What's new

Prev Next

New features

This release of Trellix Intrusion Prevention System includes the following new features:

Introduction to Trellix Virtual Intrusion Prevention System Sensor - IPS-VM5000 and support on Kernel-based Virtual Machine (KVM)

This release of 11.1 introduces Trellix Virtual IPS Sensor IPS-VM5000. This Sensor operates at 5 Gbps throughput.

The Sensors are flexible enough to adapt to the security needs of any enterprise environment. When deployed at key network access points, they provide real-time monitoring on high traffic loads to detect malicious activity and respond to the malicious activity as configured by the administrator.

The IPS-VM5000 Sensor supports all the features supported by IPS-VM600. This release also introduces support for Trellix vIPS Sensor deployments (IPS-VM600 and IPS-VM5000) on KVM.

The table describes the hardware and server requirements for the vIPS deployments in the ESXi server and KVM:

Sensor model

Virtualization Plaftorm

Hardware

IPS-VM5000

  • ESXi:

    • ESXi 7.0 Update 3

    • ESXi 8.0

  • KVM: 2.12

  • Memory: 16 GB

  • Storage: 32 GB

  • CPU: 12 logical CPU cores

  • Ethernet ports of type vmxnet3 for ESXi or virtio for KVM:

    • 1 for management

    • 1 for response

    • 6 for monitoring

IPS-VM600

  • ESXi:

    • ESXi 7.0 Update 3

    • ESXi 8.0

  • KVM: 2.12

  • Memory: 8 GB

  • Storage: 8 GB

  • CPU: 4 logical CPU cores

  • Ethernet ports of type vmxnet3 for ESXi or virtio for KVM:

    • 1 for management

    • 1 for response

    • 6 for monitoring

You can deploy the Sensor in the following modes:

  • SPAN mode

  • Inline fail-closed mode

  • For inline fail-open mode, you must use an external Active Fail-Open Bypass Kit.

Note

Tap mode is not applicable to Virtual Sensors.

To know the list of features supported by IPS-VM5000/IPS-VM600, refer to the section Features supported by a Virtual Sensor.

For information on IPS-VM5000 Sensor capacity, refer to the section Virtual IPS Sensor capacity by model number.

To achieve expected performance on IPS-VM5000 and IPS-VM600 in KVM, you need to install and configure Open Virtual Switch (OVS) with Data Plane Development Kit (DPDK) on the host machine and assign the OVS-DPDK ports to the Trellix vIPS Sensor ports. To do, refer to the section Install and configure OVS with DPDK on host machine.

Note

  • IPS-VM5000 deployments are currently not supported on public cloud.

  • Trellix IPS Manager deployments are currently not supported on KVM.

For more information, refer to Trellix Virtual Intrusion Prevention System 11.1.x Product Guide and Trellix Intrusion Prevention System 11.1.x Product Guide.

Integrating Trellix vIPS with AWS Gateway Load Balancer

This release of 11.1 introduces integration of Trellix vIPS with AWS Gateway Load Balancer. The Gateway Load Balancer (GWLB) enables you to deploy, scale, and manage virtual appliances, such as firewall, intrusion prevention systems, and deep packet inspection systems. The GWLB and its registered virtual appliance instances exchange application traffic using the GENEVE protocol on port 6081.

GWLB uses Gateway Load Balancer endpoint (GWLBe) to securely exchange traffic across VPC boundaries. A GWLBe is a VPC endpoint that provides private connectivity between virtual appliances in the service provider VPC and application servers in the service consumer VPC. You can deploy GWLB in the same VPC as the Trellix vIPS appliances. You must register the Trellix vIPS appliances with a target group for the GWLB. Traffic to and from a GWLBe is configured using route tables.

The following table lists the requirements of different vIPS solution components for the integration of Trellix vIPS with AWS GWLB.

Component

AWS Instance Type

Software Requirements

Network Requirements

Manager

c5.xlarge or c6i.xlarge

Manager AMI

1 Network Interface (management subnet)

Sensor

c5.xlarge or c6i.xlarge

Sensor AMI

1 Network Interface (management and data subnet)

You can find the cost estimates for your deployments from My Estimate.

The following section lists the requirements to deploy AWS GWLB.

Requirement

Purpose

Privileges/ Other requirements

Route Table

To route the traffic flow to Sensor through Endpoint and load balancer

Endpoint Service

To create Endpoint

  • Specify the subnets

  • Specify the Loadbalancer type as Gateway

Endpoint

To forward the traffic flow to load balancer

To specify Endpoint, Endpoint Service is mandatory.

Gateway Load Balancer

To forward the traffic flow to the Sensor

Trellix recommends you to have at least two availability zones prior to deployment.

Target group

To register the required Sensor to receive traffic

The Sensor should use same VPC as Manager.

AWS GUI access

To launch Trellix vIPS AMIs and configure setup

  • Identify the AMI instance for deployment

  • Identify the instances to be protected

  • To create and manage resources in AWS you require any of the following:

    • IAM (Identity and Access Management) user account with appropriate permissions

    • AWS access key and secretkey

Trellix IPS Manager AMI

To deploy the Manager instance

Trellix vIPS Sensor AMI

To deploy the Virtual IPS Sensor instance

The following table lists the ports for security group settings required to integrate Trellix vIPS with AWS GWLB.

Important

For more information about ports and traffic destinations used by Trellix IPS, see KB59342.

Ports

Purpose

Source/Destination

Manager

Inbound rules

8501–8504, 8506–8510

TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Sensor

443

TCP port used for web UI access on the Manager.

---

TCP port used to establish trust between the Manager and Sensor

Sensor

22

TCP port used for Manager CLI access (via SSH).

Sensor

Outbound Rules

8500

UDP port used by the Manager to make real-time configuration changes on the Sensor.

Sensor

Sensor

Inbound rules

8500

UDP port used by the Manager to make real-time configuration changes on the Sensor.

Manager

22

TCP port used for Sensor CLI access.

Manager

6081

UDP protocol for all incoming traffic with GENVE header.

GWLB

9001

TCP port used to send Health Check details between Sensor and GWLB.

GWLB

Outbound Rules

8501-8504, 8506-8510

TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Manager

443

TCP Port is used for vIPS Sensor registration onto the Manager.

Manager

The following commands are added to facilitate Trellix vIPS integration with AWS GWLB:

Normal Mode

Command

Description

clear cloud-gwlb status

This command clears HealthCheck counters.

show cloud-gwlb status

This command displays information about GWLB IP address and all details related to HealthCheck.



For more information, see Integrating Trellix vIPS with AWS Gateway Load Balancer in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

vIPS license enhancements

Starting with this release of 11.1, the Manager supports licensing of both VM5000 and VM600 Sensors. Virtual Sensors require a software license to activate the baseline throughput of 5 Gbps and 1 Gbps on VM5000 and VM600 Sensors respectively. The license is provided as a .zip or .jar file. The procured license contains the details of the Sensor's throughput. The Manager checks the compliance periodically to check the number of licenses against the Sensor's throughput.

In case of the VM5000 Sensor, 5 active licenses each of 1 Gbps is required to achieve the throughput of the Sensor. For VM600 Sensor, only 1 active 1 Gbps license is required.

Note

  • If you are using any VM600 or VM5000 Sensor and plan to upgrade the Manager to 11.1.7.41 or later versions, you must assign 1 license to each VM600 and 5 licenses to each VM5000 Sensor instance. Without the license assignment, you cannot deploy signature sets and policy updates to the Sensor.

  • In this release of the Manager, licenses for Clusters in public cloud is not supported.

You can upload the license from the Licenses page in the Manager. In the Manager, go to Manager<Admin Domain Name>SetupLicenses and click Virtual Sensors tab. Here, you can add a license in the Manager, assign a license to the Sensor, unassign a license from the Sensor, and remove a license from the Manager.

You can assign/unassign licenses through the following nodes in the Manager:

  • VM600 Sensors - License column of Device Manager, Device Details section of <Device_Name> panel, Summary, and Licenses.

  • VM5000 Sensors - License column of Device Manager, Device Details section of <Device_Name> panel, and Summary.

For more information, see Managing licenses for Virtual Sensors in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

Integration with Trellix Investigation Analysis

Trellix Investigation Analysis (IA) is a security analytics solution that allows the analysis of alerts and network metadata gathered from all devices connected to it. IA provides a high-level view of the network metadata gathered over customizable dashboards supporting multiple configurations. It thus enables users to have a metadata-based view of network activities and search indexed metadata from various network protocols, which allows them to zero down on threat information critical for performing further investigation.

Starting with this release of 11.1, Trellix IPS offers integration capability with IA appliances or IA cluster, and exports netflow records and Layer 7 metadata from IPS Sensors, and alert data from IPS Manager to IA as per the configuration and filter parameters set on the IA. The alert data, L7 metadata information, and flow records exported by Trellix IPS are displayed on the Dashboard of IA's Web UI which you can review and analyze further for the detection and analysis of network threats.

You need to perform the following steps to enable integration with Trellix IA:

  1. Create Client Profile using the IA Command Line Interface (CLI). During the configuration of the Client Profile, you can setup specific alert severity threshold and enable protocols for L7 metadata information which you want to be exported to IA, as per your requirement.

    Note

    Currently, IPS Sensors support the export of L7 metadata related to HTTP, HTTPS, SMTP, and FTP protocols only to IA.

  2. Create Client Group on the IA CLI which enables you to assign the required Client Profile to it. A hash token value of 32 bytes is also generated on the completion of Client Group configuration task on the IA CLI, which is used by Trellix IPS for authentication purpose.

    Note

    You can create up to 20 Client Profiles and 10 Client Groups on an IA appliance based on your requirement.

  3. Configure the required Client Groups created on the IA CLI, which includes adding details such as Client Group name, IP address of the associated IA appliance, and the authentication hash token, in the Manager.

  4. Enable the association of the Client Group configured in the Manager at the domain level or device level.

    Note

    You can configure multiple Client Groups in the Manager and enable their association per-domain or per-Sensor basis.

The following tabs are available for enabling IA integration in the Manager:

Navigation path

Description

At Global-level

Devices<Admin Domain Name>GlobalIPS Device SettingsIA IntegrationClient Group Configuration

To configure the Client Group details in the Manager

Devices<Admin Domain Name>GlobalIPS Device SettingsIA IntegrationClient Group Association

To enable association of any Client Group for the admin domain as well as child domains

Note

If you enable the IA integration at an admin domain level, all child domains and the Sensors attached to these domains inherit this settings. However, you can configure any child domain with a different Client Group as per your network requirement. Consequently, the Sensors attached to that domain will inherit the same settings, unless you opt for enabling the association of a separate Client Group with different configurations for any specific Sensor within that domain.

At Device-level

Devices<Admin Domain Name>Devices<Device Name>SetupIA IntegrationClient Group Association

To enable association of any Client Group per Sensor basis within any domain

Note

You must configure the Client Group details in the Manager to enable its association at the domain or device level. You can configure any Client Group by using the Client Group Configuration tab available at the Global-level, or on the Client Group Association tabs available at both domain and device levels.

Following is the list of Sensor CLI commands that have been added in support of Trellix IA integration:

Debug Mode

Command

Description

show ia status

This command displays IA feature status and communication status between Trellix IPS and Trellix IA, along with other configuration details related to IA integration.

getiastats

This command displays counter specifics related to IA config and metadata export.

cleariastats

This command clears all the IA config and metadata statistics-related counters in the Sensor.

ianetflowstat

This command displays internal statistics specifics related to netflow and L7 metadata from datapath side.



For more information on Trellix IA integration, refer to the section Integration with Trellix Investigation Analysis in Trellix Intrusion Prevention System 11.1.x Integration Guide.

Enhancements

This release of Trellix Intrusion Prevention System includes the following enhancements:

Syslog and SNMP server configuration

Previously, SNMP and Syslog notification profiles were configured separately through the IPS Events, Faults, and User Activity sections. Starting with this release, a Server Configuration page has been added under Manager<Admin Domain Name>SetupNotification in the Manager and Central Manager. This page acts as a standard location to configure the server profiles. These server profiles can be used to configure the Syslog and SNMP notification profiles under IPS Events/Faults/User Activity.

Note

Previously, users were provided with an option to configure Syslog servers for IPS Events and User Activity related notifications via UDP/TCP/TCP over SSL. However, Fault notifications were configured to be communicated only through UDP channel. Starting with this release, users can choose UDP/TCP/TCP over SSL while configuring Syslog server for Fault notifications.

While configuring SNMP notifications, users now have the option to choose SHA256 Authentication Type and AES256 Encryption Type for improved security.

If you are upgrading the Manager to 11.1 Update 2 or later software versions, the Manager automatically lists any existing SNMP and Syslog servers under the respective tabs in this page. The server profile name is automatically assigned by the Manger in this format <Domain Name><event/fault/audit><profile number>. For example, you are upgrading the Manager from 11.1.7.3 to 11.1.7.41. The SNMP servers are configured for the admin domain named IPS-Denver and two child domains named IPS-Welton and IPS-Larimer. IPS-Denver has 3 existing profiles while IPS-Welton and IPS-Larimer have 2 existing profiles.

When you upgrade the Manager to 11.1.7.41 or later versions, this configuration is automatically mapped under the SNMP tab under each domain. User accessing the admin domain named IPS-Denver will be viewing the server profile names as IPS-Denverfault1, IPS-Denverfault2, and IPS-Denverfault3. User accessing the child domain IPS-Welton will be viewing 2 server profiles IPS-Weltonfault1 and IPS-Weltonfault2. Similarly, user accessing the child domain IPS-Larimer will be viewing 2 server profiles IPS-Larimerfault1 and IPS-Larimerfault2.

User accessing one domain will not be able to view the servers created in other domains.

In case user has used the same Syslog or SNMP server for IPS Events, Faults, and User Activity, three server profiles will created under the SNMP and Syslog tabs. Users can opt to delete the duplicate entries and have only one entry assigned to all the profiles. Before deleting the duplicate entries, ensure that the associated servers are not attached to any of the Syslog or SNMP notification profiles.

Note

Before upgrading the Manager to 11.1 Update 2 or later software versions, if user has created a Syslog server (under IPS Events page) at admin domain level and same server is used in child domains, post upgrade, the user sees profiles with the same name at both admin and child domain levels. In this case, if the user plans to remove one of the profiles from any of the domains and tries creating or updating a profile with the old name in the same domain or any other domain, an error is displayed stating the name is already in use.

For more information, refer to the section Configure SNMP and Syslog servers in Trellix Intrusion Prevention System 11.1.x Product Guide.

Signature set version validation during its download or manual import

The signature set's major version (i.e, its first two digits) should be equal to or higher than the IPS Manager's major version (i.e, its first two digits) for it to be compatible with the Manager. Starting with this release of 11.1, the Manager performs validation based on the signature set file's major version being equal to or higher than its major version and prevents the download or manual import of any incompatible signature set version that does not match the validation criteria. For example, any Manager running on version 11.1 Update 2 supports the download and deployment of signature set version 11.9.x.x, but not signature set version 10.8.x.x or 9.8.x.x.

For more information, refer to the section Signature sets in Trellix Intrusion Prevention System 11.1.x Product Guide.

Terminology updates in the UI

This release contains the following terminology updates in the Manager UI:

Option

Prior to 11.1.7.41

11.1.7.41 and later

Syslog Server Configuration

To configure a Syslog Server profile under IPS Events, navigate to Manager<Admin Domain Name>Setup NotificationIPS EventsSyslog. Under the Syslog Notification Profiles section, click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon or choose an existing profile and click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png icon. The Add a Syslog Notification Profile page appears.

  • To add a server profile, click the Add button next to the Target Server drop-down menu. Add a Syslog Server Profile page appears. Enter the server details and click Save.

  • To modify an existing server profile, click the Edit button next to the Target Server drop-down menu. Edit a Syslog Server Profile page appears. Update the server details and click Save.

  • To delete an unused server profile, click the Delete button next to the Target Server drop-down menu.

To configure a Syslog Server profile, navigate to Manager<Admin Domain Name>SetupNotificationServer Configuration and click Syslog tab.

  • To add a server profile, click the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon located at the at the bottom-left corner of the page. The Syslog Server Configuration Details panel opens to the right of the page. Enter the server details and click Save.

  • To modify an existing server profile, double-click the respective Target Server Profile Name. The Syslog Server Configuration Details panel opens to the right of the page. Update the server details and click Save.

  • To delete an unused server profile, select the profile and click the GUID-C5DB3A60-0A1C-4C8F-83A6-37EAFFF00433-low.jpg icon located at the at the bottom-left corner of the page.

Users can use these server profiles to configure the Syslog Notification Profiles under IPS Events/Faults/User Activity.

To configure a Syslog Server profile under Faults, navigate to Manager<Admin Domain Name>Setup NotificationFaultsSyslog. Add or update the server details and click Save.

The Server Configuration page acts as the standard page for configuring the Syslog and SNMP Server profiles. Hence, the terminology updates remain the same as above.

To configure a Syslog Server profile under User Activity, navigate to Manager<Admin Domain Name>Setup NotificationUser ActivitySyslog. Add or update the server details and click Apply.

The Server Configuration page acts as the standard page for configuring the Syslog and SNMP Server profiles. Hence, the terminology updates remain the same as above.

SNMP Server Configuration

To configure SNMP Server profile, navigate to Manager<Admin Domain Name>Setup NotificationIPS Events/Faults/User ActivitySNMP. Under the SNMP Servers section, click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon or choose an existing profile and GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png

  • Add or update the server details depending on the action you performed above and click Save.

To configure SNMP Server profile, navigate to Manager<Admin Domain Name>SetupNotificationServer Configuration and click SNMP tab.

  • To add a server profile, click the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon located at the at the bottom-left corner of the page. The SNMP Forwarder Configuration Details panel opens to the right of the page. Enter the server details and click Save.

  • To modify a server profile, double-click an existing profile. The SNMP Forwarder Configuration Details panel opens to the right of the page. Update the server details and click Save.

  • To delete a server profile, select the unused profile and click GUID-C5DB3A60-0A1C-4C8F-83A6-37EAFFF00433-low.jpg icon.

Users can use these server profiles to configure the SNMP Notification Profile under IPS Events/Faults/User Activity.

Import a CSV file containing Domains

To import a CSV file, navigate to Manager<Admin Domain Name>Setup NotificationIPS EventsSNMP, go to Other Actions menu and click Import.

To import a CSV file, navigate to Manager<Admin Domain Name>Setup NotificationIPS EventsSNMP, go to Other Actions menu and click Import Custom.

IPS CLI enhancements

Along with commands related to Trellix IA integration documented in the What's new section, the following Sensor CLI command is updated:

Debug Mode

Command

Description

rspstat

Displays the datapath attack response related statistics. With this release, it also displays the number of attacks superseded by alert-correlation.



For more information, see CLI Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.12 that includes additional security against new vulnerabilities.

JDK upgrade

Starting with this release of 11.1, the IPS Manager uses JDK version 8u362 that includes additional security against new vulnerabilities.