You can configure a Product Compatibility Check to automatically download a Product Compatibility List from Trellix.
This list identifies products that are no longer compatible in your ePO - On-prem environment.
ePO - On-prem performs this check any time the installation and startup of an extension might leave your server in an undesirable state. The check occurs:
During an upgrade from a previous version of ePO - On-prem
When an extension is installed from the Extensions menu
Before a new extension is retrieved from the Software Catalog
When a new compatibility list is received from Trellix
When the Data Migration Tool runs
See the Trellix ePolicy Orchestrator - On-premises Installation Guide for details.
Product Compatibility Check
The Product Compatibility Check uses an XML file, the Product Compatibility List, to determine which product extensions aren't compatible with a version of ePO - On-prem.
An initial list is included in the ePO - On-prem software package from the Trellix website. When you run setup during installation or upgrade, ePO - On-prem automatically retrieves the most current list of compatible extensions from a trusted Trellix source. If the Internet source is unavailable or if the list can't be verified, ePO - On-prem uses the latest version it has available.
The ePO - On-prem server updates the Product Compatibility List in the background once per day.
Remediation
When you view the list of incompatible extensions through the installer or the Upgrade Compatibility Utility, you are notified if a known replacement extension is available.
Sometimes during an upgrade:
An extension blocks the upgrade and must be removed or replaced before the upgrade can continue.
An extension is disabled, but you must update it after the ePO - On-prem upgrade is complete.
Disabling automatic updates
You might want to disable automatic updates of the Product Compatibility List. The download occurs:
As part of a background task.
When the Software Catalog content is refreshed (helpful when your ePO - On-prem server does not have inbound Internet access).
When you re-enable the download setting for the Product Compatibility List (also re-enables Software Catalog automatic updates of the Product Compatibility List).
Using a manually downloaded Product Compatibility List
If your ePO - On-prem server does not have Internet access, you can use a manually downloaded Product Compatibility List.
You can manually download the list:
When you install ePO - On-prem.
When using Server Settings → Product Compatibility List to manually upload a Product Compatibility List. This list takes effect immediately after upload.
Tip
Best practice: Disable automatic updating of the list to prevent overwriting the manually downloaded Product Compatibility List.
Open https://epo.trellix.com/ProductCompatibilityList.xml to manually download the list.
Blocked or disabled extensions
If an extension is blocked in the Product Compatibility List, it prevents the ePO - On-prem software upgrade. If an extension is disabled, it doesn't block the upgrade, but the extension isn't initialized after the upgrade until a known replacement extension is installed.
Command-line options for installing the Product Compatibility List
You can use these command-line options with the setup.exe command to configure Product Compatibility List downloads.
Command | Description |
|---|---|
| Disables automatic downloading of the Product Compatibility List from the Trellix website. |
| Specifies an alternate Product Compatibility List file. |
Both command-line options can be used together in a command string.