Views:

Connect a TippingPoint Security Management System (SMS) 6.1.0 or later to Network Security through a Service Gateway.

Important
Important
Intrusion Prevention Configuration currently only supports policy enforcement on the first TippingPoint SMS connected to Trend Vision One. Support for policy enforcement on multiple TippingPoint SMS deployments is coming soon.

Procedure

  1. Generate an API key to access the SMS Web API.
    1. From your SMS interface, select AdminAuthentication and AuthorizationRoles and verify that the role for the selected user account has the Access SMS Web Services capability enabled.
    2. Select AdminAuthentication and AuthorizationUsers.
    3. Select the user account, and click Edit.
    4. Click Regenerate API Key to get a new API key.
      You can reset the API key for any reason. But when you do, from this point, the previous API key can no longer be used.
  2. In the Trend Vision One console, go to Workflow and AutomationService Gateway Management.
    Note
    Note
    Connecting a TippingPoint SMS using a Service Gateway requires a Service Gateway 2.0 or later appliance. You can check the Service Gateway version in Service Gateway Management.
  3. If you do not have a Service Gateway available for connecting your TippingPoint SMS to Trend Vision One, you must install a Service Gateway appliance .
    Note
    Note
    Multiple TippingPoint SMS deployments can connect to a single Service Gateway appliance.
    1. Click Download Virtual Appliance to open the Service Gateway Virtual Appliance panel.
    2. Select either VMware ESXi (OVA) or Microsoft Hyper-V (VHDX) as the disk image type you want to use.
    3. Click Download Disk Image.
    4. Copy the Registration Token, which you will need when deploying the appliance.
    5. Install the Service Gateway virtual appliance.
    6. Click Close.
  4. Configure the Service Gateway appliance for use with a TippingPoint SMS.
    1. Click the name of the Service Gateway appliance.
    2. Click Manage Services.
    3. Click the install icon (SG2_install_icon=GUID-feef28dd-2ddb-4093-b4e4-5455a0b110bb.png) to install and then enable the following services.
      Service
      Description
      Forward proxy
      Required for data sharing between the TippingPoint SMS and Trend Vision One, allowing users to view filter and profile distribution statuses
      Suspicious Object List Synchronization
      Required for the Suspicious Object Sync function, which synchronizes the centralized Trend Vision One Suspicious Object List with the TippingPoint SMS
      Note
      Note
      The Suspicious Object List Synchronization service is not required when connecting to a TippingPoint SMS 6.2.0 or later.
  5. In the Service Gateway Management app, record the Service Gateway Management API key and the IP address of the Service Gateway appliance.
    1. Click Manage API Key and record the API key, then click Close.
    2. Click the Service Gateway appliance name and record the IPv4 address.
  6. Configure a TippingPoint SMS connector in Trend Vision One.
    • For customers that have updated to the Foundation Services release, go to Service ManagementProduct Instance.
    • For customers using the legacy Trend Vision One console, go to Point Product ConnectionProduct Connector.
    Alternatively:
    1. In the Trend Vision One console, go to Network SecurityNetwork Inventory.
    2. Select the Continue with TippingPoint deployment option.
    3. Click Connect a TippingPoint SMS.
    4. Follow the steps in the connection guide dialog for configuring a Service Gateway (if required), generating an enrollment token using the Product Instance app, and connecting your SMS to Trend Vision One using the SMS Client interface.
  7. Connect your TippingPoint SMS to Trend Vision One.
    1. On the TippingPoint SMS web management console, go to AdministrationConnect to Trend Vision One.
    2. Click Configure.
    3. Paste the enrollment token into the Enrollment Token field.
      Using an enrollment token automatically provisions a one-year Trend Vision One certificate. The certificate automatically renews 30 days before expiration to avoid any gaps in security protection.
    4. Enable and configure the Service Gateway function.
      1. In the Service Gateway section, enable the State toggle.
      2. In the IP Address field, enter the IP address of the Service Gateway.
      3. In the API Key field, enter the Service Gateway Management API key.
    5. Enable and configure the Suspicious Object Sync function.
      1. In the Suspicious Object Sync (Service Gateway Required) section, enable the State toggle.
      2. In the Download Interval field, specify how often you want the Suspicious Object List to be synchronized.
    6. (Optional) If you would like to submit suspicious URL objects for sandbox analysis, enable the Cloud Sandbox URL analysis.
      1. In the Cloud Sandbox URL Analysis section, enable the State toggle.
      2. In the Saved Query dropdown menu, select your desired query.
    7. Click Test Connectivity to verify that the TippingPoint SMS can connect to Trend Vision One.
    8. Click Save.
  8. Verify the connection status.
    1. In the Trend Vision One console:
      • For customers that have updated to the Foundation Services release, go to Point Product ConnectionProduct Instance.
      • For customers using the legacy Trend Vision One console, go to Point Product ConnectionProduct Connector.
    2. Check that the Connection status for TippingPoint Security Management System is green.
    Devices managed by the TippingPoint SMS can be viewed in Network SecurityNetwork Inventory.
  9. To check for vulnerabilities and receive policy recommendations in Trend Vision One, enable the TippingPoint SMS as an Attack Surface Risk Management data source.
    1. In the Trend Vision One console, go to Attack Surface Risk ManagementExecutive Dashboard.
    2. Click Data sources.
    3. In the Trend Micro Security Services section, click TippingPoint Security Management System.
    4. Enable Data upload permission to allow the TippingPoint SMS to provide data for more comprehensive risk insights into your network activity.