Validating DTI access

Prev Next

Before using the features associated with the DTI network, you must establish communication between the appliance and the DTI network. Use the following procedures to verify this communication.

Prerequisites
  • Operator or Admin access

  • Access to the DTI network

Validating DTI access using the Web UI

Use the Trellix System Information page to validate DTI cloud communication.

CM_HealthCheckPage_scap.PNG
To validate DTI access:
  1. Click the About tab.

  2. Click Health Check on the upper left side.

  3. Locate the Dynamic Threat Intelligence Cloud section.

    All_DTIValidate_scap.PNG
    CM_DTIValidate_scap.PNG
  4. Verify that the DTI Client field is Enabled.

Validating DTI access using the CLI

Use the commands in this topic to verify DTI communication.

To validate DTI access:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Check the status of the DTI service. (This example is from a managed appliance.)

    hostname (config) # show fenet status
    
    Dynamic Threat Intelligence Service:
     
        Update source  : <online>
        Enabled        : yes
        Download       : DTIUser@10.11.121.13 : singleport
        Upload         : DTIUser@10.11.121.13 : singleport
        Mil            : DTIUser@10.11.121.13 : singleport
    HTTP Proxy:
     
        Address        :
        Username       :
        User-agent     :
    Request Session:
     
        Timeout        : 30
        Retries        : 0
        Speed Time     : 60
        Max Time       : 14400
        Rate Limit     :
     
        Speed Limit     : 1
    Dynamic Threat Intelligence Lockdown:
     
        Enabled        : no
        Locked         : no
        Lock After     : 5 failed attempts
      UPDATES
                          Enabled   Notify  Scheduled       Last Updated At
                          -------   ------  --------------  ---------------
      Security contents:  yes       no      every           2016/07/20 05:43:00
      Stats contents   :  yes               none            2016/07/20 18:55:00
  3. Confirm the following information:

    • Update source is online.

    • DTI service is enabled.

    • DTI service username is the name provided with DTI subscription license.

    • DTI service address is cloud.fireeye.com.