Migrate using Trellix ePO - SaaS Migration extension

Prev Next

(This topic applies to Trellix DLP - SaaS.) Trellix ePO - SaaS is a multi-tenant, enterprise SaaS model of Trellix ePO - On-prem, accessible through an internet browser. You can migrate Trellix DLP Discover scans and policies from your Trellix ePO - On-prem server to the cloud using the ePO - SaaS Migration extension. This process allows you to manage your Trellix DLP Discover scans and policies that are migrated to the cloud using Trellix ePO - SaaS.

Before you begin

Make sure that these conditions are met.

  • You have an active Trellix ePO - SaaS account.
  • You have installed the Trellix ePO - SaaS migration extension in your current Trellix ePO - On-prem server.

    Note

    The Trellix ePO - On-prem version must be 5.9.0 or later.

  • The Trellix ePO - On-prem server has internet connectivity. If you're using a proxy server, make sure that you configured the proxy server settings properly. You can configure the proxy server settings from ConfigurationServer SettingsProxy Settings to download and install the migration extension from Software Catalog.
  • The agent repository policies have proper proxy settings to connect to the Trellix ePO - SaaS server.
  • You have configured the proxy and firewall settings to allow communication with the Trellix ePO - SaaS server.
    Port Customer data center location Trellix ePO - SaaS URL
    443 United States

    ui-*.manage.trellix.com

    Frankfurt ui-*.manage.trellix.com
    * Refers to the code specific to the country. For information about the Trellix ePO - SaaS URL, see KB90878.
  • The Trellix ePO - SaaS tenant account that you're planning to link has an active subscription and administrator rights.
  • You have identified features that aren't supported and excluded them from the migration process.
  • You have explored the available options in Trellix ePO - On-prem from the MenuePO - SaaSePO - SaaS MigrationSettings page.

Task

  1. Log on to Trellix ePO - On-prem and select MenuePO - SaaSePO - SaaS Migration.
  2. Configure Trellix ePO - SaaS account:
    1. Click Configure ePO - SaaS account. Enter your Trellix ePO - SaaS credentials, to link to an existing Trellix ePO - SaaS account.
    2. (If your account belongs to multiple tenants...) Select a tenant account from the tenant drop-down list. The tenant drop-down appears only if the user account is configured for multiple tenants.
    3. Click Link to ePO - SaaS Account.
      You have successfully linked your Trellix ePO - On-prem account to your Trellix ePO - SaaS account. The email ID used to log on is displayed in the left pane.
  3. Customize migration settings:
    1. Click Settings on the right side of the window, to customize your migration. You can select policies and Active Directory configuration from Migrate Resources.
      • Migrate Resources — Select Policy and Active Directory configuration to migrate to Trellix ePO - SaaS.

        Client Task and Tag aren't applicable to Trellix DLP Discover.

      • Delete Systems after Migration — Select to delete the migrated policies and settings on the Trellix ePO - On-prem on-premises server after migrating to Trellix ePO - SaaS. If you aren't sure about the migrated resources, we recommend not to select this option.
      • Auto Migrate newly added Systems — (Recommended) Select to automatically migrate the newly added policies and settings.
    2. Click Save.
  4. Clone configuration to Trellix ePO - SaaS:
    1. Click Clone configuration to ePO - SaaS to copy the policies and settings to Trellix ePO - SaaS.
      You can see a list of Trellix DLP policies and settings that can't be migrated.
    2. Click Clone to ePO - SaaS.
      If you have migrated the policies and settings earlier, the button appears as Clone again to ePO - SaaS. Click Clone again to ePO - SaaS to migrate the newly created or any policies and settings that were not migrated earlier. For example, if you have migrated your Trellix DLP Endpoint policies and settings earlier, you can click Clone again to ePO - SaaS to migrate the Trellix DLP Discover policies and scan settings.
  5. (Skip this step if you prefer to manually set up Active Directory server.)
    Migrate Active Directory configurations to Trellix ePO - SaaS:
    1. Click Migrate active directory configurations to ePO - SaaS
      A list of Active Directory servers registered with Trellix ePO - On-prem is displayed. Active Directory servers registered with server names or IP addresses are disabled from migrating the configuration. You can reconfigure such systems with domain names and migrate.
    2. Select the Active Directory servers for which you want to migrate the configuration. Based on the system with which you have registered the Windows Server, select SaaS or On-Premises from the drop-down list, search, and add the server systems. Click to Save selected systems as AD connector. Migrating the configuration takes longer when systems are selected from On-Premises.
    3. Click the checkbox to choose the Active Directory servers. Click Migrate <n> AD configurations, where n is the number of Active Directory connectors that are selected for migrating the configuration. For migrating Active Directory configuration, you can choose a maximum of two Active Directory connectors.
      Migrating the configuration of each Active Directory server can take 20–30 minutes and the migration status is displayed. Click Move to next step.

    Note

    The Migrate compatible systems to ePO - SaaS option isn't applicable to Trellix DLP Discover – SaaS .

Results

The Trellix DLP Discover scan settings, policies, and Active Directory configuration are copied to Trellix ePO - SaaS. Migration begins during the next agent-server communication.

What to do next

Log on to Trellix ePO - SaaS:

  1. Verify that all supported scans and policies appear as expected.
  2. Verify that the connectors are installed successfully in Trellix ePO - SaaS from the MenuConfigurationDirectory Service page.
  3. After you migrate all Trellix DLP Discover servers with Trellix ePO - SaaS, update policy assignments and groups in System Tree.

    The ePO - SaaS Migration extension tool migrates only the scans and policies from Trellix ePO - On-prem on-premises server to Trellix ePO - SaaS. Apply policy to run the migrated scans.

Note

After you migrate, make sure that you delete all registered Trellix DLP Discover servers from the Trellix ePO - On-prem System Tree. If these aren't deleted, Trellix ePO - On-prem can try to re-register these Discover servers and manage them again from Trellix ePO - On-prem.