Views:

Install services on your Service Gateway appliance to connect or manage your on-premises or third-party products.

Service
Description
Additional Requirements
ActiveUpdate Service
Serves on-premises Trend Micro products as a local ActiveUpdate server to reduce outgoing internet traffic.
File Security Virtual Appliance
Enables on-premises scanning of files for malware using the NFS v3 protocol and File Security SDK.
Requires installation of this service exclusively on the Service Gateway appliance to enhance performance.
Allows on-premises Trend Micro products with no direct access to the internet to use the service gateway as a proxy to reach Trend Micro services.
Requires the Service Gateway API key.
Greenbone Connector
Sends vulnerability data on scanned devices and internet-facing assets from the Greenbone server to Trend Vision One.
Requires the following information:
  • Greenbone server IP address
  • Greenbone account username
  • Greenbone account password
The provided username and password must be for a Greenbone account with at least an Observer role.
MISP Threat Intelligence Connector
Enables Trend Vision One to share threat intelligence data with MISP integration or retrieve threat intelligence data from MISP integration.
Service requires configuring MISP in Third-Party Integration.
Nessus Pro Connector
Sends device information and vulnerability data from the Nessus Pro server to Trend Vision One.
Requires the following Nessus Pro server settings:
  • Server URL
  • Nessus Pro secret key
  • Nessus Pro access key
On-premises Directory Connector
Supports sharing objects and activity data from Active Directory and OpenLDAP servers with Trend Vision One.
Service requires configuring third-party apps in Third-Party Integration.
Rapid7 - Nexpose Connector
Sends device and vulnerability data from your Nexpose server to Trend Vision One.
Requires the following information:
  • Rapid7 server URL
  • Rapid7 Security Console username
  • Rapid7 Security Console password
Leverages file reputation and web reputation technology to detect security risks. On-premises Trend Micro products can perform queries against the Service Gateway virtual appliance, which provides Smart Protection either through the local Smart Protection Server on the virtual appliance or as a reverse proxy.
  • Use the address information listed in the settings panel to configure connected products.
  • Update to Smart Protection Services 2.0.0 or later requires Service Gateway 3.0.
Suspicious Object Exchange Service
Enables sharing suspicious object data from Trend Vision One with third-party apps.
Service requires configuring third-party apps in Third-Party Integration.
Suspicious Object List Synchronization Service
Supports the sharing of Suspicious Object lists between Trend Vision One and on-premises Trend Micro products.
Requires the Service Gateway API key.
Syslog Connector
Enables sharing data from Trend Vision One with your local syslog server.
Service requires configuring third-party apps in Third-Party Integration.
Third-party intelligence synchronization (deprecated)
Note
Note
The service has been updated to MISP Threat Intelligence Connector and Suspicious Object Exchange Service.
Shares threat intelligence from Trend Vision One with third-party applications or retrieves threat intelligence from third-party applications.
Service requires configuring third-party apps in Third-Party Integration.
Third-Party Log Collection Service
Supports sending logs in Common Event Format (CEF) syslog format from third-party sources to Trend Vision One for analysis and correlation.
Service requires configuring third-party apps in Third-Party Integration.
TippingPoint Log Forwarding Service
Supports forwarding logs to Trend Vision One for correlation and analysis.
Requires the Service Gateway API key.
TippingPoint Policy Management Service
Allows the Intrusion Prevention Configuration app to modify TippingPoint policy configurations to mitigate CVEs.
Service requires a connected TippingPoint SMS console.
Zero Trust Secure Access On-Premises Gateway
Zero Trust Secure Access Internet Access is a forward proxy or ICAP service that protects end users from malicious activity on the internet through the use of secure gateways. Through integration with your Active Directory server, the on-premises gateway can also serve as an authentication proxy.
Service requires setting up Internet Access and AI Service Access configuration in the Zero Trust Secure Access app.
Once the Internet Access On-Premises Gateway service is enabled, you may configure custom ports for the following related services:
  • HTTP proxy
  • Authentication proxy
  • ICAP
  • ICAPS
After configuring custom ports for services, the services will be restarted. Selected ports must be available. To view the default ports for the above services, see Service Gateway virtual appliance communication ports.