This section lists methods you can use to secure your Trellix appliances. For detailed information about implementing the methods, see the Trellix System Security Guide.
AAA
Authentication, authorization and accounting (AAA) methods control users' access to network resources, and monitor users' activities.
AAA information in the System Security Guide includes:
Authentication—Configuring authentication methods and order, local authentication (user accounts, password complexity, and password policies), remote authentication, Common Access Card (CAC) authentication, Secure Shell (SSH) authentication, and Single Sign-On (SSO) authentication.
Authorization—Defining roles for local user accounts.
Accounting—Managing audit logs.
Trellix Cloud IAM—Using Identity Access Management (IAM), a Web service that provides user authentication and authorization.
Important
There are two versions of IAM. If the URL you use to access the IAM UI ends with
fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends withtrellix.com, see the Trellix IAM Guide for information regarding IAM.
The guide also provides reference information about Trellix appliance roles and capabilities and Trellix Cloud IAM entitlements.
Certificates
Trellix appliances use X.509 (TLS/SSL) certificates to allow secure connections between the appliance and the Web browser running the Web UI, and to verify remote servers for various client applications. They also use the certificates to encrypt the emails they forward to a downstream MTA on the Email Security — Server appliance, and secure the connection to a WebDAV server on the File Protect appliance.
Certificate information in the System Security Guide includes:
Regenerating the system self-signed server certificate
Managing HTTPS and MTA server certificates
Configuring Web server and SharePoint CA certificate chains
Adding supplemental CA client certificates
Importing and downloading public and private keys, and exporting public keys
Defining common attributes of X.509 certificates
Obtaining a CA certificate from a trusted public Certificate Authority (CA)
Specifying the minimum version requirement for Transport Layer Security (TLS)
Improving certificate security