Trellix recommends that the latest system image is running on the appliances. The minimum system images for Trellix Helix are Network Security 8.0, Email Security — Server 8.0, and Endpoint Security (HX) 4.0. However, the following features require later versions:
The HelixConnect Client requires Network Security 8.3.4 or later, Email Security — Server 8.4.3 or later, and Endpoint Security (HX) 5.0.2 or later.
Appliance Settings pages require the following minimum releases.
3rd Party Feeds—Network Security 9.0.2 and Email Security — Server 9.0.2.
Allowed List—Email Security — Server 8.4.3.
Attachment Decryption: Email Security — Server 9.0.1.
Blocked List—Email Security — Server 8.4.3.
Certificates/Keys—Network Security 9.0.1 and Email Security — Server 9.0.1.
Data Streaming: Network Security 9.0.0 and Email Security — Server 9.0.0. The ability to enable or disable the streaming of local signatures from the appliance to Trellix Helix requires Network Security 9.0.2 and Email Security — Server 9.0.2.
Email Policy—Email Security — Server 8.4.3.
Email Server—Email Security — Server 9.0.1.
Event Filters—Network Security 9.0.1. The ability to delete and restore all default filters requires Network Security 9.0.2.
ICAP—Network Security 9.0.2.
Impersonation—Email Security — Server 8.4.3.
Inline Policy Exceptions: Network Security 9.0.0.
IPS Configure: Network Security 9.0.0.
Live Interface—Email Security — Server 9.0.1.
Riskware Policy—Network Security 8.3.4. The Custom Riskware Rules tab on the Riskware Policy page requires Email Security — Server 9.0.1.
SmartVision Config—Network Security 9.0.0.
Updates—Network Security 9.0.0, Email Security — Server 9.0.0, and Endpoint Security (HX) 5.1.1.
User Accounts—Network Security 9.0.2 and Email Security — Server 9.0.2.
Whitelists—Network Security 8.3.4. The Domain Whitelist tab on the Whitelists page requires Network Security 9.0.0.
Bulk appliance updates require Network Security 9.0.0, Email Security — Server 9.0.0, and Endpoint Security (HX) 5.1.1.
Bulk configuration changes (the "Write to Group" feature) require Network Security 8.3.4 and Email Security — Server 8.4.3. Exceptions are the Riskware Policy page, which requires Network Security 9.0.0, and the Events Filters and SmartVision Config pages, which require Network Security 9.0.2.
The ability to receive intelligence (observable) feeds from Trellix Helix requires Network Security and Email Security — Server 9.0.2 or later.
The ability to enable appliances to communicate with Trellix Helix through an HTTP proxy requires the following releases:
DTI service communication: Network Security and Email Security — Server 9.0.2 or later and Endpoint Security (HX) 5.1.0 or later.
Health services communication: Network Security and Email Security — Server Release 9.1.0 or later and Endpoint Security (HX) 5.1.0 or later.
Admin or operator access to the appliances.
Factory-configured DTI credentials are registered on the LDAP server that Trellix Helix and the DTI network use. For verification, contact Trellix Technical Support.