FAQs for ENS Firewall Global Threat Intelligence
Last Modified: 2024-02-16 10:34:11 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
FAQs for ENS Firewall Global Threat Intelligence
Technical Articles ID:
KB90837
Last Modified: 2024-02-16 10:34:11 Etc/GMT Environment
Endpoint Security (ENS) Firewall 10.x
Summary
Recent updates to this article
To receive email notification when this article is updated, click Subscribe on the right side of the page. You must be logged on to subscribe.
This article provides detailed information about ENS Firewall Global Threat Intelligence (GTI) functionality. What host name and port number need to be open for GTI functionality to work? To work properly, the following host name and port number must be open. Make sure that they're open on any gateway firewalls, and if applicable, from the proxy server. Host:
Port: 443 Can I change the host name and port information for GTI reputation lookups? No. The host name and port information used for GTI reputation lookups is hard-coded into the product. This information can't be changed in the local configuration, or in the ePolicy Orchestrator (ePO) policies. Does the GTI functionality work with or without a proxy server?
Yes. ENS Firewall GTI functions correctly with or without a proxy server. When a proxy server is configured, the internet browser is configured to connect directly to a proxy server for internet access.
08/31/2018 09:27:48.481 AM mfeesp(9820.12244) LPC.CommonLPC.Debug: Fetching Property setting [gtiProxyServerAddress] with its value [10.10.10.1] 08/31/2018 09:27:48.481 AM mfeesp(9820.12244) LPC.CommonLPC.Debug: Fetching Property setting [gtiProxyServerPort] with its value [8080] 08/31/2018 09:27:48.481 AM mfeesp(9820.12244) LPC.CommonLPC.Debug: Fetching Property setting [gtiProxyType] with its value [2],/div> If a failure occurs, review the 08/31/2018 12:38:36.921 PM mfeesp(3052.4660) GTIBL.GTI.Debug: could not setup proxy (proxy host: Proxy.customer.com host: tunnel.web.trustedsource.org.) How do I test GTI connectivity using Verify whether GTI connectivity is successful.
What rules does GTI trigger if traffic is blocked? ENS Firewall GTI triggers the following firewall rules if network traffic is blocked due to matching the configured GTI In or Out network-reputation threshold ratings.
Use the following IP addresses to test the ENS Firewall GTI functionality. When you access these IP addresses, blocked events must display in the ENS 207.67.117.52 MEDIUM RISK 207.67.117.53 UNVERIFIED RISK Example block event: Event: Traffic IP Address: 207.67.117.51 Description: MICROSOFT TELNET CLIENT Path: C:\Windows\System32\telnet.exe Message: Blocked Outgoing TCP - Source 10.0.0.1 : (57640) Destination 207.67.117.51 : http (80) Matched Rule: GTI Rule - TCP - Out What happens to traffic if the ENS Firewall can't reach the GTI server? You can configure the ENS Firewall to either block or allow traffic by default if the GTI ratings server isn't reachable. Configure the setting If McAfee GTI ratings server is not reachable in the ENS Firewall Options policy under the section named McAfee GTI Network Reputation. What hash type is used for file queries? ENS uses SHA-256 for file queries to GTI. ENS continues to support MD5 for policy configuration and reporting. Are domain name ratings used? No. The IP address and port number of the connection request is rated against the GTI database. Domain name ratings aren't used. Can GTI ratings differ depending on how a connection is made? Yes. GTI ratings differ depending on how a connection is made. For example, port 25 traffic to an IP address can have a different GTI rating than port 80 traffic. How do I configure exclusions for the ENS Firewall GTI feature? You can add the affected IP addresses in the Firewall Options policy under the Defined Networks section.
ENS Firewall GTI automatically excludes the following IP addresses from a ratings check:
If the setting Log matching traffic is enabled in the ENS Firewall Options policy under the section McAfee GTI Network Reputation, Event ID 35002 events are generated and reported to the ePO server. Can I use ePO queries to report on GTI events? Yes. A default query named Endpoint Security Firewall: Events from McAfee GTI in the last 6 months is provided. You can also create your own ePO queries to report on GTI events. How can I dispute GTI ratings or learn more about GTI ratings? To dispute or request any further information about GTI ratings, you have two options:
NOTE: Domain and URL ratings can differ from IP address:port number ratings. When using the Check URL action on the
Related Information
For detailed information about configuring GTI features, see the Endpoint Security Product Guide. For product documents, go to the Product Documentation portal.
Affected ProductsLanguages:This article is available in the following languages: |
|