Set up a cluster of Trellix DLP Network Monitor appliances

Prev Next

To load balance the analysis of incoming traffic, you can set up a cluster of Trellix DLP Network Monitor appliances.

  • Configure the Trellix DLP Network Monitor appliance for a cluster role from the Setup Wizard during installation.

  • Configure two or more Trellix DLP Network Monitor appliances with LAN 1 connected to the same network segment.

  • All appliances in a cluster must be in the same subnet or network.

  1. In ePO - On-prem, open the Policy Catalog.

  2. Select the DLP Appliance Management <version> product, choose the General category, and open the policy that you want to edit.

  3. In Load Balancing, select Enable.

  4. In Cluster ID, use the arrows to select a number to identify the cluster.

  5. In Virtual IP, enter a virtual IP address so that packets for the virtual IP address are sent to the cluster primary appliance.

    The appliances in the cluster use the netmask assigned to the physical IP address. The virtual IP address must be in the same subnet or network as the other Trellix DLP Network Monitor appliances, and cannot be the same IP address as any other appliance in the cluster.

    Caution

    The cluster ID and virtual IP address must be same for all members of a cluster.

  6. Click Save.

ePO - On-prem pushes the configuration to all appliances in the cluster when you apply the changes. It takes about five minutes for the cluster to stabilize and identify the cluster primary appliance and cluster scanners. The appliance descriptions then change accordingly in Appliance Management.