Cloud Endpoint Security (HX) servers are initially deployed for you by Trellix, with appropriate Trellix licenses already established. Verify that you have access to the server, using the information provided when the server was set up for you.
When a new cloud Endpoint Security (HX) environment is initially established, it includes licenses, basic authorization roles, and the server address list for the cloud Endpoint Security (HX) ecosystem.
If you need to migrate your agents or server settings from an existing server to a cloud server, see Migrating between on-premises appliances and cloud servers.
Complete the following steps to tailor your new cloud Endpoint Security (HX) environment.
Task | Instructions |
|---|---|
1. Configure other system administration features such as AAA, SSL certificates, and SNMP data access. | See the Trellix System Security Guide and the Endpoint Security (HX) System Administration Guide. |
2. Verify that the Endpoint Security server is connected to Trellix's Dynamic Threat Intelligence (DTI) cloud. | If the validation fails, verify that the DTI configuration is set up correctly. See the Endpoint Security (HX) System Administration Guide. |
3. Review the server address list. | In a cloud Endpoint Security (HX) environment, the primary server deployed for you in the AWS cloud should appear in the server address list. |
4. Obtain the agent installation package. | If your Endpoint Security (HX) server is connected to the DTI, the most recent Windows, macOS, and Linux agent images are automatically downloaded to the server after the DTI connection is established. If your Endpoint Security (HX) is not connected to the DTI or if you need an older agent image than the ones that have been downloaded, you will need to manually download the agent image you need. See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide. |
5. Install the agent software on your host endpoints. | See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide. NoteA single cloud Endpoint Security (HX) ecosystem can support up to 100,000 agents. |
6. Optionally, connect your Endpoint Security (HX) server to Helix. | After you have deployed your cloud ecosystem and installed the agent software on your endpoints, the cloud Endpoint Security (HX) ecosystem can be integrated with Helix. This integration is set up for you by Trellix. If you connect your Endpoint Security (HX) server to Helix, see the Helix Getting Started Guide for information on how to get started with Helix. See also the Trellix System Security Guide for information on Helix's Identity Access Management (IAM) and single sign-on (SSO) authentication. ImportantThere are two versions of IAM. If the URL you use to access the IAM UI ends with In Helix, Central Management System of a cloud Endpoint Security (HX) is set up using the Central Management System Web UI. (Errors result for attempts to set up server management using the Central Management System CLI.) See the appendix "Configuring a Managed Appliance" in the Trellix System Security Guide. |
7. Optionally, connect your Endpoint Security (HX) server to a Central Management System series appliance. | After you have deployed your cloud Endpoint Security (HX) ecosystem and installed the agent software on your endpoints, you can integrate the cloud ecosystem with a cloud Central Management System appliance. For more information, see Integrating CM series and Endpoint Security servers. Additional information for managing your Endpoint Security (HX) servers through the Central Management System appliance is provided in the Endpoint Security (HX) System Administration Guide. |
Note
Trellix recommends that you add the following list of domains to an Allow List to permit communication between the agents and the HX server:
hex01.helix.apps.fireeye.com
hex01.apps.xdr.trellix.com
hex03.helix.apps.fireeye.com
hex03.apps.xdr.trellix.com
hex05.helix.apps.fireeye.com
hex05.apps.xdr.trellix.com
hex07.helix.apps.fireeye.com
hex07.apps.xdr.trellix.com
hex04.helix.apps.fireeye.com
hex04.apps.xdr.trellix.com
hex08.helix.apps.fireeye.com
hex08.apps.xdr.trellix.com
hex10.apps.xdr.trellix.com