General Availability (GA) | Release Notes |
October 27, 2022 | Network Security Platform IPS 10.1.7.65-10.1.5.190 Manager-NS-series Release Notes Network Security Platform vIPS 10.1.7.65-10.1.7.155 Manager-Virtual IPS Release Notes |
June 22, 2022 | Network Security Platform 10.1.7.61-10.1.5.170 Manager-NS-series - Release Notes Network Security Platform 10.1.7.61-10.1.7.135 Manager-Virtual IPS - Release Notes |
March 21, 2022 | Network Security Platform 10.1.7.55-10.1.5.153 Manager-NS-series - Release Notes Network Security Platform 10.1.7.55-10.1.7.123 Manager-Virtual IPS - Release Notes |
December 9, 2021 | Network Security Platform 10.1.7.50-10.1.5.116 Manager-NS-series - Release Notes Network Security Platform 10.1.7.50-10.1.7.96 Manager-Virtual IPS - Release Notes |
September 7, 2021 |
Network Security Platform 10.1.7.44-10.1.5.106-107 Manager-NS-series Release Notes
Network Security Platform 10.1.7.44-10.1.7.86 Manager-Virtual IPS Release Notes
Network Security Platform 10.1.19.33-10.1.17.36 Manager-NS-series FIPS CC and DoDIN APL Release Notes
|
June 5, 2021 | Network Security Platform 10.1.19.30-10.1.17.26 Certification Release Notes |
May 18, 2021 | Network Security Platform 10.1.7.40-10.1.5.92 Manager-NS-series Release Notes Network Security Platform 10.1.7.40-10.1.7.65 Manager-Virtual IPS Release Notes |
November 12, 2020 | Network Security Platform 10.1.7.35-10.1.5.75 Manager-NS-series Release Notes Network Security Platform 10.1.7.35-10.1.7.51 Manager-Virtual IPS Release Notes |
October 29, 2020 | Network Security Platform 10.1.7.24-10.1.7.33 Manager-Virtual IPS Release Notes |
August 20, 2020 | Network Security Platform 10.1.7.29-10.1.5.64 NS-series Release Notes Network Security Platform10.1.7.29-10.1.7.42 Virtual IPS Release Notes |
June 16, 2020 | Network Security Platform 10.1.7.7 - 10.1.5.41 Manager NS-Series Release Notes |
February 13, 2020 | Network Security Platform 10.1.7.4 Manager 10.1.5.5. NS-Series Release Notes |
December 10, 2019 | Network Security Platform 10.1.7.x -10.1.5.x Manager NS-Series Release Notes |
Trellix IPS 10.1.x Known Issues
Technical Articles ID:
KB92105
Last Modified: 2023-04-05 09:14:22 Etc/GMT
Last Modified: 2023-04-05 09:14:22 Etc/GMT
Environment
Trellix Intrusion Prevention System (Trellix IPS) 10.x
Summary
Recent updates to this article
Date | Update |
April 5, 2023 | General rebranding. |
October 27,2022 |
|
To receive email notification when this article is updated, click Subscribe on the right side of the page. You must be logged on to subscribe.
Contents
Click to expand the section you want to view:
Issue resolutions in updates and major releases are cumulative; Technical Support recommends that you install the latest version. To find the most recent release for your product, go to the Product Downloads site.
Reference Number | Related Article | Found in Version | Issue Description |
KB95078 | 10.1.7.50 | Issue: Starting with 10.1.7.50, the Manager only supports TLS 1.2 ciphers for Manager and Sensor communication. If you upgrade your Manager to 10.1.7.50 or later but your Sensor software doesn't support TLS 1.2, communication between the Manager and Sensor is interrupted. To avoid this issue, you must first upgrade the Sensor to a software version that supports TLS 1.2 and then upgrade your Manager to 10.1.7.50. For details about how to avoid this issue, see the related article for a list of TLS 1.2 supported Sensor software and upgrade your Sensor before rolling out your Manager upgrade. |
Non-critical
Reference Number | Related Article | Found in Version | Issue Description |
NSPMGR-22113 | 10.1M10 | Issue: Some alerts aren't converted to a detected state for malicious files in the Attack Log page. This issue is seen when the Multi-Vector Virtual Execution (MVX) engine is configured for stacked Sensors. |
|
NSPMGR-22112 | 10.1M10 | Issue: When you click the report icon in the Attack Log page, Report data isn't available for some alerts. This issue is seen when the MVX engine is configured. |
|
NSPMGR-22064 | 10.1M10 | Issue: The Ssensor health node keeps loading and doesn't display health information for other devices, when any one of the Sensors connected to the Manager is rebooting. | |
NSPMGR-21842 | 10.1M10 | Issue: Grouping by the Manager column works only after a refresh in the Device Manager page of the Central Manager. Workarounds:
|
|
NSPMGR-21145 | Issue: You see an automatic switch over in an MDR pair. This puts the peer Manager into active mode. | ||
NSPMGR-20787 | Issue: [AWS] After installing the 10.1.7.44 Manager, the size of the root partition is displayed as 20 GB while the actual size should be 150 GB. Workaround: Upgrade to the latest Manager and run the new growpart RPM bundled with the Manager. The steps to extend the root partition can be found under "Extend the file system of EBS volumes" section of the AWS User Guide. |
||
NSPMGR-20340 |
Issue: After upgrading the stack Sensor software version from the Device Manager page, the Sensor fails to reboot automatically.
Workaround: Reboot the Sensor manually.
|
||
NSPMGR-18927 | Issue: Discrepancies are reported in IP address to geolocation mapping data when compared with |
||
NSPMGR-17727 | Issue: When you swap the 2×40g and 4×40g modules, the Module information isn't refreshed in the Manager. | ||
NSPMGR-17563 | Issue: You can't enter more than two characters in the Ignore rules tab, Search Attack Name text field. Workaround: You can't type more than two characters, but you can copy and paste the full attack name in the Search Attack Name text field. |
||
NSPMGR-16892 |
Issue: After you migrate the Manager and Sensor certificate from self-signed to CA-signed, trust establishment fails between the Manager and Sensor.
Workaround:
|
||
NSPMGR-16846 | Issue: You see the last activity displayed as null in the Manager database, when you close the browser session abruptly instead of logging out. Workaround: Always log off from the Manager using the in manager option. |
||
NSPMGR-15657 | 10.1 |
Issue: You see Access Denied Exceptions in the
Workarounds:
|
|
NSPMGR-15626 | 10.1 | Issue: When policies are updated in the Manager, the pending changes status isn't updated under |
|
NSPMGR-12791 | 10.1 | Issue: Malware policies for alerts aren't displayed when you access them from the Attack Log, Other Actions, Update Policy option. | |
NSPMGR-8125 | Issue: When you try to reboot Virtual IPS Sensors from the Manager, the reboot fails. | ||
NSPMGR-8034 |
Issue: The Manager doesn't display properly on Microsoft Edge and Firefox v57 browsers.
Workaround: Disable the touchscreen feature on your system. To disable the touchscreen feature:
|
||
NSPMGR-7952 | 9.1 |
Issue: You can't integrate NTBA with the Manager because the NTBA Direction drop-down list displays a blank value.
This issue might happen when you add an NTBA to the Manager. Workaround:
|
|
NSPMGR-7895 | 9.1 | Issue: After you quarantine the host, the Quarantine page displays the vNSP Cluster name instead of the Virtual IPS Sensor name. | |
NSPMGR-2772 | 10.1 | Issue: The File Hashes page stops responding when deleting records from the block or allow lists when the number of entries exceeds 159. | |
NSPMGR-2758 | 9.2 | Issue: After you upgrade the Manager, the private GTI configurations can't be updated to the Sensor. | |
NSPMGR-2669 | 9.2 | Issue: After you import chain certificates, an incorrect key length for the parent certificates is displayed. | |
NSPMGR-2646 | 9.1 | Issue: The Attack Log page doesn't display the IP address for the |
|
NSPMGR-2472 | 9.1 | Issue: The Attack count isn't incremented for any block-listed executable in the Endpoint Executables page. | |
NSPMGR-2438 | 9.1 |
Issue: [Linux-Based Manager] The following diagnostic tools don't work:
|
Back to top
Critical
Non-critical
Back to top
Reference Number | Related Article | Found in Version | Issue Description |
NSPSNSR-9392 | 10.1 | Issue: Capturing packets when the port is in span mode under high load causes the Sensor to stop responding and passing network traffic (Sensor crashes). |
Non-critical
Reference Number | Related Article | Found in Version | Issue Description |
NSPSNSR-12831 | KB96096 | 10.1M10 | Issue: [NS-Series 9100] Sensors show handshake buffer allocation failures on SSL traffic (Extended Master Secret). You see the following entry in the |
NSPSNSR-12819 | 10.1M10 | Issue: Some counters don't match the expected values in when files are submitted to the MVX engine in bulk. |
|
NSPSNSR-12575 | Issue: [NS9x00] 2×40g I/O module ports don't come up in their respective slots, although you enable the ports in the Manager. | ||
NSPSNSR-12451 | Issue: [NS9300] When you bring up the cross-connect ports, the Layer2 status is incorrectly displayed as abnormal, although the Sensor health status is good. | ||
NSPSNSR-12298 | 10.1M10 | Issue: Packet matching might not work correctly in the firewall policy after upgrading to 10.1.5.153 when there are multiple network objects configured in a single rule. Workaround: Upgrade the Sensor to 10.1.5.170 or later versions to avoid this issue. |
|
NSPSNSR-11939 | Issue: A supported file type for malware inspection is uploaded to a server via a POST or PUT request, and the server responds with a file that's downloaded as a Response. The Sensor can inspect only the file uploaded and doesn't scan the file downloaded for the POST request. This limitation applies only when both the HTTP download and HTTP upload options are enabled. |
||
NSPSNSR-10394 | Issue: [NS3500] The management port speed is displayed incorrectly in the Sensor CLI. | ||
NSPSNSR-9483 | 9.1 | Issue: The Scheduler intermittently fails to pick files submitted to the cloud to get the report; the files continue to show as pending. | |
NSPSNSR-9187 | 10.1 | Issue: For |
|
NSPSNSR-8719 | 9.1 | Issue: GTI File Reputation stops working with high traffic load. | |
NSPSNSR-8235 | Issue: An invalid string is seen in the Layer 7 data alerts generated for Office engine. | ||
NSPSNSR-8195 | Issue: The value of the |
||
NSPSNSR-7937 | Issue: Hitless reboot doesn't work as multiple datapath processors stop responding (crash). | ||
NSPSNSR-7935 | Issue: In rare scenarios, some files aren't processed for malware scanning. | ||
NSPSNSR-7932 | Issue: The packet ( |
||
NSPSNSR-7542 | Issue: APK files with the extension |
||
NSPSNSR-6916 | Issue: If there are host sweep alerts, there's a mismatch in Network Protocol ID when the Manager forwards alert messages to the |
||
NSPSNSR-6837 | Issue: Redirection to the Guest Access portal fails for inter-VLAN routing. | ||
NSPSNSR-4344 | 9.2 | Issue: Sensor Snort IDs are sent in the failed rules file instead of Global Snort IDs. | |
NSPSNSR-4339 | 9.2 | Issue: The Sensor prioritizes HTTP traffic over SSL traffic when outbound SSL decryption is enabled. | |
NSPSNSR-4326 | 9.2 | Issue: Outbound SSL implementation shows outbound flows as configurable through the Manager. | |
NSPSNSR-4314 | 9.2 | Issue: Rules with IPv4 address range can't be created. | |
NSPSNSR-4278 | 9.2 | Issue: [SNORT] Snort attack packet detected by |
|
NSPSNSR-3990 | Issue: Layer 7 data collection remains enabled although it's disabled from the Policy page, which leads to low performance of the device. | ||
NSPSNSR-3069 | Issue: Connection limiting host count is as low as 128k, but must be more than 256k for NS-series Sensors. | ||
NSPSNSR-2972 | Issue: RX/TX counters are updated slowly. |
Back to top
Critical: There are currently no critical issues.
Non-critical
Non-critical
Reference Number | Related Article |
Found in Version | Issue Description |
NSPSNSR-12831 | KB96096 | 10.1M10 | Issue: [VM600] Sensors show handshake buffer allocation failures on SSL traffic (Extended Master Secret). You see the following entry in the |
NSPSNSR-11685 | 10.1 | Issue: Jumbo features like Jumbo Malware and Jumbo Frames don't work on the Virtual IPS Sensor deployed on ESX 7.0. | |
NSPSNSR-10740 | 10.1 | Issue: When you execute the |
|
NSPSNSR-10555 | 10.1 | Issue: In certain conditions for a Windows VM, fewer alerts are seen when consecutive, identical attacks appear. |
Critical:
Non-critical: There are currently no non-critical issues.
Reference Number | Related Article |
Found in Version |
Issue Description |
NSPNAD-1721 | 10.1 | Issue: During split file download, XDP files aren't extracted. | |
NSPNAD-1690 | 10.1 | Issue: The Manager doesn't trigger alerts for custom rules that use the |
Non-critical: There are currently no non-critical issues.
Related Information
To contact Technical Support, go to the Create a Service Request page and log on to the ServicePortal.
- If you are a registered user, type your User ID and Password, and then click Log In.
- If you are not a registered user, click Register and complete the fields to have your password and instructions emailed to you.
Affected Products
Languages:
This article is available in the following languages: