The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Back up and restore in FIPS mode

Prev Next

Back up and restore communication information for Trellix ESM devices in FIPS mode.

Primarily, you can use it if a failure requires Trellix ESM replacement. If the communication information is not exported before the failure, communication with the device can't be re-established. This method exports and imports the .prk file.

The private key for the primary Trellix ESM is used by the secondary Trellix ESM to establish communication with the device initially. Once communication is established, the secondary Trellix ESM copies its public key to the device's authorized keys table. The secondary Trellix ESM then erases the private key for the primary Trellix ESM, and initiates communication with its own public or private key pair.

  1. Export the .prk file from the primary Trellix ESM.

    1. On the system navigation tree of the primary Trellix ESM, select the device with communication information you want to back up, then click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png.

    2. Select Key Management, then click Export Key.

    3. Select Backup SSH Private key, then click Next.

    4. Type and confirm a password, then set the expiration date.

      Note

      After the expiration date passes, the person who imports the key is unable to communicate with the device until another key is exported with a future expiration date. If you select Never Expire, the key never expires if imported into another Trellix ESM.

    5. Click OK, then select the location to save the .prk file created by the Trellix ESM.

    6. Log off from the primary Trellix ESM.

  2. Add a device to the secondary Trellix ESM and import the .prk file.

    1. On the system navigation tree of the secondary device, select the system or group level node to which you want to add the device.

    2. From the actions toolbar, click Add Device.

    3. Select the type of device that you want to add, then click Next.

    4. Enter a name for the device that is unique in this group, then click Next.

    5. Enter the target IP address of the device. Enter the FIPS communication port, then click Next.

    6. Click Import Key, browse to the previously exported .prk file, then click Upload.

    7. Type the password specified when this key was initially exported.

    8. Log off from the secondary Trellix ESM.