Install and setup Trellix DLP Network Monitor – SaaS for the first time

Prev Next

To start using the Trellix DLP Network Monitor – SaaS appliance (hardware appliance or virtual appliance) with ePO - SaaS, use this workflow to deploy, install, and provision the Trellix DLP Network Monitor – SaaS appliance with ePO - SaaS.

  1. Before the installation:

    1. Obtain the Trellix DLP Network Monitor – SaaS subscription.

    2. Set up an Trellix ePO - SaaS account.

    3. Configure cloud storage for evidence and fingerprints.

  2. Manage users and accounts in Trellix ePO - SaaS.

  3. Configure the network information in Trellix ePO - SaaS.

    Configure the DNS server and NTP server for your appliance from ePO - SaaS.

    Note

    The DNS server details must be configured in ePO - SaaS before provisioning the appliance with ePO - SaaS. The DNS information entered in Setup Wizard is overwritten by the DNS information entered in ePO - SaaS configuration upon connecting to ePO - SaaS.

  4. Install the appliance software on a physical hardware appliance or on a virtual machine.

  5. (Optional) Allow WebSocket for communication between the appliance and ePO - SaaS, if you are using a firewall in your network.

    The appliance uses WebSocket protocol to communicate with some of the ePO - SaaS components. For successful provisioning and management of the appliance with ePO - SaaS, allow WebSocket communication between the appliance IP address and the Trellix Data Exchange Layer (DXL) URL in your firewall. For information about the DXL URL, see KB90878.

  6. Provision the appliance with ePO - SaaS:

    1. Generate the registration token in ePO - SaaS. The registration token generated in ePO - SaaS must be entered in the Setup Wizard while registering the appliance with ePO - SaaS. For generating the registration token, follow the instructions provided in Register appliances and servers.

    2. Register the appliance with Trellix ePO - SaaS from the Setup Wizard.

      Specify the registration token that you generated in ePO - SaaS, to register the appliance with ePO - SaaS. Optionally, you can specify the web proxy server settings and logon credentials for the appliance to connect to ePO - SaaS.

  7. (Optional) Configure proxy server settings in ePO - SaaS.

    If you haven't specified the proxy server settings in the Setup Wizard, enter the proxy server settings in this page. The settings in this page override the settings entered in the Setup Wizard. You can also use this task to update the proxy server settings in future, if required.

  8. Set up Active Directory connectors and register your Active Directory server with ePO - SaaS.

  9. After the installation:

    1. Create and configure policies.

    2. Verify policies.

    3. Verify the incidents in Protection Workspace.