • Added support for RHEL7.6 for KVM Network Security virtual.

  • Added batching support for L7metadata for Network Investigator.

  • Added additional health monitoring modules for unsupported SFP and per port QinQ.