What URLs are required for operation of WebMarshal features?


This article applies to:

  • WebMarshal 

Question:

  • What URLs are required for operation of WebMarshal features?

Information:

  • Note: Additional URL cdn-updates.marshal.com is used from February 2022.

WebMarshal includes a number of features that are automatically updated using web-based services.

These services are accessed by the WebMarshal processing node servers.

You should ensure that access to these services is permitted by any firewall or external proxy (and by WebMarshal rules if required by network setup). 

  • If WebMarshal is installed as a plugin to ISA, you may need to create special ISA rules. See Trustwave Knowledgebase article Q10286.

The required URLs include:

URL From Server Purpose
HTTP://crl.trustwave.com All HTTPS Certificate Revocation Checking - Trustwave sites
(Other URLS may be required for HTTPS CRL checking of third party sites)
HTTPS://tracenetlicensing.m86security.com
HTTP://tracenetdl.m86security.com
HTTPS://tnreclassify.m86security.com
HTTPS://tnfeedback.m86security.com
HTTPS://cdn-updates.marshal.com
  • This URL is hosted on Microsoft Azure CDN. IP addresses may change. IP addresses can be retrieved using the "Front Door" tag in Microsoft Azure IP Ranges and Service Tags.
Processing Nodes TRACEnet service (updates, reclassification requests, and feedback)
HTTPS://tracenetlicensing.m86security.com
HTTPS://cdn-updates.marshal.com
  • This URL is hosted on Microsoft Azure CDN. IP addresses may change. IP addresses can be retrieved using the "Front Door" tag in Microsoft Azure IP Ranges and Service Tags.
Processing Nodes Automatic updates to File Type, Unpacking, and other functionality.
HTTPS://filterlistlicensing.m86security.com
HTTPS://secureupdate.8e6.com
HTTPS://updates.8e6.com

Note: Beginning 3 October 2022, the database content will be served from HTTPS://tracenetlicensing.m86security.com
The 8e6.com servers will be decommissioned later in October.
Processing Nodes

Trustwave Web Filter Database (Previously known as M86 URL filtering List)
(Note that this URL must also be accessible from the Array Manager at the time of initial configuration of the list.)

  • Be sure that any external devices allow WebMarshal to access both "secureupdate" and "updates". Trustwave may serve the database content from either of these sites, depending on operational need.
HTTP://sophos.marshal.com
HTTPS://sophos.marshal.com
Processing nodes Sophos for Marshal Engine and IDE updates (if installed)
  • HTTPS required from SfM version 1.1.
  • Note that the LiveProtection service (present in version 1.1 and above)  performs DNS-based queries and must have access to a DNS server that can query the Sophos DNS servers.
HTTPS://safebrowsing.googleapis.com Processing Nodes Google Safe Browsing updates (WebMarshal 7.1 and above, if the Safe Browsing feature is enabled)
HTTP://mcafee.marshal.com
HTTPS://mcafee.marshal.com
Processing nodes McAfee for Marshal Engine updates (if installed)
  • HTTPS required from MfM version 1.1.
HTTP://update.nai.com/ Processing nodes McAfee for Marshal definition file updates (if installed)
HTTP://kaspersky.marshal.com/
HTTPS://kaspersky.marshal.com
Processing nodes Kaspersky for Marshal Engine and signature updates (if installed)
HTTPS://ksn?.kaspersky-labs.com
(where ? is any single character)
Processing nodes Kaspersky Security Network Cloud (enabled by default when installed but can be disabled)
HTTPS://bitdefender.marshal.com/
HTTPS://agent-av-mirror.trustwave.com
Processing nodes Bitdefender for Marshal Engine and signature updates (if installed)

 
Notes:

  • Because WebMarshal is a proxy server, it is assumed that processing nodes will have full access to the web.
  • In some versions the "marshal8e6.com" domain is used instead of "m86security.com". IP address resolution of the servers is identical regardless of this domain change.

Last Modified 9/29/2022.
https://support.trustwave.com/kb/KnowledgebaseArticle12872.aspx