New features
This release of Trellix Intrusion Prevention System includes the following new features:
Introduction to Trellix Virtual Intrusion Prevention System Sensor - IPS-VM5000 and support on Kernel-based Virtual Machine (KVM)
This release of 11.1 introduces Trellix Virtual IPS Sensor IPS-VM5000. This Sensor operates at 5 Gbps throughput.
The Sensors are flexible enough to adapt to the security needs of any enterprise environment. When deployed at key network access points, they provide real-time monitoring on high traffic loads to detect malicious activity and respond to the malicious activity as configured by the administrator.
The IPS-VM5000 Sensor supports all the features supported by IPS-VM600. This release also introduces support for Trellix vIPS Sensor deployments (IPS-VM600 and IPS-VM5000) on KVM.
The table describes the hardware and server requirements for the vIPS deployments in the ESXi server and KVM:
Sensor model | Virtualization Plaftorm | Hardware |
|---|---|---|
IPS-VM5000 |
|
|
IPS-VM600 |
|
|
You can deploy the Sensor in the following modes:
SPAN mode
Inline fail-closed mode
For inline fail-open mode, you must use an external Active Fail-Open Bypass Kit.
Note
Tap mode is not applicable to Virtual Sensors.
To know the list of features supported by IPS-VM5000/IPS-VM600, refer to the section Features supported by a Virtual Sensor.
For information on IPS-VM5000 Sensor capacity, refer to the section Virtual IPS Sensor capacity by model number.
To achieve expected performance on IPS-VM5000 and IPS-VM600 in KVM, you need to install and configure Open Virtual Switch (OVS) with Data Plane Development Kit (DPDK) on the host machine and assign the OVS-DPDK ports to the Trellix vIPS Sensor ports. To do, refer to the section Install and configure OVS with DPDK on host machine.
Note
IPS-VM5000 deployments are currently not supported on public cloud.
Trellix IPS Manager deployments are currently not supported on KVM.
For more information, refer to Trellix Virtual Intrusion Prevention System 11.1.x Product Guide and Trellix Intrusion Prevention System 11.1.x Product Guide.
Integrating Trellix vIPS with AWS Gateway Load Balancer
This release of 11.1 introduces integration of Trellix vIPS with AWS Gateway Load Balancer. The Gateway Load Balancer (GWLB) enables you to deploy, scale, and manage virtual appliances, such as firewall, intrusion prevention systems, and deep packet inspection systems. The GWLB and its registered virtual appliance instances exchange application traffic using the GENEVE protocol on port 6081.
GWLB uses Gateway Load Balancer endpoint (GWLBe) to securely exchange traffic across VPC boundaries. A GWLBe is a VPC endpoint that provides private connectivity between virtual appliances in the service provider VPC and application servers in the service consumer VPC. You can deploy GWLB in the same VPC as the Trellix vIPS appliances. You must register the Trellix vIPS appliances with a target group for the GWLB. Traffic to and from a GWLBe is configured using route tables.
The following table lists the requirements of different vIPS solution components for the integration of Trellix vIPS with AWS GWLB.
Component | AWS Instance Type | Software Requirements | Network Requirements |
|---|---|---|---|
Manager | c5.xlarge or c6i.xlarge | Manager AMI | 1 Network Interface (management subnet) |
Sensor | c5.xlarge or c6i.xlarge | Sensor AMI | 1 Network Interface (management and data subnet) |
You can find the cost estimates for your deployments from My Estimate.
The following section lists the requirements to deploy AWS GWLB.
Requirement | Purpose | Privileges/ Other requirements |
|---|---|---|
Route Table | To route the traffic flow to Sensor through Endpoint and load balancer | |
Endpoint Service | To create Endpoint |
|
Endpoint | To forward the traffic flow to load balancer | To specify Endpoint, Endpoint Service is mandatory. |
Gateway Load Balancer | To forward the traffic flow to the Sensor | Trellix recommends you to have at least two availability zones prior to deployment. |
Target group | To register the required Sensor to receive traffic | The Sensor should use same VPC as Manager. |
AWS GUI access | To launch Trellix vIPS AMIs and configure setup |
|
Trellix IPS Manager AMI | To deploy the Manager instance | |
Trellix vIPS Sensor AMI | To deploy the Virtual IPS Sensor instance |
The following table lists the ports for security group settings required to integrate Trellix vIPS with AWS GWLB.
Important
For more information about ports and traffic destinations used by Trellix IPS, see KB59342.
Ports | Purpose | Source/Destination | ||
|---|---|---|---|---|
Manager | Inbound rules | 8501–8504, 8506–8510 | TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Sensor |
443 | TCP port used for web UI access on the Manager. | --- | ||
TCP port used to establish trust between the Manager and Sensor | Sensor | |||
22 | TCP port used for Manager CLI access (via SSH). | Sensor | ||
Outbound Rules | 8500 | UDP port used by the Manager to make real-time configuration changes on the Sensor. | Sensor | |
Sensor | Inbound rules | 8500 | UDP port used by the Manager to make real-time configuration changes on the Sensor. | Manager |
22 | TCP port used for Sensor CLI access. | Manager | ||
6081 | UDP protocol for all incoming traffic with GENVE header. | GWLB | ||
9001 | TCP port used to send Health Check details between Sensor and GWLB. | GWLB | ||
Outbound Rules | 8501-8504, 8506-8510 | TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Manager | |
443 | TCP Port is used for vIPS Sensor registration onto the Manager. | Manager |
The following commands are added to facilitate Trellix vIPS integration with AWS GWLB:
Command | Description |
|---|---|
| This command clears HealthCheck counters. |
| This command displays information about GWLB IP address and all details related to HealthCheck. |
For more information, see Integrating Trellix vIPS with AWS Gateway Load Balancer in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.
vIPS license enhancements
Starting with this release of 11.1, the Manager supports licensing of both VM5000 and VM600 Sensors. Virtual Sensors require a software license to activate the baseline throughput of 5 Gbps and 1 Gbps on VM5000 and VM600 Sensors respectively. The license is provided as a .zip or .jar file. The procured license contains the details of the Sensor's throughput. The Manager checks the compliance periodically to check the number of licenses against the Sensor's throughput.
In case of the VM5000 Sensor, 5 active licenses each of 1 Gbps is required to achieve the throughput of the Sensor. For VM600 Sensor, only 1 active 1 Gbps license is required.
Note
If you are using any VM600 or VM5000 Sensor and plan to upgrade the Manager to 11.1.7.41 or later versions, you must assign 1 license to each VM600 and 5 licenses to each VM5000 Sensor instance. Without the license assignment, you cannot deploy signature sets and policy updates to the Sensor.
In this release of the Manager, licenses for Clusters in public cloud is not supported.
You can upload the license from the Licenses page in the Manager. In the Manager, go to → → → and click Virtual Sensors tab. Here, you can add a license in the Manager, assign a license to the Sensor, unassign a license from the Sensor, and remove a license from the Manager.
You can assign/unassign licenses through the following nodes in the Manager:
VM600 Sensors - License column of Device Manager, Device Details section of <Device_Name> panel, Summary, and Licenses.
VM5000 Sensors - License column of Device Manager, Device Details section of <Device_Name> panel, and Summary.
For more information, see Managing licenses for Virtual Sensors in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.
Integration with Trellix Investigation Analysis
Trellix Investigation Analysis (IA) is a security analytics solution that allows the analysis of alerts and network metadata gathered from all devices connected to it. IA provides a high-level view of the network metadata gathered over customizable dashboards supporting multiple configurations. It thus enables users to have a metadata-based view of network activities and search indexed metadata from various network protocols, which allows them to zero down on threat information critical for performing further investigation.
Starting with this release of 11.1, Trellix IPS offers integration capability with IA appliances or IA cluster, and exports netflow records and Layer 7 metadata from IPS Sensors, and alert data from IPS Manager to IA as per the configuration and filter parameters set on the IA. The alert data, L7 metadata information, and flow records exported by Trellix IPS are displayed on the Dashboard of IA's Web UI which you can review and analyze further for the detection and analysis of network threats.
You need to perform the following steps to enable integration with Trellix IA:
Create Client Profile using the IA Command Line Interface (CLI). During the configuration of the Client Profile, you can setup specific alert severity threshold and enable protocols for L7 metadata information which you want to be exported to IA, as per your requirement.
Note
Currently, IPS Sensors support the export of L7 metadata related to HTTP, HTTPS, SMTP, and FTP protocols only to IA.
Create Client Group on the IA CLI which enables you to assign the required Client Profile to it. A hash token value of 32 bytes is also generated on the completion of Client Group configuration task on the IA CLI, which is used by Trellix IPS for authentication purpose.
Note
You can create up to 20 Client Profiles and 10 Client Groups on an IA appliance based on your requirement.
Configure the required Client Groups created on the IA CLI, which includes adding details such as Client Group name, IP address of the associated IA appliance, and the authentication hash token, in the Manager.
Enable the association of the Client Group configured in the Manager at the domain level or device level.
Note
You can configure multiple Client Groups in the Manager and enable their association per-domain or per-Sensor basis.
The following tabs are available for enabling IA integration in the Manager:
Navigation path | Description | |
|---|---|---|
At Global-level | → → → → → | To configure the Client Group details in the Manager |
→ → → → → | To enable association of any Client Group for the admin domain as well as child domains NoteIf you enable the IA integration at an admin domain level, all child domains and the Sensors attached to these domains inherit this settings. However, you can configure any child domain with a different Client Group as per your network requirement. Consequently, the Sensors attached to that domain will inherit the same settings, unless you opt for enabling the association of a separate Client Group with different configurations for any specific Sensor within that domain. | |
At Device-level | → → → → → → | To enable association of any Client Group per Sensor basis within any domain |
Note
You must configure the Client Group details in the Manager to enable its association at the domain or device level. You can configure any Client Group by using the Client Group Configuration tab available at the Global-level, or on the Client Group Association tabs available at both domain and device levels.
Following is the list of Sensor CLI commands that have been added in support of Trellix IA integration:
Command | Description |
|---|---|
| This command displays IA feature status and communication status between Trellix IPS and Trellix IA, along with other configuration details related to IA integration. |
| This command displays counter specifics related to IA config and metadata export. |
| This command clears all the IA config and metadata statistics-related counters in the Sensor. |
| This command displays internal statistics specifics related to netflow and L7 metadata from datapath side. |
For more information on Trellix IA integration, refer to the section Integration with Trellix Investigation Analysis in Trellix Intrusion Prevention System 11.1.x Integration Guide.
Enhancements
This release of Trellix Intrusion Prevention System includes the following enhancements:
Syslog and SNMP server configuration
Previously, SNMP and Syslog notification profiles were configured separately through the IPS Events, Faults, and User Activity sections. Starting with this release, a Server Configuration page has been added under → → → in the Manager and Central Manager. This page acts as a standard location to configure the server profiles. These server profiles can be used to configure the Syslog and SNMP notification profiles under IPS Events/Faults/User Activity.
Note
Previously, users were provided with an option to configure Syslog servers for IPS Events and User Activity related notifications via UDP/TCP/TCP over SSL. However, Fault notifications were configured to be communicated only through UDP channel. Starting with this release, users can choose UDP/TCP/TCP over SSL while configuring Syslog server for Fault notifications.
While configuring SNMP notifications, users now have the option to choose SHA256 Authentication Type and AES256 Encryption Type for improved security.
If you are upgrading the Manager to 11.1 Update 2 or later software versions, the Manager automatically lists any existing SNMP and Syslog servers under the respective tabs in this page. The server profile name is automatically assigned by the Manger in this format <Domain Name><event/fault/audit><profile number>. For example, you are upgrading the Manager from 11.1.7.3 to 11.1.7.41. The SNMP servers are configured for the admin domain named IPS-Denver and two child domains named IPS-Welton and IPS-Larimer. IPS-Denver has 3 existing profiles while IPS-Welton and IPS-Larimer have 2 existing profiles.
When you upgrade the Manager to 11.1.7.41 or later versions, this configuration is automatically mapped under the SNMP tab under each domain. User accessing the admin domain named IPS-Denver will be viewing the server profile names as IPS-Denverfault1, IPS-Denverfault2, and IPS-Denverfault3. User accessing the child domain IPS-Welton will be viewing 2 server profiles IPS-Weltonfault1 and IPS-Weltonfault2. Similarly, user accessing the child domain IPS-Larimer will be viewing 2 server profiles IPS-Larimerfault1 and IPS-Larimerfault2.
User accessing one domain will not be able to view the servers created in other domains.
In case user has used the same Syslog or SNMP server for IPS Events, Faults, and User Activity, three server profiles will created under the SNMP and Syslog tabs. Users can opt to delete the duplicate entries and have only one entry assigned to all the profiles. Before deleting the duplicate entries, ensure that the associated servers are not attached to any of the Syslog or SNMP notification profiles.
Note
Before upgrading the Manager to 11.1 Update 2 or later software versions, if user has created a Syslog server (under IPS Events page) at admin domain level and same server is used in child domains, post upgrade, the user sees profiles with the same name at both admin and child domain levels. In this case, if the user plans to remove one of the profiles from any of the domains and tries creating or updating a profile with the old name in the same domain or any other domain, an error is displayed stating the name is already in use.
For more information, refer to the section Configure SNMP and Syslog servers in Trellix Intrusion Prevention System 11.1.x Product Guide.
Signature set version validation during its download or manual import
The signature set's major version (i.e, its first two digits) should be equal to or higher than the IPS Manager's major version (i.e, its first two digits) for it to be compatible with the Manager. Starting with this release of 11.1, the Manager performs validation based on the signature set file's major version being equal to or higher than its major version and prevents the download or manual import of any incompatible signature set version that does not match the validation criteria. For example, any Manager running on version 11.1 Update 2 supports the download and deployment of signature set version 11.9.x.x, but not signature set version 10.8.x.x or 9.8.x.x.
For more information, refer to the section Signature sets in Trellix Intrusion Prevention System 11.1.x Product Guide.
Terminology updates in the UI
This release contains the following terminology updates in the Manager UI:
Option | Prior to 11.1.7.41 | 11.1.7.41 and later |
|---|---|---|
Syslog Server Configuration | To configure a Syslog Server profile under IPS Events, navigate to → → → → → . Under the Syslog Notification Profiles section, click
| To configure a Syslog Server profile, navigate to → → → → and click Syslog tab.
Users can use these server profiles to configure the Syslog Notification Profiles under IPS Events/Faults/User Activity. |
To configure a Syslog Server profile under Faults, navigate to → → → → → . Add or update the server details and click Save. | The Server Configuration page acts as the standard page for configuring the Syslog and SNMP Server profiles. Hence, the terminology updates remain the same as above. | |
To configure a Syslog Server profile under User Activity, navigate to → → → → → . Add or update the server details and click Apply. | The Server Configuration page acts as the standard page for configuring the Syslog and SNMP Server profiles. Hence, the terminology updates remain the same as above. | |
SNMP Server Configuration | To configure SNMP Server profile, navigate to → → → → → . Under the SNMP Servers section, click
| To configure SNMP Server profile, navigate to → → → → and click SNMP tab.
Users can use these server profiles to configure the SNMP Notification Profile under IPS Events/Faults/User Activity. |
Import a CSV file containing Domains | To import a CSV file, navigate to → → → → → , go to Other Actions menu and click Import. | To import a CSV file, navigate to → → → → → , go to Other Actions menu and click Import Custom. |
IPS CLI enhancements
Along with commands related to Trellix IA integration documented in the What's new section, the following Sensor CLI command is updated:
Command | Description |
|---|---|
| Displays the datapath attack response related statistics. With this release, it also displays the number of attacks superseded by alert-correlation. |
For more information, see CLI Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.12 that includes additional security against new vulnerabilities.
JDK upgrade
Starting with this release of 11.1, the IPS Manager uses JDK version 8u362 that includes additional security against new vulnerabilities.
.png)
.png)
.jpg)