What's new

Prev Next

New features

This release of the Trellix Intrusion Prevention System includes the following new features:

Integrating Trellix vIPS with AWS Gateway Load Balancer Traffic Mirroring

This release of 11.1 introduces the integration of Trellix vIPS with AWS Gateway Load Balancer (GWLB) Traffic Mirroring. The Gateway Load Balancer (GWLB) with traffic mirroring enables you to deploy, scale, and manage virtual appliances, such as firewalls, intrusion prevention systems, and deep packet inspection systems. It is capable of inspecting traffic flowing into and out of protected AWS instances.

The GWLB with traffic mirroring and its registered virtual appliance instances exchange application traffic using the GENEVE protocol on port 6081. The solution has been designed to adapt to a public cloud environment and to scale with the requirements of your organization's subnets.

The following table lists the requirements of different vIPS solution components for the integration of Trellix vIPS with AWS GWLB traffic mirroring.

Component

AWS Instance Type

Software Requirements

Network Requirements

Manager

c7i.xlarge

Manager AMI

1 Network Interface

Sensor

c7i.xlarge

Sensor AMI

1 Network Interface

You can find the cost estimates for your deployments from My Estimate.

The following section lists the other component requirements to integrate Trellix vIPS with AWS GWLB traffic mirroring.

Requirement

Purpose

Privileges/ Other requirements

Endpoint Service

To create Endpoint

  • Specify the subnets

  • Specify the Loadbalancer type as Gateway

Endpoint

To forward the traffic flow to the load balancer

To specify the Endpoint, Endpoint Service is mandatory

Gateway Load Balancer

To forward the traffic flow to the Sensor

Trellix recommends you have at least two availability zones before deployment

Target group

To register the required Sensor to receive traffic

The Sensor should use the same VPC as the Manager

Traffic Mirroring

To forward the traffic flow from source to destination

Tip

Traffic Mirroring is available only on the following non-Nitro instance types: C4, D2, G3, G3s, H1, I3, M4, P2, P3, R4, X1, and X1e.

AWS GUI access

To launch Trellix vIPS AMIs and configure setup

  • Identify the AMI instance for deployment

  • Identify the instances to be protected

  • To create and manage resources in AWS you require any of the following:

    • IAM (Identity and Access Management) user account with appropriate permissions

    • AWS access key and secret key

Trellix IPS Manager AMI

To deploy the Manager instance

Trellix vIPS Sensor AMI

To deploy the Virtual IPS Sensor instance

The following table lists the ports for security group settings required to integrate Trellix vIPS with AWS GWLB traffic mirroring.

Important

For more information about ports and traffic destinations used by Trellix IPS, see KB59342.

Component

Rules

Ports

Purpose

Source/Destination

Manager

Inbound rules

8501–8504, 8506–8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Sensor

443

TCP port used for web UI access on the Manager.

---

TCP port is used to establish trust between the Manager and the Sensor

Sensor

22

TCP port used for Manager CLI access (via SSH).

Sensor

Outbound Rules

8500

The UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Sensor

Sensor

Inbound rules

8500

The UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Manager

22

TCP port used for Sensor CLI access.

Manager

6081

UDP protocol for all incoming traffic with GENEVE header.

GWLB

9001

TCP port used to send Health Check details between Sensor and GWLB.

GWLB

Outbound Rules

8501-8504, 8506-8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Manager

443

TCP Port is used for vIPS Sensor registration onto the Manager.

Manager

For more information, see Integrating AWS with GWLB Traffic Mirroring in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This release of the Trellix Intrusion Prevention System includes the following enhancements:

Support for RSA 4096-bit key self-signed and CA-signed certificates

Starting with this release of 11.1, trust between the Manager and Sensor could also be established by using self-signed and CA-signed certificates with a 4096-bit key.

For more information, see Managing Certificates for Manager and Sensor in Trellix Intrusion Prevention System 11.1.x Product Guide

Support for DNS response fields for layer 7 data collection

In 11.1 Minor 6 release, Trellix IPS provided support for the collection of layer 7 data for DNS request fields. In this release of 11.1, Trellix IPS extends its support for the collection layer 7 data for DNS response fields as well, and the export of DNS response based L7 metadata to other Trellix products, such as Trellix Network Investigator (NI).

You can navigate to Devices<Admin Domain Name>Devices<Device Name>SetupAdvancedL7 Data Collection page and enable L7 data collection for DNS request and response fields per interface or sub-interface of selected Sensors.

Note

To view or customize both DNS request and response fields, you need to use Manager and Sensor that are running on 11.1 Update 7 release versions, and a compatible signature set (11.10.23.3 and above) with DNS related attack signatures.

For more information, Enable Layer 7 Data Collection for an interface or sub-interface in Trellix Intrusion Prevention System 11.1.x Product Guide.

Introduction of SmartVision attacks

Trellix IPS now includes SmartVision attacks, a new set of native IPS attack definitions. These attacks generate base events that allow for more comprehensive and effective detection and correlation of network activities and potential threats, particularly for the lateral movement, when the integration between Trellix IPS and Trellix NI is enabled.

SmartVision attack definitions are included in the IPS signature set and automatically added into the default IPS policies (except Default DoS and Reconnaissance Only policy) with severity levels set to Low and higher, when a compatible signature set is in use.

When a SmartVision alert/attack is detected in any customer network environment, Manager sends the relevant alert data in JSON format to Trellix NI. NI consumes and utilizes these base events that enable it to perform more effective threat detection and correlation.

Note the following when you start working with SmartVision attacks:

  • You need a Manager and Sensor running on 11.1 Update 7 versions or later, along with a compatible signature set (11.10.23.3 and above) that includes SmartVision attack signatures.

  • There should be successful integration between Trellix IPS and Trellix NI. The Manager sends SmartVision attack signatures to only those Sensors that have integration with Trellix NI enabled at the domain or device level.

  • After changing NI integration configuration in selected Sensors over the Client Group Association tab (at both domain and device levels), you must deploy configuration changes to the Sensor

  • You can configure and update the settings of SmartVision attacks in the Policy<Admin Domain Name>Intrusion PreventionPolicy TypesIPS page. However, the Quarantine, Block, and Capture Packets (for Attack and Pre-Attack and Post Attack) sections are not available for configuration for the attack IDs related to SmartVision attacks in the Manager, as these options are disabled by the signature set.

For more information, see Harnessing SmartVision attacks for effective threat detection and response in Trellix Intrusion Prevention System 11.1.x Product Guide.

Terminology updates in the UI

Navigation Path

Prior to 11.1.7.111

11.1.7.111 and later

Devices<Admin Domain Name>Devices<Device Name>SetupAdvancedL7 Data Collection

The page includes Flows and Protocols/Fields sections and associated configuration options with one Save button.

The page includes two tabs - Flows and Protocols. Each tab includes a corresponding Save button.

In the Protocols/Fields section of the page:

  1. You can Enable, Disable, or Customize to personalize the settings for a specific protocol.

  2. Click GUID-64007DBE-A893-4782-83D1-485E177DBBDE-low.png icon to view the corresponding fields of a specific protocol. All fields are enabled by default.

  3. To disable a specific field for any protocol, you must first select Customize.

On the Protocols tab of the page:

  1. Use the expand_all_button.jpg button to view or customize the associated fields of all protocols listed on the tab. All fields are collapsed by default.

  2. Click Arrow.jpg icon to view or customize the corresponding fields of a specific protocol. All fields are enabled by default.

  3. To disable a specific field for any protocol, deselect the associated check-box.