Migrate Trellix DLP Network appliance policies and settings to ePO - SaaS

Prev Next

ePO - SaaS is a multi-tenant, enterprise SaaS model of ePO - On-prem, accessible through an internet browser. You can migrate Trellix DLP Network appliance policies and settings from your ePO - On-prem on-premises server to cloud using the ePO - SaaS Migration extension. This process allows you to manage your Trellix DLP Network appliance policies and settings that are migrated to the cloud using ePO - SaaS.

Make sure that these conditions are met.

  • You have an active ePO - SaaS account.

  • You have installed the ePO - SaaS migration extension in your current ePO - On-prem server.

    Note

    The ePO - On-prem version must be 5.3.1 or later.

  • The ePO - On-prem server has internet connectivity. If you're using a proxy server, make sure that you configured the proxy server settings properly. You can configure the proxy server settings from ConfigurationServer SettingsProxy Settings to download and install migration extension from Software Catalog.

  • The agent repository policies have proper proxy settings to connect to the ePO - SaaS server.

  • You have configured the proxy and firewall settings to allow communication with the ePO - SaaS server.

    Port

    Customer data center location

    ePO - SaaS URL

    443

    United States

    ui-*.manage.trellix.com

    Frankfurt

    ui-*.manage.trellix.com

    * Refers to the code specific to the country. For information about the ePO - SaaS URL, see KB90878.

  • (Optional) Allow WebSocket for communication between the appliance and ePO - SaaS, if you are using a firewall in your network.

    The appliance uses WebSocket protocol to communicate with some of the ePO - SaaS components. For successful provisioning and management of the appliance with ePO - SaaS, allow WebSocket communication between the appliance IP address and the Trellix Data Exchange Layer (DXL) URL in your firewall. For information about the DXL URL, see KB90878.

  • The ePO - SaaS tenant account that you're planning to link has an active subscription and administrator rights.

  • You have identified features that aren't supported and excluded them from the migration process.

  • You have explored the available options in ePO - On-prem from the MenuePO - SaaSePO - SaaS MigrationSettings page.

  • As OpenLDAP servers are not supported with ePO - SaaS, do these changes in the ePO - On-prem on-premises server:

    • Delete rules in DLP Policy Manager that refer to OpenLDAP server and apply the change.

    • Deselect OpenLDAP servers from Policy CatalogDLP Appliance Management Users and Groups and click Save.

    Failing to make these OpenLDAP server related changes can result in policy push failures after migration.

  • You can deploy an Active Directory connector on a Windows Server only. For Active Directory configuration migration, you need a minimum of two Windows Server systems, which are saved as Active Directory connectors, to support failover. You can register the system with either ePO - SaaS or ePO - On-prem.

  • Active Directory servers must be configured with domain names (DNS) only. The Active Directory Connector (systems) that you add must be in the same domain as that of the Active Directory servers registered with ePO - On-prem. Active Directory servers with server names and IP addresses can't be migrated, update such Active Directory servers with DNS.

  1. Log on to ePO - On-prem and select MenuePO - SaaS ePO - SaaS Migration.

  2. Configure ePO - SaaS account:

    1. Click Configure ePO - SaaS account. Enter your ePO - SaaS credentials, to link to an existing ePO - SaaS account.

    2. (If your account belongs to multiple tenants...) Select a tenant account from the tenant drop-down list. The tenant drop-down appears only if the user account is configured for multiple tenants.

    3. Click Link to ePO - SaaS Account.

      You have successfully linked your ePO - On-prem account to your ePO - SaaS account. The email ID used to log on is displayed in the left pane.

  3. Customize migration settings:

    1. Click Settings on the right side of the window, to customize your migration. You can select policies and Active Directory configuration from Migrate Resources.

      • Migrate Resources — Select Policy and Active Directory configuration to migrate to ePO - SaaS.

        Client Task and Tag aren't applicable to appliances.

      • Delete Systems after Migration — Select to delete the migrated policies and settings on the ePO - On-prem on-premises server after migrating to ePO - SaaS. If you aren't sure about the migrated resources, we recommend not to select this option.

      • Auto Migrate newly added Systems — (Recommended) Select to automatically migrate the newly added policies and settings.

    2. Click Save.

  4. Clone configuration to ePO - SaaS:

    1. Click Clone configuration to ePO - SaaS to copy the policies and settings to ePO - SaaS.

      You can see a list of Trellix DLP Network policies and settings that can't be migrated. In the context of appliances, features are referred to as systems.

      Note

      DLP Capture and automatic registration of document features are currently not supported.

    2. Click Clone to ePO - SaaS.

      If you have migrated the policies and settings earlier, the button appears as Clone again to ePO - SaaS. Click Clone again to ePO - SaaS to migrate the newly created or any policies and settings that were not migrated earlier. For example, if you have migrated your Trellix DLP Endpoint policies and settings earlier, you can click Clone again to ePO - SaaS to migrate the appliance policies and settings.

  5. Skip this step if you prefer to manually setup Active Directory server.

    Migrate Active Directory configurations to ePO - SaaS:

    1. Click Migrate active directory configurations to ePO - SaaS

      A list of Active Directory servers registered with ePO - On-prem is displayed. Active Directory servers registered with server names or IP addresses are disabled from migrating the configuration. You can reconfigure such systems with domain names and migrate.

    2. Select the Active Directory servers for which you want to migrate the configuration. Based on the system with which you have registered the Windows Server, select ePO - SaaS or On-Premises from the drop-down list, search, and add the server systems. Click GUID-7AAC22A2-66FC-4AFC-833A-C76F74AA7810-low.png to Save selected systems as AD connector. Migrating the configuration takes longer when systems are selected from On-Premises.

    3. Click the checkbox to choose the Active Directory servers. Click Migrate <n> AD configurations, where n is the number of Active Directory connectors that are selected for migrating the configuration. For migrating Active Directory configuration, you can choose a maximum of two Active Directory connectors.

      Migrating the configuration of each Active Directory server can take about 20–30 minutes and the migration status is displayed. Click Move to next step.

    Note

    The Migrate compatible systems to ePO - SaaS option isn't applicable to Trellix DLP Network - SaaS appliances.

The Trellix DLP Network appliance policies and Active Directory configuration are copied to ePO - SaaS. Migration begins during the next agent-server communication.

Log on to ePO - SaaS:

  1. Verify that all policies appear as expected.

  2. Verify that the connectors are installed successfully in ePO - SaaS from the MenuConfigurationDirectory Service page.

  3. After provisioning all appliances with ePO - SaaS, update policy assignments and groups in System Tree.

    The ePO - SaaS Migration extension tool migrates only the policies and settings from ePO - On-prem on-premises server to ePO - SaaS, but the policy assignments and appliance groups in System Tree are not migrated automatically:

    1. Create subgroups of appliances, as needed.

      By default, you can find appliances in the Lost and Found subgroup in System Tree after provisioning the appliances. You can drag and drop the appliances to the required subgroup, which inherits the group's policy assignments.

    2. Assign and push appropriate policies to the appliances in these subgroups. See, Assign and push a policy to a system and Assign and push a policy to configure a Trellix DLP Network appliance in the Product Guide.