Enables or disables communication between Trellix IPS and Intelligent Sandbox over TCP.
set nsp-tcp-channel enable:
This will switch Intelligent Sandbox to use TCP channel to communicate with Trellix IPS.
When the command
set nsp-tcp-channel enableis executed in Intelligent Sandbox, check the MATD channel in use in Trellix IPS.Log on to the Sensor CLI and enter into debug mode.
Execute the CLI command
show matd channel.If the MATD Trellix IPS channel type is seen as SSL, execute the CLI command
switch matd channel tcpto switch to TCP channel .Execute
set amchannelencryption off.
set nsp-tcp-channel disable:
This will switch Intelligent Sandbox to use SSL encrypted channel to communicate with Trellix IPS.
Encrypted data transfer from Trellix IPS.
When SSL encryption is enabled on Intelligent Sandbox and Trellix IPS, the data sent from Trellix IPS to Intelligent Sandbox is encrypted.
There would be no support for NULL cipher from 4.10.x release onwards.
When the command
set nsp-tcp-channel disableis executed in Intelligent Sandbox, check the MATD channel in use in Trellix IPS.Log on to the Sensor CLI and enter into the debug mode.
If the MATD Trellix IPS channel type is seen as TCP, execute the CLI command
switch matd channel SSLto switch to SSL channel.Execute
set amchannelencryption on.
Syntax:
set nsp-tcp-channel enable | disable
Parameter | Description |
|---|---|
enable | Enable TCP channel support |
disable | Disable TCP channel support |
Example:
set nsp-tcp-channel enable NSP TCP Channel Support Enabled and restarted service