Installation requirements

Prev Next

Trellix CP has specific system, certificate, and network requirements for installation and operation.

For details about ePolicy Orchestrator - On-prem requirements, see the ePolicy Orchestrator - On-prem documentation.

Requirement

Details

Software

  • ePolicy Orchestrator - On-prem, versions 5.1 and later, on-premise only

  • Java SE 8.0 or later JRE

Hardware (physical or virtual)

  • 16 GB RAM

  • Dual Core CPU

Operating system

  • Windows Server 2008 64-bit with Service Pack 2 or later

  • Windows Server 2008 R2 64-bit with Service Pack 1 or later

  • Windows Server 2012 64-bit

  • Windows Server 2012 R2 64-bit

Note

For the latest information on supported platforms, environments, and operating systems, see KB86369.

Active Directory

You must know the:

  • Domain controller name or IP address of the LDAP server

  • Port number that LDAP runs on

SSL certificate

  • Public (not self-signed)

  • Obtained from a recognized authority like Verisign or Go Daddy

  • Matches the address (A) record defined in the Domain Name System (DNS) unless a wildcard (*) certificate is used

    Note

    In high availability environments, you can associate a wildcard certificate with multiple Trellix CP servers.

Certificate KeyStore

You must have a Certificate KeyStore (in Java KeyStore format) containing the public SSL certificate. Detailed instructions for importing a public certificate to the KeyStore can be found in the Tomcat documentation.

https://tomcat.apache.org/tomcat-7.0-doc/ssl-howto.html

You must know the:

  • KeyStore password

  • KeyStore alias given to the SSL certificate

Network

  • You must have a valid, externally facing URL to access the Trellix CP server

  • TCP port 443 must be free and available on the server

Router and firewall access rules

You must configure Windows Firewall on the Trellix CP server to:

  • Allow incoming traffic from all sources on TCP port 443

  • Allow incoming and outgoing traffic to LDAP port

Installation account

  • Use a valid LDAP account for installation.

    Note

    We recommend using service account credentials.

  • Use the same LDAP account to install the Trellix CP server and extension.

  • Elevated permissions aren't required.