What's new

Prev Next

IAM domain URL updates

The Identity and Access Management (IAM) domain URLs used by Trellix Intrusion Prevention System have been updated. As a user, you must update the destination URLs in your firewall configuration to ensure uninterrupted communication to the IAM service. The following table outlines the changes to the IAM domain URLs:

Existing destination URL

Updated destination URL

iam.skyhigh.cloud

iam-rs.skyhigh.cloud

iam.cloud.trellix.com

iam-rs.cloud.trellix.com

For information on the updated destination URLs, refer to the section Set the desktop firewall in Trellix Intrusion Prevention System 11.1.x Product Guide.

New features

This release of the Trellix Intrusion Prevention System includes the following new feature:

Integrating Trellix vIPS with Azure Gateway Load Balancer

This release of 11.1 introduces the integration of Trellix vIPS with Azure Gateway Load Balancer. The Gateway Load Balancer (GWLB) is an SKU of the Azure Load Balancer portfolio catered for high performance and high availability scenarios with Trellix Network Virtual Appliances (NVAs). GWLB enables you to deploy, scale, and manage virtual appliances, such as firewalls, intrusion prevention systems, and deep packet inspection systems. It combines a transparent network gateway (i.e., a single entry and exit point for all traffic) and distributes traffic while scaling your Trellix vIPS appliances with the demand.

The GWLB and its registered virtual appliance instances exchange application traffic using the VXLAN protocol.

The following table lists the requirements of different vIPS solution components for the integration of Trellix vIPS with Azure GWLB.

Component

Azure Virtual Machine Type

Software Requirements

Network Requirements

Trellix IPS Manager

D2s_v3

Trellix IPS Manager image

1 Network Interface (management subnet)

Virtual IPS Sensor

F4s_v2

Virtual IPS Sensor image

1 Network Interface for both management and data subnet

Load Balancer

Gateway

Azure

1

Protected virtual machines

Any

Customer Supplied

1 or more (as required)

The following table lists the requirements to deploy vIPS in the GWLB-based Azure environment.

Requirement

Purpose

Role

Azure GUI access

To launch Trellix vIPS and configure the setup

Privilege: Contributor

Virtual IPS Sensor

To install a Virtual IPS Sensor

Privilege: Contributor

Gateway Load Balancer

To forward the traffic flow to the Sensor

Privilege: Contributor

Web server (or) Virtual Machines to be protected

Any

Privilege: OS Administrator

The following commands are added to facilitate Trellix vIPS integration with Azure GWLB:

Normal Mode

Command

Description

show cloud-gwlb status

This command displays information about HealthCheck



Debug Mode

Command

Description

set cloud-gwlb healthcheck <disable | enable>

This command is used to set the HealthCheck status.

show cloud-gwlb healthcheck status

This command displays the status of HealthCheck.



For more information, Integrating Trellix vIPS with Azure Gateway Load Balancer in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This release of the Trellix Intrusion Prevention System includes the following enhancements:

Public GTI communication interface upgrade for IP and URL Reputation

Starting with this release, Trellix IPS uses ECHDE ciphers to connect to Public GTI for IP and URL Reputation. During the configuration, the Sensor will receive ECDSA based client certificate bundle from the Manager. The ECDSA certificates expire annually. The renewed client certificate bundle are updated in the IPS Update Server. The Manager downloads the certificate bundle to send it to the Sensor whenever the client certificate is expired. For any issues, contact Trellix support.

The following CLI command is updated with new GTI counters:

Normal Mode

Command

Description

downloadstatus

The command displays the status of various download and upload operations from the Manager to Sensor and from the Sensor to Manager. It also lists the number of times you operated and status of your previous attempt to operate. The time of the command execution is also listed.



You can verify certificate transfers through User Activities logged in the Manager. If there are any issues such as invalid certificates, missing certificates, or DNS configuration issues, you can view the detailed information through several system generated Faults displayed in the Manager.

For more information, see Manager critical faults in Trellix Intrusion Prevention System 11.1.x Product Guide.

Support for import of multiple licenses in the Manager

Starting with this release of 11.1, the Manager facilitates the import of multiple licenses (SKU files in the .zip format). You can import multiple licenses in the System, Proxy Decryption, and Virtual Sensors tab of the Licenses page in Manager<Admin Domain Name>Setup . When importing multiple license files, if they contain any combination of pre-existing, expired, or invalid licenses, the Manager will skip those files with an appropriate Error message, and valid license files will be imported.

Warning dialog box
Warning dialog box


Note

  • Upgrade licenses are not supported for multiple imports. You must import the upgrade license file individually.

  • When the license(s) assigned to the vIPS device expires and sufficient unassigned license(s) are available in the pool, license(s) will be auto-assigned to the device.

For more information, Add license to the Manager in Trellix Intrusion Prevention System 11.1.x Installation Guide and Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

Syslog server configuration enhancement

Starting with this release, you can configure the syslog server timeout value in minutes using 'notifications.syslog.tcptimeout'. When 'notifications.syslog.tcptimeout' is configured, the Manager reconnects to the syslog server at given intervals. If the time since the last connection re-establishment to the syslog server exceeds the configured timeout, the Manager will re-establish the connection before sending the syslog message. However, if 'notifications.syslog.tcptimeout' is not configured, the Manager will not reconnect once the trust has been established. After configuring 'notifications.syslog.tcptimeout', you must restart the Manager service for the changes to take effect.

Note

The IPS Manager can now send 16384 bytes in a single syslog message.

For more information, see Configure a Syslog server in Trellix Intrusion Prevention System 11.1.x Product Guide.

Support for DNS protocol for layer 7 data collection

Starting with this release of 11.1, Trellix IPS supports collecting layer 7 data for DNS request fields and the export of the DNS request based L7 metadata to other Trellix products, such as Trellix Network Investigator (NI).

You can navigate to Devices<Admin Domain Name>Devices<Device Name>SetupAdvancedL7 Data Collection and enable L7 data collection for DNS request fields per interface or sub-interface of selected Sensors.

Note

  • To view or customize DNS settings, you need to use Manager and Sensor that are running on 11.1 Minor 6 release versions, and a compatible signature set (11.10.19.7 or above) with DNS related attack signatures.

  • Only DNS request based fields can be enabled, disabled, or customized for Layer 7 data collection in the Manager.

For more information, Enable Layer 7 Data Collection for an interface or sub-interface in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements in Trellix IPS Manager

With this release of 11.1, several enhancements have been made to speed up Manager operations and improve its functionality and stability. Few of the key areas of enhancement are as follows:

  • From this release onwards, the fields in the Capture Packets section (for both Attack and Pre-Attack and Post-Attack) are set to disabled by default for all attacks of Informational and low (1) severity levels, and not available for configuration for some specific attack IDs. This is done to prevent certain scenarios of excessive packet log generation.

    Note

    If you are running a Manager version lower than 11.1 Minor 6 release in which the packet logging is already enabled for any of the specific attack IDs (either inherit-enabled by signature set or manually enabled by the user) and you perform an upgrade, the fields in the Capture Packets section will still be visible during attack details configuration.

  • The Manager makes asynchronous requests to the Trellix IPS Update Server, and in case of connectivity errors, it logs the error messages in the updateserver.log file for troubleshooting purposes. This is done to enhance the overall performance and stability of the Manager UI.

  • Several log files have been added for troubleshooting purposes, such as c3p0.log, c3p0monitor.log alertRate.log, and packetlogRate.log.

For more information, see Configure attack details and System Log Files in Trellix Intrusion Prevention System 11.1.x Product Guide.

Alert Pruning and Database Tuning enhancement

Starting with this release of 11.1, When data tuning gets triggered while the alert pruning operation is in progress, data tuning waits for permission and resumes after alert pruning is complete. Similarly, when alert pruning gets triggered while the data tuning operation is in progress, alert pruning waits for permission and resumes after data tuning is complete. This enhancement prevents overlapping and failure scenarios of data tuning and alert pruning.

For more information, see Alert Pruning and Database Tuning in Trellix Intrusion Prevention System 11.1.x Product Guide.

CA-signed certificate file size enhancement

Starting with this release, the CA certificate file size has been increased to support more than 2046 bytes.

For more information, see Import the CA-signed certificate in Trellix Intrusion Prevention System 11.1.x Product Guide.

Terminology updates in the UI

Navigation Path

Prior to 11.1.7.97/11.1.7.98

11.1.7.97/11.1.7.98 and later

Analysis<Admin Domain Name>Event Reporting

The option available:

Next Generation Reports

The option is renamed to Custom Reports

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.11.6 which includes additional security against new vulnerabilities and bug fixes.

JDK and Java upgrade

Starting with this release of 11.1, the IPS Manager uses JDK and Java version 1.8.0_412 which includes additional security against new vulnerabilities.

Apache Tomcat server upgrade

Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.88. This server update provides a collection of security fixes.