IAM domain URL updates
The Identity and Access Management (IAM) domain URLs used by Trellix Intrusion Prevention System have been updated. As a user, you must update the destination URLs in your firewall configuration to ensure uninterrupted communication to the IAM service. The following table outlines the changes to the IAM domain URLs:
Existing destination URL | Updated destination URL |
|---|---|
iam.skyhigh.cloud iam-rs.skyhigh.cloud | iam.cloud.trellix.com iam-rs.cloud.trellix.com |
For information on the updated destination URLs, refer to the section Set the desktop firewall in Trellix Intrusion Prevention System 11.1.x Product Guide.
New features
This release of the Trellix Intrusion Prevention System includes the following new feature:
Integrating Trellix vIPS with Azure Gateway Load Balancer
This release of 11.1 introduces the integration of Trellix vIPS with Azure Gateway Load Balancer. The Gateway Load Balancer (GWLB) is an SKU of the Azure Load Balancer portfolio catered for high performance and high availability scenarios with Trellix Network Virtual Appliances (NVAs). GWLB enables you to deploy, scale, and manage virtual appliances, such as firewalls, intrusion prevention systems, and deep packet inspection systems. It combines a transparent network gateway (i.e., a single entry and exit point for all traffic) and distributes traffic while scaling your Trellix vIPS appliances with the demand.
The GWLB and its registered virtual appliance instances exchange application traffic using the VXLAN protocol.
The following table lists the requirements of different vIPS solution components for the integration of Trellix vIPS with Azure GWLB.
Component | Azure Virtual Machine Type | Software Requirements | Network Requirements |
|---|---|---|---|
Trellix IPS Manager | D2s_v3 | Trellix IPS Manager image | 1 Network Interface (management subnet) |
Virtual IPS Sensor | F4s_v2 | Virtual IPS Sensor image | 1 Network Interface for both management and data subnet |
Load Balancer | Gateway | Azure | 1 |
Protected virtual machines | Any | Customer Supplied | 1 or more (as required) |
The following table lists the requirements to deploy vIPS in the GWLB-based Azure environment.
Requirement | Purpose | Role |
|---|---|---|
Azure GUI access | To launch Trellix vIPS and configure the setup | Privilege: Contributor |
Virtual IPS Sensor | To install a Virtual IPS Sensor | Privilege: Contributor |
Gateway Load Balancer | To forward the traffic flow to the Sensor | Privilege: Contributor |
Web server (or) Virtual Machines to be protected | Any | Privilege: OS Administrator |
The following commands are added to facilitate Trellix vIPS integration with Azure GWLB:
Command | Description |
|---|---|
| This command displays information about HealthCheck |
Command | Description |
|---|---|
| This command is used to set the HealthCheck status. |
| This command displays the status of HealthCheck. |
For more information, Integrating Trellix vIPS with Azure Gateway Load Balancer in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.
Enhancements
This release of the Trellix Intrusion Prevention System includes the following enhancements:
Public GTI communication interface upgrade for IP and URL Reputation
Starting with this release, Trellix IPS uses ECHDE ciphers to connect to Public GTI for IP and URL Reputation. During the configuration, the Sensor will receive ECDSA based client certificate bundle from the Manager. The ECDSA certificates expire annually. The renewed client certificate bundle are updated in the IPS Update Server. The Manager downloads the certificate bundle to send it to the Sensor whenever the client certificate is expired. For any issues, contact Trellix support.
The following CLI command is updated with new GTI counters:
Command | Description |
|---|---|
| The command displays the status of various download and upload operations from the Manager to Sensor and from the Sensor to Manager. It also lists the number of times you operated and status of your previous attempt to operate. The time of the command execution is also listed. |
You can verify certificate transfers through User Activities logged in the Manager. If there are any issues such as invalid certificates, missing certificates, or DNS configuration issues, you can view the detailed information through several system generated Faults displayed in the Manager.
For more information, see Manager critical faults in Trellix Intrusion Prevention System 11.1.x Product Guide.
Support for import of multiple licenses in the Manager
Starting with this release of 11.1, the Manager facilitates the import of multiple licenses (SKU files in the .zip format). You can import multiple licenses in the System, Proxy Decryption, and Virtual Sensors tab of the Licenses page in → → . When importing multiple license files, if they contain any combination of pre-existing, expired, or invalid licenses, the Manager will skip those files with an appropriate Error message, and valid license files will be imported.
![]() |
Note
Upgrade licenses are not supported for multiple imports. You must import the upgrade license file individually.
When the license(s) assigned to the vIPS device expires and sufficient unassigned license(s) are available in the pool, license(s) will be auto-assigned to the device.
For more information, Add license to the Manager in Trellix Intrusion Prevention System 11.1.x Installation Guide and Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.
Syslog server configuration enhancement
Starting with this release, you can configure the syslog server timeout value in minutes using 'notifications.syslog.tcptimeout'. When 'notifications.syslog.tcptimeout' is configured, the Manager reconnects to the syslog server at given intervals. If the time since the last connection re-establishment to the syslog server exceeds the configured timeout, the Manager will re-establish the connection before sending the syslog message. However, if 'notifications.syslog.tcptimeout' is not configured, the Manager will not reconnect once the trust has been established. After configuring 'notifications.syslog.tcptimeout', you must restart the Manager service for the changes to take effect.
Note
The IPS Manager can now send 16384 bytes in a single syslog message.
For more information, see Configure a Syslog server in Trellix Intrusion Prevention System 11.1.x Product Guide.
Support for DNS protocol for layer 7 data collection
Starting with this release of 11.1, Trellix IPS supports collecting layer 7 data for DNS request fields and the export of the DNS request based L7 metadata to other Trellix products, such as Trellix Network Investigator (NI).
You can navigate to → → → → → → and enable L7 data collection for DNS request fields per interface or sub-interface of selected Sensors.
Note
To view or customize DNS settings, you need to use Manager and Sensor that are running on 11.1 Minor 6 release versions, and a compatible signature set (11.10.19.7 or above) with DNS related attack signatures.
Only DNS request based fields can be enabled, disabled, or customized for Layer 7 data collection in the Manager.
For more information, Enable Layer 7 Data Collection for an interface or sub-interface in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhancements in Trellix IPS Manager
With this release of 11.1, several enhancements have been made to speed up Manager operations and improve its functionality and stability. Few of the key areas of enhancement are as follows:
From this release onwards, the fields in the Capture Packets section (for both Attack and Pre-Attack and Post-Attack) are set to disabled by default for all attacks of Informational and low (1) severity levels, and not available for configuration for some specific attack IDs. This is done to prevent certain scenarios of excessive packet log generation.
Note
If you are running a Manager version lower than 11.1 Minor 6 release in which the packet logging is already enabled for any of the specific attack IDs (either inherit-enabled by signature set or manually enabled by the user) and you perform an upgrade, the fields in the Capture Packets section will still be visible during attack details configuration.
The Manager makes asynchronous requests to the Trellix IPS Update Server, and in case of connectivity errors, it logs the error messages in the updateserver.log file for troubleshooting purposes. This is done to enhance the overall performance and stability of the Manager UI.
Several log files have been added for troubleshooting purposes, such as c3p0.log, c3p0monitor.log alertRate.log, and packetlogRate.log.
For more information, see Configure attack details and System Log Files in Trellix Intrusion Prevention System 11.1.x Product Guide.
Alert Pruning and Database Tuning enhancement
Starting with this release of 11.1, When data tuning gets triggered while the alert pruning operation is in progress, data tuning waits for permission and resumes after alert pruning is complete. Similarly, when alert pruning gets triggered while the data tuning operation is in progress, alert pruning waits for permission and resumes after data tuning is complete. This enhancement prevents overlapping and failure scenarios of data tuning and alert pruning.
For more information, see Alert Pruning and Database Tuning in Trellix Intrusion Prevention System 11.1.x Product Guide.
CA-signed certificate file size enhancement
Starting with this release, the CA certificate file size has been increased to support more than 2046 bytes.
For more information, see Import the CA-signed certificate in Trellix Intrusion Prevention System 11.1.x Product Guide.
Terminology updates in the UI
Navigation Path | Prior to 11.1.7.97/11.1.7.98 | 11.1.7.97/11.1.7.98 and later |
|---|---|---|
→ → | The option available: Next Generation Reports | The option is renamed to Custom Reports |
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.6 which includes additional security against new vulnerabilities and bug fixes.
JDK and Java upgrade
Starting with this release of 11.1, the IPS Manager uses JDK and Java version 1.8.0_412 which includes additional security against new vulnerabilities.
Apache Tomcat server upgrade
Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.88. This server update provides a collection of security fixes.
.png)