Network ports and URL allow list

Prev Next

EDRF uses specific network ports to connect to DXL and Trellix EDR client.

Note

Make sure your network settings are configured correctly and SSL traffic inspection is disabled on URLs or IP addresses.

URL allow list

You must allow access to the following URLs to ensure that components can connect to cloud services and function correctly.

URL

UI URLs:

  • US-West data center — https://ui.soc.trellix.com

  • US-East data center — https://ui.soc.us-east-1.trellix.com

  • Frankfurt data center — https://ui.soc.eu-central-1.trellix.com

  • Sydney data center — https://ui.soc.ap-southeast-2.trellix.com

  • Canada data center — https://ui.soc.ca-central-1.trellix.com

  • Asia Pacific South data center — https://ui.soc.ap-south-1.trellix.com

API URLs:

  • US-West data center — https://api.soc.trellix.com/cloudproxy/databus/produce

  • US-East data center — https://api.soc.us-east-1.trellix.com/cloudproxy/databus/produce

  • Frankfurt data center — https://api.soc.eu-central-1.trellix.com/cloudproxy/databus/produce

  • Sydney data center — https://api.soc.ap-southeast-2.trellix.com/cloudproxy/databus/produce

  • Canada data center — https://api.soc.ca-central-1.trellix.com/cloudproxy/databus/produce

  • Asia Pacific South data center — https://api.soc.ap-south-1.trellix.com/cloudproxy/databus/produce

Note

Grant access to the URL for all DXL brokers where trace submission to the cloud is enabled.

Common URLs:

  • https://iam.cloud.trellix.com/iam/v1.0

  • https://iam-rs.cloud.trellix.com/iam-registration-service/v1.1

  • https://uam.api.trellix.com/prod/api/v1

  • https://content.endpoint.ccs-trellix.com

Important

For ports and URLs needed for ePO - SaaS communication, see the Trellix Knowledge Base article, Ports and URLs needed for Trellix ePolicy Orchestrator - SaaS communication through firewalls - KB90878.

Common paths for ePO - On-prem and ePO - SaaS implementations

Source

Destination

Port

Description

URL

Browsers

Trellix EDR workspace

TCP 443

Access Trellix EDR interface

  • https://ui.soc.trellix.com

    Note

    The URL changes for each tenant data center location. For details, see URL allow list.

  • https://*.oktacdn.com

  • https://mcafeecloud.okta.com

  • https://auth.ui.trellix.com

  • https://login.auth.ui.trellix.com

Endpoint —Trellix Agent

Enterprise DNS server

TCP/UDP 53

Resolution of Trellix GTI URLs.

  • tie.gti.trellix.com

  • tieserver.rest.gti.trellix.com

Endpoint — Trellix EDR with Forensics Client

Trellix EDR workspace

TCP 443

Snapshots (default route, and recommended one)

https://api.soc.trellix.com/

Note

The URL changes for each tenant data center location. For details, see URL allow list.

All components

Enterprise NTP server

TCP 123

Network time synchronization

Administrator workstation

ePO - On-prem

TCP 8443

Required only during the Trellix EDR service installation to configure Trellix Agent.

Administrator workstation

ePO - SaaS

TCP 443

Endpoint — Phoenix Agent

Trellix EDR workspace

TCP 443

Snapshot Agent, it detects proxy settings automatically.

https://api.soc.trellix.com/

Note

The URL changes for each tenant data center location. For details, see URL allow list.



Specific paths for ePO - On-prem implementations

Source

Destination

Port

Description

URL

Endpoint — Trellix Agent

ePO - On-prem

TCP 80

TCP 443

Policies download, Trellix system logs upload.

ePO - On-prem /Endpoint (Trellix Agent)

Endpoint (Trellix Agent)

TCP 8081

Trellix Agent wake-up call /SADR/Peer-to-Peer/Relay.

For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797.

ePO - On-prem /Endpoint (Trellix Agent)

Endpoint (Trellix Agent)

UDP 8082

Super agent/agent update broadcast, Peer-to-Peer server discovery, RelayServer discovery.

Endpoint (Trellix Agent)

Endpoint (Trellix Agent)

UDP 8083

RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open.

Endpoint (Trellix Agent)

ePO - On-prem /AH/Repos /Endpoint (Trellix Agent ) SADR

ICMP

Ping or Subnet distance calculation

Endpoint (Trellix Agent 5.8.x or DXL client)

DXL broker

TCP 8883

DXL messaging

DXL broker

Trellix EDR workspace

TCP 443

Send information to Trellix EDR workspace:

  • Trace data from Endpoints /EDRF Client client.

  • Real-time search responses from Endpoints /EDRF Client client.

https://api.soc.trellix.com/cloudproxy/databus/produce

Note

The URL changes for each tenant data center location. For details, see URL allow list.

DXL broker

IAM

TCP 443

Authentication

  • https://iam.cloud.trellix.com

  • https://iam-rs.cloud.trellix.com

Trellix Endpoint

IAM

TCP 443

Authentication

  • https://iam.cloud.trellix.com

  • https://iam-rs.cloud.trellix.com

ePO - On-prem

IAM

TCP 443

Authentication

  • https://iam.cloud.trellix.com

  • https://iam-rs.cloud.trellix.com

ePO - On-prem

Trellix EDR workspace

TCP 443

Queries and responses used in investigations (examples, queries to ePO - On-prem events and queries to SIEM).

Currently, DXLsupports a bridge between cloud and on-premises for real-time queries and remediations. This behavior is expected to change in future DXLversions, where an alternate route is used for Snapshots.

https://api.soc.trellix.com/

Note

The URL changes for each tenant data center location. For details, see URL allow list.

ePO - On-prem

Endpoint (EDRF Client client)

Configurable by default 8088 and 8089

Alternate route for snapshots (not by default, not recommended).

DXL broker

ePO - On-prem

TCP 443

Policies download, Trellix system logs upload.

ePO - On-prem

DXL broker

TCP 8081

Trellix Agent wake-up call.

For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797.



Specific paths for ePO - SaaS implementations

Source

Destination

Port

Description

URL

Endpoint — Trellix Agent

ePO - SaaS

TCP 80

Policies download, Trellix Agent system logs upload.

POD specific Implementation — ah-<pod>.manage.trellix.com. Only one URL per POD.

Currently:

  • ah-usw001.manage.trellix.com

  • ah-usw002.manage.trellix.com

Trellix Agent handlers

TCP 443

ePO - SaaS

Endpoint (Trellix Agent)

TCP 8081

Trellix Agent wakeup call/ SADR (not supported) /Peer-to-Peer/ Relay.

For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797.

TCP 8082

Peer-to-peer server discovery, RelayServer discovery.

TCP 8083

RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open.

Endpoint — (Trellix Agent 5.8.2 or DXL client)

ePO - SaaS

TCP 443

DXL messaging (ICMP is not supported) and real-time search queries.

POD specific implementation — dxl-<pod>.manage.trellix.com. Only one URL per POD.

Currently:

  • dxl-usw001.manage.trellix.com

  • dxl-usw002.manage.trellix.com

Endpoint — (Trellix Agent 5.8.2 or DXL client)

Trellix EDR workspace

TCP 443

Send information to Trellix EDR workspace:

  • Trace data from Endpoints /EDRF Client client.

  • Real-time search responses from Endpoints /EDRF Client client.



For details about the default ports required for each component on ePO - On-prem, see the Trellix Knowledge Base article, ePolicy Orchestrator port requirements for firewall traffic - KB66797.