This article applies to:
Question:
- What URLs are required for operation of WebMarshal features?
Information:
- Note: Additional URL cdn-updates.marshal.com is used from February 2022.
WebMarshal includes a number of features that are automatically updated using web-based services.
These services are accessed by the WebMarshal processing node servers.
You should ensure that access to these services is permitted by any firewall or external proxy (and by WebMarshal rules if required by network setup).
- If WebMarshal is installed as a plugin to ISA, you may need to create special ISA rules. See Trustwave Knowledgebase article Q10286.
The required URLs include:
URL | From Server | Purpose |
HTTP://crl.trustwave.com | All | HTTPS Certificate Revocation Checking - Trustwave sites (Other URLS may be required for HTTPS CRL checking of third party sites) |
HTTPS://tracenetlicensing.m86security.com HTTP://tracenetdl.m86security.com HTTPS://tnreclassify.m86security.com HTTPS://tnfeedback.m86security.com HTTPS://cdn-updates.marshal.com - This URL is hosted on Microsoft Azure CDN. IP addresses may change. IP addresses can be retrieved using the "Front Door" tag in Microsoft Azure IP Ranges and Service Tags.
| Processing Nodes | TRACEnet service (updates, reclassification requests, and feedback) |
HTTPS://tracenetlicensing.m86security.com HTTPS://cdn-updates.marshal.com - This URL is hosted on Microsoft Azure CDN. IP addresses may change. IP addresses can be retrieved using the "Front Door" tag in Microsoft Azure IP Ranges and Service Tags.
| Processing Nodes | Automatic updates to File Type, Unpacking, and other functionality. |
HTTPS://filterlistlicensing.m86security.com HTTPS://secureupdate.8e6.com HTTPS://updates.8e6.com Note: Beginning 3 October 2022, the database content will be served from HTTPS://tracenetlicensing.m86security.com The 8e6.com servers will be decommissioned later in October. | Processing Nodes | Trustwave Web Filter Database (Previously known as M86 URL filtering List) (Note that this URL must also be accessible from the Array Manager at the time of initial configuration of the list.) - Be sure that any external devices allow WebMarshal to access both "secureupdate" and "updates". Trustwave may serve the database content from either of these sites, depending on operational need.
|
HTTP://sophos.marshal.com HTTPS://sophos.marshal.com | Processing nodes | Sophos for Marshal Engine and IDE updates (if installed) - HTTPS required from SfM version 1.1.
- Note that the LiveProtection service (present in version 1.1 and above) performs DNS-based queries and must have access to a DNS server that can query the Sophos DNS servers.
|
HTTPS://safebrowsing.googleapis.com | Processing Nodes | Google Safe Browsing updates (WebMarshal 7.1 and above, if the Safe Browsing feature is enabled) |
HTTP://mcafee.marshal.com HTTPS://mcafee.marshal.com | Processing nodes | McAfee for Marshal Engine updates (if installed) - HTTPS required from MfM version 1.1.
|
HTTP://update.nai.com/ | Processing nodes | McAfee for Marshal definition file updates (if installed) |
HTTPS://bitdefender.marshal.com/ HTTPS://agent-av-mirror.trustwave.com | Processing nodes | Bitdefender for Marshal Engine and signature updates (if installed) |
Notes:
- Because WebMarshal is a proxy server, it is assumed that processing nodes will have full access to the web.
- In some versions the "marshal8e6.com" domain is used instead of "m86security.com". IP address resolution of the servers is identical regardless of this domain change.