EDRF uses specific network ports to connect to DXL and Trellix EDR client.
Note
Make sure your network settings are configured correctly and SSL traffic inspection is disabled on URLs or IP addresses.
URL allow list
You must allow access to the following URLs to ensure that components can connect to cloud services and function correctly.
URL |
|---|
UI URLs:
|
API URLs:
|
Common URLs:
|
Important
For ports and URLs needed for ePO - SaaS communication, see the Trellix Knowledge Base article, Ports and URLs needed for Trellix ePolicy Orchestrator - SaaS communication through firewalls - KB90878.
Source | Destination | Port | Description | URL |
|---|---|---|---|---|
Browsers | Trellix EDR workspace | TCP 443 | Access Trellix EDR interface |
|
Endpoint —Trellix Agent | Enterprise DNS server | TCP/UDP 53 | Resolution of Trellix GTI URLs. |
|
Endpoint — Trellix EDR with Forensics Client | Trellix EDR workspace | TCP 443 | Snapshots (default route, and recommended one) | https://api.soc.trellix.com/
|
All components | Enterprise NTP server | TCP 123 | Network time synchronization | |
Administrator workstation | ePO - On-prem | TCP 8443 | Required only during the Trellix EDR service installation to configure Trellix Agent. | |
Administrator workstation | ePO - SaaS | TCP 443 | ||
Endpoint — Phoenix Agent | Trellix EDR workspace | TCP 443 | Snapshot Agent, it detects proxy settings automatically. | https://api.soc.trellix.com/
|
Source | Destination | Port | Description | URL |
|---|---|---|---|---|
Endpoint — Trellix Agent | ePO - On-prem | TCP 80 TCP 443 | Policies download, Trellix system logs upload. | |
ePO - On-prem /Endpoint (Trellix Agent) | Endpoint (Trellix Agent) | TCP 8081 | Trellix Agent wake-up call /SADR/Peer-to-Peer/Relay. For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797. | |
ePO - On-prem /Endpoint (Trellix Agent) | Endpoint (Trellix Agent) | UDP 8082 | Super agent/agent update broadcast, Peer-to-Peer server discovery, RelayServer discovery. | |
Endpoint (Trellix Agent) | Endpoint (Trellix Agent) | UDP 8083 | RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open. | |
Endpoint (Trellix Agent) | ePO - On-prem /AH/Repos /Endpoint (Trellix Agent ) SADR | ICMP | Ping or Subnet distance calculation | |
Endpoint (Trellix Agent 5.8.x or DXL client) | DXL broker | TCP 8883 | DXL messaging | |
DXL broker | Trellix EDR workspace | TCP 443 | Send information to Trellix EDR workspace:
| https://api.soc.trellix.com/cloudproxy/databus/produce
|
DXL broker | IAM | TCP 443 | Authentication |
|
Trellix Endpoint | IAM | TCP 443 | Authentication |
|
ePO - On-prem | IAM | TCP 443 | Authentication |
|
ePO - On-prem | Trellix EDR workspace | TCP 443 | Queries and responses used in investigations (examples, queries to ePO - On-prem events and queries to SIEM). Currently, DXLsupports a bridge between cloud and on-premises for real-time queries and remediations. This behavior is expected to change in future DXLversions, where an alternate route is used for Snapshots. | https://api.soc.trellix.com/
|
ePO - On-prem | Endpoint (EDRF Client client) | Configurable by default 8088 and 8089 | Alternate route for snapshots (not by default, not recommended). | |
DXL broker | ePO - On-prem | TCP 443 | Policies download, Trellix system logs upload. | |
ePO - On-prem | DXL broker | TCP 8081 | Trellix Agent wake-up call. For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797. |
Source | Destination | Port | Description | URL |
|---|---|---|---|---|
Endpoint — Trellix Agent | ePO - SaaS | TCP 80 | Policies download, Trellix Agent system logs upload. | POD specific Implementation — ah-<pod>.manage.trellix.com. Only one URL per POD. Currently:
|
Trellix Agent handlers | TCP 443 | |||
ePO - SaaS | Endpoint (Trellix Agent) | TCP 8081 | Trellix Agent wakeup call/ SADR (not supported) /Peer-to-Peer/ Relay. For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797. | |
TCP 8082 | Peer-to-peer server discovery, RelayServer discovery. | |||
TCP 8083 | RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open. | |||
Endpoint — (Trellix Agent 5.8.2 or DXL client) | ePO - SaaS | TCP 443 | DXL messaging (ICMP is not supported) and real-time search queries. | POD specific implementation — dxl-<pod>.manage.trellix.com. Only one URL per POD. Currently:
|
Endpoint — (Trellix Agent 5.8.2 or DXL client) | Trellix EDR workspace | TCP 443 | Send information to Trellix EDR workspace:
|
For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797.