This release of Trellix vIPS is to provide new features and enhancements on the Manager and Virtual IPS Sensor software.
Release parameters | Version |
|---|---|
IPS Manager software | 11.1.7.26 |
Signature Set | 11.9.3.5 |
Virtual IPS Sensor software | 11.1.7.22 |
Virtual Controller/Probe | 2.4.2 |
Trellix SSL Agent (For inbound SSL decryption using DHE/ECDHE ciphers) | 1.0.4 |
Note
The Signature Set version 11.9.3.5 bundled with this release of Manager contains only Digital Envoy database for IP address to Geolocation Mapping. This signature set version will not be a part of the publicly available signature sets.
Note
The Manager software 11.1 is not supported on Windows-based Appliance. The end-of-life for Windows-based Appliance has been declared and the end-of-life is on 01-Apr, 2023. Trellix recommends you to migrate from Windows-based Appliance to Linux-based Appliance.
Note
If you have a 9.x Manager managing 9.x NTBA, you should consider upgrading 9.x Manager to 10.1 or 11.1. If you plan to upgrade the Manager to 11.1, you need to first upgrade it to 10.1.7.65 and then to 11.1.
Upgrade support
Upgrade paths for Manager software versions
Note
Before you start upgrading to the latest 11.1 Manager version, ensure that you do not change the timestamp and timezone values of the Manager.
Caution
The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.
Caution
If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.26 or above, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.26 or above. Post this, you may upgrade the Sensor to 11.1.7.22 or above.
For example, if you have a VM600 Sensor running on software version 9.2.7.26 (TLS 1.0) and Manager software version 10.1.7.44, and you plan to upgrade the Sensor to 11.1.7.22 and Manager to 11.1.7.26, you must follow the upgrade path as listed below:
Upgrade your VM600 Sensor from 9.2.7.26 (Supports TLS 1.0) to 10.1.7.86 (Supports TLS 1.2).
Upgrade the Manager from 10.1.7.44 to 11.1.7.26.
Upgrade the Sensor from 10.1.7.86 to 11.1.7.22.
Note
If you have Sensor software version that supports TLS 1.0, please refer to KB96194 and contact Trellix Support for assistance.
Windows-based Manager:
Version | Upgrade path to 11.1 |
|---|---|
10.1.7.4, 10.1.7.7, 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66.3 | 11.1.7.26 |
11.1.7.3, 11.1.7.3.5 | 11.1.7.26 |
Linux-based Manager:
Note
After upgrade, the Linux-based Manager reboots automatically. If it fails to reboot, check the installation logs for errors and reboot the Manager manually.
Version | Upgrade path to 11.1 |
|---|---|
10.1.7.4, 10.1.7.7, 10.1.7.25 (Cloud), 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66 (Cloud), 10.1.7.66.3 | 11.1.7.26 |
11.1.7.3, 11.1.7.3.5 | 11.1.7.26 |
Note
For all direct upgrades to 11.1.7.26, use the IPSM_111726_setup.bin Version 11.1.7.26 upgrade file.
Upgrade paths for Sensor software versions
Virtual IPS Sensor software (IPS-VM600):
Caution
The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.
Caution
If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.26 or above, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.26 or above. Post this, you may upgrade the Sensor to 11.1.7.22 or above.
For example, if you have a VM600 Sensor running on software version 9.2.7.26 (TLS 1.0) and Manager software version 10.1.7.44, and you plan to upgrade the Sensor to 11.1.7.22 and Manager to 11.1.7.26, you must follow the upgrade path as listed below:
Upgrade your VM600 Sensor from 9.2.7.26 (Supports TLS 1.0) to 10.1.7.86 (Supports TLS 1.2).
Upgrade the Manager from 10.1.7.44 to 11.1.7.26.
Upgrade the Sensor from 10.1.7.86 to 11.1.7.22.
Note
If you have Sensor software version that supports TLS 1.0, please refer to KB96194 and contact Trellix Support for assistance.
Sensor models | Version | Upgrade path to 11.1 |
|---|---|---|
Virtual IPS Sensor software (IPS-VM600) | 10.1.7.1, 10.1.7.42, 10.1.7.51, 10.1.7.65, 10.1.7.86, 10.1.7.96 , 10.1.7.123, 10.1.7.135, 10.1.7.155, 10.1.7.156 (Cloud) | 11.1.7.22 |
11.1.7.1 | 11.1.7.22 |
Note
If the Sensor is running on 10.1.7.123 or a later version of 10.1 and you plan to downgrade it to 10.1.7.86 or an older version, you need to first downgrade the Sensor to 10.1.7.96 and then downgrade it to an older version. Please refer to KB96194 and contact Trellix Support for further assistance.
Heterogeneous support
This version of 11.1 Manager software can be used to configure and manage the following devices:
Device | Version |
|---|---|
NS-series Sensors (NS3100, NS3200, NS3500, NS5100, NS5200, NS7150, NS7250, NS7350, NS7100, NS7200, NS7300, NS7500, NS9100, NS9200, NS9300, NS9500 standalone and stack) | 10.1, 11.1 |
Virtual IPS for ESXi server, AWS, and Azure (IPS-VM600) | 10.1, 11.1 |
NTBA Appliances (T-600, T-1200) | 9.1 |
Virtual NTBA Appliances (T-VM, T-100VM, T-200VM) | 9.1 |
Integration support
Trellix IPS version 11.1 supports integration with the following product versions:
Product | Version supported |
|---|---|
Trellix ePolicy Orchestrator - On-prem | 5.10.0 Update 15 |
Trellix Endpoint Security | 10.7.0 |
Trellix Global Threat Intelligence | Compatible with all versions |
McAfee Endpoint Intelligence Agent | 3.2.4 |
McAfee Logon Collector | 3.0.10 |
Trellix Threat Intelligence Exchange | 4.0.0 |
Trellix Data Exchange Layer | 6.0.3 |
Trellix Intelligent Sandbox | 5.2, 5.0 |
Virtual Trellix Intelligent Sandbox | 5.2, 5.0 |
Trellix Virtual Execution | 9.1.2 and above |
Trellix Detection as a Service | 2022.08.01 |
Note
Integration of Trellix DaaS on public cloud is not a part of this release.
Note
Integration with any point product is not supported on public cloud deployments.