Release information

Prev Next

This release of Trellix vIPS is to provide new features and enhancements to the Manager and Virtual IPS Sensor software.

Release parameters

Version

IPS Manager software

11.1.7.84

Signature Set

11.10.17.3

Virtual IPS Sensor software

11.1.7.81

Virtual Controller/Probe

2.6.2

Trellix SSL Agent (For inbound SSL decryption using DHE/ECDHE ciphers)

1.0.5

Caution

The IPS Manager no longer supports HTTP-based connection and can be accessed via HTTPS connection only. You need to manually enter https://<hostname or host-IP> on the supported browsers to access the Manager UI.

Note

If you have a 9.x Manager managing 9.x NTBA, you should consider upgrading 9.x Manager to 10.1 or 11.1. If you plan to upgrade the Manager to 11.1, you need to first upgrade it to 10.1.7.65 and then to 11.1.

Upgrade support

Upgrade paths for Manager software versions

Note

Before upgrading to the latest 11.1 Manager version, ensure that you do not change the timestamp and timezone values of the Manager.

Caution

  • The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.

  • If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.84, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.84. Post this, you may upgrade the Sensor to 11.1.7.81 Please refer to KB96194 for more information and contact Trellix Support for assistance.

Important

Trellix IPS Manager 11.1.7.84 enhances the communication security between the Manager and Central Manager (CVE-2024-5671, CVE-2024-5731). You must upgrade the Manager and Central Manager to the same version to avoid alert synchronization issues.

Windows-based Manager:

Version

Upgrade path to 11.1

10.1.7.4, 10.1.7.7, 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66.3, 10.1.7.66.11

11.1.7.84

11.1.7.3, 11.1.7.3.5, 11.1.7.26, 11.1.7.41, 11.1.7.41.2, 11.1.7.56, 11.1.7.71

11.1.7.84

Linux-based Manager:

Note

After upgrade, the Linux-based Manager reboots automatically. If it fails to reboot, check the installation logs for errors and reboot the Manager manually.

Version

Upgrade path to 11.1

10.1.7.4, 10.1.7.7, 10.1.7.25 (Cloud), 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.50.2, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66 (Cloud), 10.1.7.66.3, 10.1.7.66.11

11.1.7.84

11.1.7.3, 11.1.7.3.5, 11.1.7.26, 11.1.7.41, 11.1.7.41.2, 11.1.7.56, 11.1.7.71

11.1.7.84

Note

For all direct upgrades to 11.1.7.84, use the IPSM_111784_setup.bin Version 11.1.7.84 upgrade file.

Upgrade paths for Sensor software versions

Virtual IPS Sensor software (IPS-VM600 and IPS-VM5000):

Caution

  • The Manager software supports only TLS 1.2 ciphers for Manager and Sensor communication.

  • If you are currently using Sensor software version that supports TLS 1.0 and you upgrade your Manager software to 11.1.7.84, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to a software version that supports TLS 1.2 and later upgrade your Manager to 11.1.7.84. Post this, you may upgrade the Sensor to 11.1.7.81. Please refer to KB96194 for more information and contact Trellix Support for assistance.

Sensor models

Version

Upgrade path to 11.1

IPS-VM600

10.1.7.1, 10.1.7.42, 10.1.7.51, 10.1.7.65, 10.1.7.86, 10.1.7.96 , 10.1.7.123, 10.1.7.135, 10.1.7.155, 10.1.7.156 (Cloud)

11.1.7.81

11.1.7.1, 11.1.7.22, 11.1.7.44, 11.1.7.56, 11.1.7.72

11.1.7.81

IPS-VM5000

11.1.7.44, 11.1.7.56, 11.1.7.72

11.1.7.81

Important

Starting with the 11.1 Update 2 release, the minimum memory requirement for IPS-VM600 deployment on ESXi and KVM is 8 GB. Contact Trellix support for more information and assistance.

Note

If the Sensor is running on 10.1.7.123 or a later version of 10.1 and you plan to downgrade it to 10.1.7.86 or an older version, you need to first downgrade the Sensor to 10.1.7.96 and then downgrade it to an older version. Please refer to KB96194 and contact Trellix Support for further assistance.

Heterogeneous support

This version of 11.1 Manager software can be used to configure and manage the following devices:

Device

Version

NS-series Sensors (NS3100, NS3200, NS3500, NS5100, NS5200, NS7150, NS7250, NS7350, NS7100, NS7200, NS7300, NS7500, NS9100, NS9200, NS9300, NS9500 standalone and stack)

10.1, 11.1

NS-series Sensors (NS3600 and NS7600)

11.1

Virtual IPS for AWS, Azure, and OCI (IPS-VM600)

10.1, 11.1

Virtual IPS for KVM and ESXi server (IPS-VM600 and IPS-VM5000)

Note

IPS-VM5000 and support for KVM have been introduced with 11.1 Update 2 release.

10.1, 11.1

NTBA Appliances (T-600, T-1200)

9.1

Virtual NTBA Appliances (T-VM, T-100VM, T-200VM)

9.1

Integration support

Trellix IPS version 11.1 supports integration with the following product versions:

Product

Version supported

Trellix Data Exchange Layer

6.0.3

Trellix Endpoint Security

10.7.0

Trellix ePolicy Orchestrator - On-prem

5.10.0 Service Pack 1, Update 2

Trellix Global Threat Intelligence

Compatible with all versions

Trellix Intelligent Sandbox

5.2.4, 5.2.2

Virtual Trellix Intelligent Sandbox

5.2.4, 5.2.2

Trellix Intelligent Virtual Execution - Server

10.0.0, 9.1.4

Trellix Intelligent Virtual Execution Cloud

Version 24R1

Trellix Logon Collector

3.0.11

Trellix Network Investigator (Appliance and Virtual)

3.0.0

Trellix Threat Intelligence Exchange

4.0.0

McAfee Endpoint Intelligence Agent

3.2.4

Note

  • After upgrading the Manager to 11.1.7.84, download the latest ePO extension and import it into the ePO user interface to avoid connectivity issues.

  • Integration with any point product is not supported on public cloud deployments.