TrendAI Vision One™ enables sharing of suspicious object data with SonicWall NSv through a Service Gateway.
Configure sharing of suspicious object data with this integration
through a Service Gateway.
NoteIntegration requires configuring at least one Service Gateway with the Suspicious Object Exchange Service.
For more information, see Service Gateway Management.
|
Procedure
- Configure settings on TrendAI Vision One™.
- Locate and click the SonicWall NSv card.
- Use the toggle to enable or disable the integration.
- Review the Legal Statement and click Accept or Close to continue.
- Under Data Transfer, configure data sharing criteria and integration settings.
-
Object type: This integration shares suspicious IP addresses and domains.
-
Risk level: Select the risk level of the suspicious object data to include in the shared data.
-
Frequency: Select the frequency for sharing suspicious object data.
-
- Under Service Gateway
Connection, configure the connection between the Service
Gateway and the integration.
-
Click Connect.The Service Gateway Connection panel appears.
-
Select a Service Gateway installed with the Suspicious Object Exchange Service.
-
Under Server Settings, select Transfer data using HTTP or Transfer data using HTTPS (HTTPS is the default).
-
Click Connect.The connection configuration is added to the list.
-
Click the Generate Now icon (
) to generate suspicious object
data sharing files immediately. -
Hover over the Copy URL icon (
) to copy the suspicious object
data sharing URLs to use on your integration.
-
- Repeat the previous step to add multiple connection configurations for this integration.
- Click Save.
- Configure settings on your integration.

Note
The following steps were performed using SonicOS 7.If you are using a different version, refer to the documentation for your version.- Add a Dynamic External Address
Group for the domain suspicious object list and configure
it.
-
Name: Type a name to help you identify this group.
-
Zone Assignment: Select the zone for your network.
-
Enable the FQDN option. This is required for the domain list.
-
Enable Enable Periodic Download and specify a download interval.

Tip
TrendAI™ recommends matching the download interval to the suspicious object data sharing Frequency configured on TrendAI Vision One™. -
Protocol: Select the protocol matching the transfer method you selected on TrendAI Vision One™ (HTTP or HTTPS).
-
In the URL field, paste the domain suspicious object data sharing URL that you obtained from the TrendAI Vision One™ console (for example, the URL ending in
sonic_so_domain.txt). -
Save the group.
-
- Add a second Dynamic External Address
Group for the IP address suspicious object list, following
the previous step but leaving the FQDN option
disabled and pasting the IP address sharing URL (for example, the URL
ending in
sonic_so_ip.txt).Your SonicWall appliance is configured to retrieve suspicious object data from the TrendAI Vision One™ Service Gateway. - To enforce blocking on the shared suspicious objects, go to and add or edit a security policy rule that uses the Dynamic External Address Group as the destination address.
