Data Exchange Layer 6.1.x Installation Guide

Prev Next

Last Updated: April 17, 2026

Install or upgrade DXL Broker

Determine which type of installation you need to perform: a first time installation in a new environment, or an upgrade to a newer version of Trellix® Data Exchange Layer.

Each type of installation includes a workflow of steps that must be completed in a specific order.

First-time installation workflow

DXL is installed as a ePO - On-prem extension. It includes the ePO - On-prem server files and DXL brokers.

When installing for the first time, you must install components in order shown below.

Vertical workflow infographic — a tall gray vertical bar at left with three numbered blue icons stacked top to bottom; to the right of each icon a blue-outlined rectangular box contains the step text. Top box text: Install the DXL extensions on Trellix ePO – On-prem server. Middle box text: Check in the DXL packages on Trellix ePO – On-prem server. Bottom box text: Install the DXL brokers.

Upgrade installation workflow

To upgrade an existing installation, you install a new version of the ePO - On-prem extension, server files, and DXL brokers.

Install upgrades to the DXL components in this order:

Upgrade

Blue circular upload icon — white circle with blue border and an upward-pointing arrow inside

White gear icon on a blue square background — represents extensions

Upgrade the DXL extensions on Trellix ePO – On-prem server.

White checkmark in a box on a blue square background — represents package check-in

Check in the DXL packages on Trellix ePO – On-prem server.

White network/broker icon on a blue square background — represents DXL brokers

Upgrade the DXL brokers.

Things to consider before installing DXL

Before installing DXL, consider the size, the number of locations, and the unique needs of your environment. The number of brokers you install depends on the number of managed endpoints and the geographical locations of those endpoints. The DXL client is automatically installed with Trellix® Agent on each managed endpoint.

At the center of DXL is the DXL broker fabric, or framework. This is the backbone that enables the communication of events and tasks throughout your environment. Each DXL client installed on a managed endpoint connects to a DXL broker, and brokers form the fabric that sends and receives information.

Broker installation example

Consider these questions to ask when planning a DXL installation and determining the number of brokers to install.

How many systems do you manage?

The number of systems you manage determines the number of DXL brokers to install. As a rule, you need one broker per 50,000 managed endpoints, however, it's best to have at least 2 brokers so that you have a primary and a failover broker in the event the primary broker is unavailable.

How many ePO - On-prem servers are in your environment?

If you have multiple ePO - On-prem servers or multiple data centers, two additional brokers are required to make a Root Hub, a hub that provides a communication link between all regions. These Root Hub brokers don't accept DXL client connections and aren't counted in the overall broker scaling for the number of managed endpoints.

Do you have multiple networks?

Are your systems on a single network, or do you have different geographical locations on different networks?

Do you have a DMZ?

If you have managed endpoints that are in a DMZ, you need a broker inside the DMZ that can communicate with the DXL fabric.

Question

Answer

How many ePO - On-prem servers?

2

How many managed endpoints?

10,000 endpoints per server

How many data centers or regions?

1 region with 2 data centers

Question

Answer

Do clients outside the network need access (broker in a DMZ)?

Yes

Number of brokers to install

Based on the answers to the questions, the number of brokers needed is:

  • One broker for the first ePO - On-prem server to support its 10,000 managed endpoints.

  • One broker for the second ePO - On-prem server to support its 10,000 managed endpoints.

  • Two brokers for a Root Hub to connect the two ePO - On-prem servers. The brokers in this hub can be managed in either data center. The Root Hub doesn't service any clients and only exists for communication between the two data centers, or provides failover if a service is temporarily unavailable.

  • One broker for inside the DMZ that communicates outside of the DMZ.

Trellix DXL protocols and ports

The Trellix DXL framework uses network protocols and ports for communication between the Trellix DXL clients and brokers throughout your environment.

Make sure these ports are open and available for use with DXL. Port 8883 is used by default, but you can assign a different port for use with DXL.

Network architecture diagram showing components and labeled connections. Visible labels include: Global Threat Intelligence (GTI); SQL server with JDBC/SSL 1433 and ADO/SSL 1433; Trellix ePO server; connection labels HTTPS 8443 (Install), 8444; HTTP 80; HTTPS 8081; HTTPS 5432 (Reporting); DXL broker with DXL/TLS 8883; Agent Handler with HTTP 80, HTTPS 443, HTTPS 8081; HTTPS 8080, HTTPS 443; TE server; IS server and IS File HTTPS 443; and Endpoints (cloud).

Required software and versions

Make sure that your system environment meets all requirements and that you have administrator rights.

DXL broker requirements

Product

Minimum version

Installed on

VMware vSphere for use with MLOS brokers

ESXi 5.1

Virtual system

ePO - On-prem

  • 5.9.0 (applicable for 6.0.0)

  • 5.10.0 (applicable for 6.0.3 or later)

Virtual system or a physical system

Trellix® Agent Extension

  • 5.5.0 (applicable for 6.0.0)

  • 5.7.8 (applicable for 6.0.3 or later)

ePO - On-prem systems with brokers installed running CentOS, Red Hat, and Microsoft Windows

Trellix Agent

  • 5.5.0 (applicable for 6.0.0)

  • 5.7.8 (applicable for 6.0.3 or later)

Each of the endpoints that you want to manage that are running CentOS, Red Hat, and Microsoft Windows

DXL operating system requirements

For a list of supported operating systems, see KB90421.

Hypervisor support for DXL

You can install DXL on a hypervisor virtual machine. See KB90421 for a complete list of supported hypervisor software.

Standalone DXL broker requirements

Linux

Microsoft Windows

Recommended requirements

Processor

4 cores

4 cores

Memory

8 GB

12 GB

Disk space

25 GB

20 GB

Minimum requirements

Processor

2 cores

2 cores

Memory

4 GB

8 GB

Disk space

20 GB

20 GB

Install DXL 6.1.x using ePO - On-prem

Installing DXL extensions and DXL brokers on the ePO - On-prem server enables the communication throughout your environment.

  • Determine the number of DXL brokers you need.

  • Review and make sure the ports are available for use with DXL.

  • Make sure that your system environment meets all requirements.

  1. Download the DXL software from the Software Catalog or Trellix Products website.

  2.         Install the DXL extensions on the ePO - On-prem server.        

    1. Go to Menu → Software → Extensions and click Install Extension

    2.                 Install the extensions in this order:                

      • DXL Broker Management

      • DXL Client

      • DXL Client Management

      • Cisco pxGrid extension (if used)

  3.         Check in DXL packages to the ePO - On-prem Main Repository.        

    1. On the ePO - On-prem console, select Menu → Software → Main Repository.

    2.                 Check in these DXL packages:                

      • DXL Broker

      •                         DXL Platform, only if you are installing the DXL broker using an .iso or .ova file. If you are installing a broker on a Microsoft Windows Server system, or on a system running a supported operating system in Amazon Web Services (AWS), you do not have to check in the DXL Platform package.                    

    3. Click Next.

Blue circle information icon

Important

Before checking in the DXL Platform, the ePO - On-prem product package upload limit must be increased. See KB90036 for details.

d. Under Branch, select Current to check in the packages, then click Save.

4. Install the DXL broker software on:

  • Microsoft Windows

  • Linux

  • Virtual appliances using .iso or .ova file

  • systems running on AWS

Verify the DXL installation.

Install DXL broker software

Brokers are installed on virtual appliances or physical systems to send and receive messages between security products that are integrated with the DXL. The network of brokers tracks active clients and dynamically adjusts the message routing as needed.

Brokers can be installed on the same system as the ePO - On-prem Server, SuperAgents, or Agent Handlers. Use one of these broker components to install DXL brokers:

  • DXL broker package — Used to install on a Linux system, a Microsoft Windows Server system, or on a system running a supported operating system in Amazon Web Services (AWS)

  • .ova — Used to install on a VMware vSphere appliance

  • .iso — Used to install on virtual appliances (including VMware vSphere) or on a physical system

Deploying brokers only on systems with specific operating systems

In ePO - On-prem 5.x and Trellix Agent 5.x and later, when deploying a broker using a Product Deployment task, the deployment task does not consider the Target platform (operating system) option on the Product Deployment page. The brokers are installed on all supported systems, regardless of the operating system selection. This occurs on Microsoft Windows systems and Linux systems. There are two workarounds you can use to ensure the brokers are installed only on those systems you want. See KB91361 for details.

Install DXL brokers on Microsoft Windows Server

DXL brokers can be installed on Microsoft Windows Server system using the product deployment task.

  1. In ePO - On-prem, select Menu → Software → Product Deployment, then click New Deployment.

  2. On the New Deployment page:

  1. Enter a name for the deployment.

  2. Select Data Exchange Layer Broker from the Package drop-down list.

  3. Select the endpoints to deploy to.

  4. Configure any other settings, then click Save at the top of the page.

    The Product Deployment page opens with your new project added to the list of deployments. Also, a client task is automatically created with the deployment settings.

  1. Navigate to System Tree and select the DXL broker system.

  2. Go to Properties → Wake up Agents and select Force complete policy and task update. It might take a few minutes for the broker properties to be sent to ePO.

Install DXL brokers on a Linux system

You can install the DXL brokers on a managed Linux system using a ePO - On-prem deployment task.

  1. In ePO - On-prem, select Menu → Software → Product Deployment, then click New Deployment.

  2. Complete the new deployment information, then start the deployment.

  3. When the deployment task finishes, configure the broker.

    1. To use a communication port other than the default 8883, update the DXL broker configuration file /opt/McAfee/dxlbroker/conf/dxlbroker.conf. Change the listenPort setting.

      # The broker listen port
      listenPort=port number
    2. Update the firewall to allow communication on the broker port with the commands for your platform (replace <listenPort> with the correct port).

      • Red Hat Enterprise Linux 6.x / CentOS 6.x

        iptables -N DXLBROKER
        iptables -I INPUT -j DXLBROKER
        iptables -A DXLBROKER -p tcp -m tcp --dport <listenPort> -j ACCEPT
        service iptables save
        
        ip6tables -N DXLBROKER
        ip6tables -I INPUT -j DXLBROKER
        ip6tables -A DXLBROKER -p tcp -m tcp --dport <listenPort> -j ACCEPT
        service ip6tables save
      • Red Hat Enterprise Linux 7.x / CentOS 7.x

        firewall-cmd --zone=public --permanent --add-port=<listenPort>/tcp
firewall-cmd --reload

c. Restart the DXL Broker service.

$> service dxlbroker restart
  1. (Optional) For troubleshooting, use the log files for installing and deploying brokers on a Linux system.

    • /var/log/dxlbroker <version_number> <build_number>.log

    • /var/log/dxlbroker-uninstall.log

  2. In the ePO - On-prem System Tree, select the broker system and click Wake Up Agents, select Force complete policy and task update, then click OK. It might take a few minutes for the broker properties to be sent to ePO.

Install DXL 6.0.3 or later Broker appliance

You can install DXL brokers appliance on supported hypervisors using the .ova file and .iso file.

  • Based on your preference, download one of these files from the Software Catalog:        

    • Broker ISO

    • Broker OVA

  • Review the supported hypervisors for the DXL broker (KB90421).

  • Extract the downloaded .iso or .ova .zip file.

  1. Browse to select the DXL .ova or .iso file.

  2. If you're using the .iso file, you can allow the automatic installation of DXL platform. Turn on the system once it is complete.

  3.         Install and configure the DXL broker appliance.        

    1. Read and accept the license agreement.

    2. Create a root password for the appliance (minimum 8 characters and should not be a dictionary word).

    3. Specify the operational account name and real name, and enter Submit.

    4. Specify the Password for operational account name (minimum 8 characters and should not be a dictionary word) and enter Submit.

The account name is typically something like jsmith and is used to log on to and administer the appliance. The real name is your full name, for example, John Smith.

e. On the Network Selection page, enter ok.

For the version 6.1.2 or later, on the Network Setup page, select the IP version that matches your network environment.

  • IPv4

  • IPv6

  • Both IPv4 and IPv6

f. Select a configuration type, then enter Submit to continue.

  • DHCP - Selecting DHCP auto-assigns the IP address

  • Manual IP address — enter the information.

g. Enter the host name and domain name of the computer where you are installing the appliance, then enter Submit.

h. Enter up to 3 Network Time Protocol servers to synchronize the time of the appliance, then enter Submit.

Use the default server listed, or enter the address.

i. Enter the IP address or fully qualified domain name, port, and account information for your ePO - On-prem server, then enter Submit.

Note

The Trellix ePO user account must have administrator rights.

j. In a web browser, navigate to ePO - On-prem and verify that the ePO - On-prem server certificate's Common Name (CN) and fingerprint match the information shown.

Verifying certificates depends on your browser. For most browsers, click the Lock icon in the address bar to view certificate details.

k. Specify the port that DXL Broker uses, then enter Submit.

Use the default port or enter a port number within the range shown.

l. DXL broker reboots automatically. You can close the logon screen when it appears.

  1. Log on to ePO - On-prem as an administrator and verify that a DXL broker is listed in the System Tree.

  2. Click Wake Up Agents, select Force complete policy and task update, then click OK. It might take a few minutes for the broker properties to be sent to the appliance.

Install DXL brokers on a system running in AWS

DXL brokers can be installed on a system that is using any of the supported operating systems running in Amazon Web Services (AWS).

You must establish and maintain a VPN connection between the on-premise infrastructure for the DXL client and the AWS infrastructure for the DXL brokers. This VPN connection must be established full time to maintain connectivity between the brokers and the clients.

See the installation instructions for the specific operating system that you're using in AWS for details about installing brokers on that system.

Verify the DXL installation

After you install and deploy the DXL broker, verify that the installation was successful and that the brokers are connected to the DXL clients on the managed endpoints.

  1. On the System Tree main page, verify that the broker is listed and tagged as DXLBROKER.

    If it isn't tagged as DXLBROKER, run the Manage DXL Brokers server task.

  2. In the System Tree, select the DXL broker name, then click the Products tab to verify that the DXL broker and version are listed.

If the DXL broker and version aren't listed, click Wake Up Agents, select Force complete policy and task update, then click OK. It might take a few minutes for the broker properties to be sent to the appliance.

When the installation is successful, the installed brokers are tagged as DXLBROKER and the correct DXL version is displayed in the Products tab. When you click the Trellix shield icon in the Windows taskbar, the Trellix Data Exchange Layer heading displays the broker connection status, and the broker name, address, and port number that the DXL client is connected to.

Install DXL broker (local) on endpoints using ePO - SaaS

You can deploy the DXL local broker on endpoints using ePO - SaaS to allow DXL traffic on your local network. The Advanced Product Deployment page enables you to deploy DXL local broker to endpoints.

  1. Select Menu → Software → Product Deployment, then click Advanced Product Deployment link under Advanced Options.

  2. In the Advanced Product Deployment page, click New Deployment.

  3. Complete the new deployment information, then start the deployment. For more information, see ePO - SaaS Product Guide.

Configure DXL local broker

You can configure DXL local broker on a DXL broker using a local configuration file.

  1.         On the DXL local broker, create the brokerstate.policy file.        

    • On Windows — C:\ProgramData\McAfee\dxlbroker\policy\brokerstate.policy

    • On Linux — /var/McAfee/dxlbroker/policy/brokerstate.policy

  2. Populate the file with the DXL broker state configuration JSON.

Note

For bridging to work properly, an identical copy of this policy file must exist on each broker.

The following is a sample brokerstate.policy containing a fabric having a root hub (rootHub) with broker1 and broker2. A third broker (broker3) is a direct spoke off of the root hub.

{
  "hubs": [
    {
      "id": "rootHub",
      "primaryBroker": "broker1",
      "secondaryBroker": "broker2",
      "name": "Root Hub"
    }
  ],
  "brokers": [
    {
      "id": "broker1",
      "hostname": "broker1",
      "port": "8883",
      "altHostname": "192.168.1.1"
    },
    {
      "id": "broker2",
{
    "hostname": "broker2",
    "port": "8883",
    "altHostname": "192.168.1.2"
},
{
    "id": "broker3",
    "hostname": "broker3",
    "port": "8883",
    "altHostname": "192.168.1.3",
    "parentId": "rootHub"
}
]
}

Hub Fields:

id = Unique identifier of a hub.

parentId = (optional) The identifier of the hub or broker to connect (bridge) to. If blank, the hub will not initiate an outgoing bridge connection (only incoming bridge connections are possible).

primaryBroker = (optional) The identifier of a broker that is a member of this hub.

secondaryBroker = (optional) The identifier of a broker that is a member of this hub.

serviceZone = (optional) The service zone name established at this hub. If blank, a service zone will not be established.

Broker Fields:

id = The identifier associated with the broker. This must match the broker identifier (brokerId) in the dxlbroker.conf.defaults file for the corresponding broker.

parentId = (optional) The identifier of the hub or broker for this broker to connect (bridge) to. If blank, the broker will not initiate an outgoing bridge connection (only incoming bridge connections are possible).

hostname = The hostname or IP address of the broker.

Port = The port number of the broker.

altHostname = (optional) An alternate host name or IP address of the broker.

serviceZone = (optional) The name of the service zone that is established at this broker. If not specified, a service zone will not be established at this broker.

3. Restart the DXL local broker service.

Connect DXL client with DXL local broker

You can configure DXL client using policy to connect it with the DXL local broker. DXL client maintains local DXL connection and a DXL connection with the ePO - SaaS DXL fabric.

  1. Log on to ePO - SaaS as an administrator.

  2. Select Menu → Policy → Policy Catalog.

  3. From the Products list, select Trellix DXL Client.

  4. Select a policy and click Edit.

  5. In Broker Connection, select a broker you want to connect with DXL client.

Note icon

Note

Broker is available on the list only when you deploy it correctly.

  1. Edit the Published Name when you need a different hostname or IP address.

Upgrading to a new software version

Install DXL upgrades when they are available to get the latest features, enhancements, and security protection.

Before upgrading Trellix DXL, if using a Hypervisor virtual machine, create a snapshot of your virtual machine. If using a Linux system, back up your system.

Blue information icon Important

The C:\ProgramData\Package Cache\ folder and files, where the WiX installer stores its bundle and other data, must not be removed from systems running DXL. When upgrading DXL, this bundle is used to uninstall the previous version of DXL as part of the upgrade process. If the bundle isn't there, DXL upgrades will fail. Ensure that system users, administrators, or disk cleanup utilities are not deleting files in this folder to free up disk space.

The tasks for updating DXL are:

  1. Download the DXL software.

  2. Upgrade the DXL extensions on the ePO - On‑prem server.

  3. Check in the DXL packages.

  4. Upgrade the DXL broker software.

  5. Verify the upgrade.

Upgrade the DXL extensions in ePO - On-prem

Install the Trellix DXL extension upgrades on the ePO - On‑prem server.

Make sure that you've downloaded the latest DXL software extension.

Blue information icon Important

The DXL extension version must be the same or newer than the DXL broker version. You can't install an older extension version with a newer broker version.

  1. Select Menu → Software → Extensions.

  2. Click Install Extension and install the extensions in this order:

  • DXL Broker Management

  • DXL Client

  • DXL Client Management

  • Cisco pxGrid extension (if used)

Upgrading DXL Broker

Based on where you have installed DXL broker, select a method to upgrade your DXL broker.

Where the DXL broker is installed

Upgrade from version

Upgrade to version

Follow these instructions

On Managed systems

Any previous version

Latest version

Upgrade DXL brokers on managed systems using Product Deployment task

On DXL Broker appliances

5.x.x

6.0.0

Upgrade DXL broker appliance using Product Deployment task

5.x.x

6.0.3 or later

Upgrade DXL broker by transitioning to a new server

6.0.0

6.0.3 or later

Upgrade DXL brokers using Product Deployment task

6.0.3 or later

Latest version

Upgrade DXL brokers using Product Deployment task

On TIE appliances

5.x.x

6.0.0

Upgrade DXL Broker on TIE appliance using Product Deployment task

5.x.x

6.0.3 or later

Upgrade DXL broker by upgrading TIE appliance

6.0.0

6.0.3 or later

Upgrade DXL Broker on TIE appliance using Product Deployment task

6.0.3 or later

Latest version

Upgrade DXL Broker on TIE appliance using Product Deployment task

Upgrade DXL brokers on managed systems using Product Deployment task

You can upgrade DXL brokers that are installed on CentOS, Red Hat, or on Microsoft Windows systems managed by ePO - On-prem.

Make sure that you have checked-in the latest DXL packages to the Main Repository on the ePO - On-prem server.

Lightbulb tip icon

Tip

In ePO - On‑prem 5.10.0 and Trellix Agent 5.6.0 and later, when deploying a broker using a Product Deployment task, the deployment task does not consider the Target platform (operating system) option on the Product Deployment page. The brokers are installed on all supported systems, regardless of the operating system selection. There are two workarounds you can use to make sure the brokers are installed only on those systems you want. See KB91361 for details.

  1. ePO - On-prem, select Menu → Software → Product Deployment.

  2. Select New Deployment.

  3. Select the Data Exchange Layer Broker package and specify the other details.

  4. Save the task.

    The deployment task is created to install DXL broker.

  5. Navigate to System Tree and select the DXL broker system.

  6. Go to Properties → Wake up Agents and select Force complete policy and task update. It might take a few minutes for the broker properties to be sent to the ePO.

For any issues during the installation, see Troubleshooting.

Upgrade DXL appliance using Product Deployment task

Follow these steps to upgrade the DXL brokers that are installed on appliances using .iso or .ova.

  • Check whether the DXL broker is installed using DXL Broker standalone ISO or ova.        

    • In ePO console, navigate to Menu → System Tree.

    • Select a DXL broker system that you want to upgrade and go to System Properties tab.

    • Check the OS OEM Identifier field. If it displays DXL Platform, the DXL broker was installed using ISO/OVA of DXL broker.

  • Make sure that you have checked-in the latest DXL packages to the Main Repository on the ePO - On-prem server.

🔆 Tip

In ePO - On-prem 5.10.0 and Trellix Agent 5.6.0 and later, when deploying a broker using a Product Deployment task, the deployment task does not consider the Target platform (operating system) option on the Product Deployment page. The brokers are installed on all supported systems, regardless of the operating system selection. There are two workarounds you can use to make sure the brokers are installed only on those systems you want. See KB91361 for details.

  1. ePO - On-prem, select Menu → Software → Product Deployment.

  2. Select New Deployment.

  3. Select the DXL platform package and specify the other details.

  4. Save the task.

    The deployment task is created to install DXL platform.

  5. Navigate to System Tree and select the DXL broker system.

  6. Go to Properties → Wake up Agents and select Force complete policy and task update.

    It might take a few minutes for the broker properties to be sent to the appliance.

  7. (Mandatory) Verify that DXL platform deployment task is completed successfully and Agent communicates with the ePO server. It might take a few minutes.

  8. Repeat steps 1 and 2.

  9. Create the deployment task for Data Exchange Layer Broker.

  10. Repeat steps 5 and 6.

For any issues during the installation, see Troubleshooting.

Upgrade DXL broker by transitioning to a new server

Follow these steps to upgrade the DXL brokers appliance that is installed using .iso or .ova.

Check whether the DXL broker is installed using DXL Broker appliance ISO or OVA.

  1. In ePO console, navigate to Menu → System Tree.

  2. Select a DXL broker system that you want to upgrade and go to System Properties tab.

  1. Check the OS OEM Identifier field. If it displays DXL Platform, the DXL broker was installed using ISO/OVA of DXL broker.

Important

Use of product deployment task to upgrade from DXL 5.0.X/6.0.0 to the latest version is applicable only if DXL is installed on managed systems with the supported Microsoft Windows or Linux. You cannot use the product deployment task to upgrade from DXL broker appliance 5.x.x/6.0.0 to 6.0.3 or later version. See KB96242.

  1. Perform the fresh installation of DXL broker. You can,

    • install DXL broker version 6.0.3 or later on the managed systems with the supporting OS (Windows and Linux), or

    • install DXL broker version 6.0.3 or later on appliance using ISO/OVA.

  2. Verify that the DXL broker is installed.

Tip

DXL Broker 6.0.3 or later can communicate with the existing DXL Broker 6.0.0 or 5.x.x server. It ensures the high availability of DXL Broker fabric before you plan to remove the earlier version of DXL broker server.

  1. Replace the DXL broker server with a new server.

  2. Decommission the DXL broker server on your network.

Upgrade DXL Broker on TIE appliance using Product Deployment task

Follow these steps to upgrade the DXL broker 5.x.x to 6.0.0 that is installed using TIE server appliance .ova or .iso.

  • Check whether the DXL broker is installed using TIE Server ISO or OVA.

    • In ePO console, navigate to Menu → System Tree.

    • Select a DXL broker system that you want to upgrade and go to System Properties tab.

    • Check the OS OEM Identifier field. If it displays TIE Platform, the DXL broker was installed using ISO/OVA of TIE server.

  • Make sure that you have checked-in the latest DXL packages to the Main Repository on the ePO - On-prem server.

Blue lightbulb icon Tip

In ePO - On-prem 5.10.0 and Trellix Agent 5.6.0 and later, when deploying a broker using a Product Deployment task, the deployment task does not consider the Target platform (operating system) option on the Product Deployment page. The brokers are installed on all supported systems, regardless of the operating system selection. There are two workarounds you can use to make sure the brokers are installed only on those systems you want. See KB91361 for details.

  1. ePO - On-prem, select Menu → Software → Product Deployment.

  2. Select New Deployment.

  3. Select the Data Exchange Layer broker package and specify the other details.

  4. Save the task.

    The deployment task is created to install DXL broker.

  5. Navigate to System Tree and select the DXL broker system.

  6. Go to Properties → Wake up Agents and select Force complete policy and task update. It might take a few minutes for the broker properties to be sent to the ePO.

For any issues during the installation, see Troubleshooting.

Upgrade DXL broker by upgrading TIE appliance

TIE server 4.0.0 includes the DXL broker the latest version. In order to upgrade DXL broker from 5.x.x to 6.0.3 or later and DXL 6.0.0 to 6.0.3 or later installed on your TIE server 2.x.x/3.x.x, you need to upgrade TIE.

Check whether the DXL broker is installed using TIE server ISO or OVA.

  1. In ePO console, navigate to Menu → System Tree.

  2. Select a DXL broker system that you want to upgrade and go to System Properties tab.

  3. Check the OS OEM Identifier field. If it displays TIE Platform, the DXL broker was installed using ISO/OVA of TIE server.

Blue information icon Important

Use of product deployment task to upgrade from DXL 5.0.X/6.0.0 to 6.0.3 or later version is applicable only if DXL is installed on managed systems with the supported Microsoft Windows or Linux. You cannot use the product deployment task to upgrade from DXL 5.0.X/6.0.0 to 6.0.3 or later version on TIE appliances.

For more instructions on TIE package and upgrade steps, see TIE installation guide. See KB96242.

Before you decommission DXL broker running on TIE appliance, you must replace with the new DXL broker.

Verify the DXL broker upgrade

After you complete the DXL upgrade, verify that the upgrade was successful.

  • In the System Tree, select the DXL broker name, then click the Products tab to verify that the DXL broker and version are listed.

    If the DXL broker and version aren't listed, click Wake Up Agents, select Force complete policy and task update, then click OK. It might take a few minutes for the broker properties to be sent to the appliance. If the DXLBROKER tag doesn't appear in the System Tree, run the Manage DXL Brokers server task again.

When the upgrade is successful, the installed brokers are tagged as DXLBROKER and the correct DXL version is displayed in the Products tab. When you click the Trellix shield icon in the Windows taskbar, the Trellix Data Exchange Layer heading displays the broker connection status, and the broker name, address, and port number that the DXL client is connected to.

Replace the DXL broker server

Removing the DXL broker server from your environment disrupts the communication with the connected clients. Trellix recommends that you configure a new DXL broker server and ensure it is up and running to avoid the disruption.

For details about product features, usage, and best practices, click ? or Help.

  1. Configure setting on new DXL Broker server from old before you decommission. :

    1. Navigate to Menu → Server Settings → DXL Topology and click Edit.

    2. If the DXL broker server to be replaced is,

      • in the top-level broker, replace it with the new DXL broker server. For more details, see Configure DXL brokers.

      • assigned as part of hub, replace it with the new DXL broker server. For more details, see Configure DXL brokers.

      • part of DMZ environment, replace it with the new DXL broker in DMZ.

      • part of DXL bridge to connect two ePO servers, reconfigure the bridging of DXL fabrics with new DXL broker.

      • Service Zone enabled, then enable the same on the new DXL broker server.

      • has any Broker Extension enabled, then enable the same on the new DXL broker server.

Blue pencil-in-square icon Note

Ensure that DXL broker server to be removed does not have a child broker in hierarchy of DXL Topology.

Blue information-in-circle icon Important

After editing DXL topology, ensure that hierarchy contains a single DXL broker or a single hub at the top-level.

  1. Update the DXL broker preference in the DXL Client for ePO:

    1. Navigate to Menu → Server Settings → DXL Client for ePO and click Edit.

    2. If ePO client broker preference is set to only communicate with the DXL broker server to be replaced then change it to the new DXL broker server else no change required.

  2. Update the DXL Client policies:

    1. Navigate to Menu → Policy Catalog → Trellix DXL Client .

    2. Review the policy and if DXL client broker preference is set to only communicate with the DXL broker server to be replaced then change it to the new DXL broker server else no change required.

Blue lightbulb icon Tip

You can manually refresh the DXL Client policy by executing the remote command https://<ePO_system_IP_address>:8443/remote/dxl.client.updatePolicy in browser.

Troubleshooting the installation

Trellix provides log files and scripts that can help you resolve common issues that might occur during installation.

Troubleshooting DXL Broker upgrade issue on DXL Broker appliances

Perform these steps, when the DXL Broker product version is not updated on the ePO System Tree page even after the DXL Broker product upgrade deployment task was successful:

  1. Log on to DXL broker appliance using the root credentials.

  2. Run this command to restart the DXL broker: sudo service dxlbroker restart

  3. Log on to ePO console and navigate to System Tree.

  4. Select the DXL broker system and go to Properties → Wake up Agents.

  5. Select Retrieve all properties even if they haven't changed since the last time they were collected. If deselected, only retrieve changed properties.

This process would take a few minutes to update broker properties on ePO .

Accessing log files

To troubleshoot installation problems, view the log files. Depending on your operating system, have these files available if you contact Technical Support.

/var/log/dxlbroker-<version_number>-<build_number>.log
/var/log/DXLPlatform-<version_number>-<build_number>-<timestamp>.log
/var/McAfee/dxlbroker/logs/ipe-start.log
/var/McAfee/dxlbroker/logs/ipe.log
C:\ProgramData\McAfee\dxlbroker\logs\dxlbroker.log
C:\ProgramData\McAfee\dxlbroker\logs\ipe.log

Reconfiguring the installation using scripts

You can use scripts to reconfigure the DXL brokers and Trellix Agent installed using an .ova or .iso file. The scripts are located in

the /home/<username> directory. They must be executed with sudo permissions, for example:

sudo /home/myname/reconfig-dxl.

Script name

Description

Reboot?

change-hostname

Changes the host name of the current DXL broker appliance. It restarts the Trellix Agent and the broker.

Recommended

change-services

Enables or disables the DXL broker.

If the broker was initially disabled during first boot, the script prompts for broker configuration information. This is only applicable for DXL Broker installed using TIE appliance (TIE ISO and OVA)

No

reconfig-dxl

Reconfigures the DXL port.

No

reconfig-ma

Reconfigures the Trellix Agent. The agent and DXL broker services are restarted. New keystores are generated when the service starts.

Blue note icon

Note: Do not run this script on a broker in a ePO - On-prem environment that is in the process of migrating certificates. During the certificate regeneration process, running the script creates a certificate chain causing connection issues. Before using this script, read KB85043 for important information.

Recommended

reconfig-network

Reconfigures the current network interface to switch between DHCP and manual IP configurations.

With version 6.1.2, this script also supports changing the network protocol by allowing you to select IPv4, IPv6, or both IPv4 and IPv6.

Needed

reconfig-ntp

Reconfigures the Network Time Protocol servers.

No

Uninstall DXL brokers on managed systems

You can uninstall DXL brokers that were installed on a Linux or Microsoft Windows system. You cannot use Product Deployment to uninstall DXL brokers that were installed using an .ova or .iso file. However, you can decommission them.

  1. Select Menu → Software → Product Deployment → New Deployment.

  2. Complete and save the new deployment information for the uninstall.

  3. In the Product Deployment page, from the Action drop-down, select Uninstall. Then start the deployment to uninstall Data Exchange Layer Broker package.

Decommission DXL broker appliance

For details about product features, usage, and best practices, click ? or Help.

  1. Shut down and Decommission DXL broker server.

  2. Remove the DXL Broker system from the System Tree.

    1. Navigate to Menu → System Tree.

    2. Select the removed DXL broker system and go to Actions → Directory Management → Delete, and click OK.