Appliance addressing

Prev Next

Your enterprise can use IP addresses or domain names (DNS) when configuring hostnames for agent communications with Endpoint Security (HX) servers.

  • Configure a single DNS address that resolves to the Endpoint Security (HX) server and DMZ server (also known as a split DNS). This option is the most flexible arrangement. It allows you to move and renumber appliances without reconfiguring agents and eliminates unnecessary agent connection attempts to unreachable appliances. However, this solution requires a more complex DNS configuration. It may be challenging to execute consistently in large networks. See also Designating provisioning appliances using a split DNS.

  • Configure a unique DNS address for each Endpoint Security (HX) server and DMZ server. This option allows you to move or renumber appliances without reconfiguring agents. However, this option requires consistent internal DNS resolution of the appliance name and may cause extra connection attempts by external endpoints to internal appliances that they cannot reach.

  • Configure a unique IP address for each Endpoint Security (HX) server and DMZ server. This option provides the most reliable connections from endpoints and does not require consistent internal DNS configuration throughout a large enterprise. However, this option is the least flexible option. If you move or renumber appliances, you may have to reinstall agents.

Important

You must decide which appliances will be your provisioning appliances before you download the installation software for your agents. When agent installation software is downloaded, the IP addresses or DNS names of the provisioning Endpoint Security (HX) servers are identified in the agent download package. See Designating provisioning appliances.