The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure network settings

Prev Next

Configure Trellix ESM connects to your network by adding server gateway and DNS server IP addresses, defining proxy server settings, setting up SSH, and adding static routes.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select the device and click Settings.png.

  3. Click Clustering.

  4. Select a shard and click the Settings tab.

  5. Main tab:

    • Define available interfaces. At least one interface must be enabled.

    • Define the local network, including IP addresses or subnets. Values are separated by commas.

    • Enable secure communication over SSH and enter the port used for SSH connections.

      Note

      Trellix ESM and devices use a FIPS capable version of SSH. SSH clients OpenSSH, Putty, dropbear, Cygwin ssh, WinSCP, and TeraTerm have been tested and are known to work. For Putty, go to http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html.

    • If you have enabled SSH connections, the systems listed can communicate through the SSH port. Deleting a system ID from the list disables communication.

    • IPv6 Settings:

      • Off — IPv6 mode is disabled.

      • Auto — the Primary and Secondary IPv6 fields are disabled. Each host determines its address from the contents of received user advertisements. It uses the IEEE EUI-64 standard to define the network ID part of the address.

      • Manual — the Primary and Secondary IPv6 fields are enabled.

  6. On the Advanced tab, set up Internet Control Message Protocol (ICMP) messages and the Intelligent Platform Management Interface (IPMI)

    • ICMP Messages

      • RedirectTrellix ESM ignores redirect messages.

      • Dest UnreachableTrellix ESM generates a message when a packet can't be delivered to its destination for reasons other than congestion.

      • Enable PINGTrellix ESM sends an Echo Reply message in response to an Echo Request message sent to an IPv6 multicast/anycast address.

    • IPMI Settings- Set the IPMI card to manage Trellix ESM devices if you have an IPMI NIC plugged into a switch.

      • Enable IPMI Settings — Enables access to IPMI commands.

      • VLAN, IP Address, Netmask, Gateway — Configures the network for the IPMI port.

  7. If your network uses a proxy server, set up the connection to your Trellix ESM on the Proxy tab.

    • On devices, if you have an interface that is using an IPv6 address, you can select IPv6. If not, IPv4 is selected.

    • Specify information required to connect to the proxy server: IP address, port, user name, and password.

    • Select basic authentication checking.

  8. On the Traffic tab, configure the maximum data output value for a network and mask to control the rate at which outbound traffic is sent.

    • Identify network addresses on which the system controls outbound traffic.

    • (Optional) - Identify the masks for the network addresses.

    • Identify the maximum throughput you defined for each network.

  9. On the Static Routes tab, configure static routes: IPv4 or IPv6 traffic, network IP address, network mask, and gateway IP address.

    A static route specifies how to reach a host or network not available through the default gateway. When you add a static route, the change is pushed to the Trellix ESM and immediately takes effect when you click Apply. Upon applying changes, Trellix ESM reinitializes itself, causing all current sessions to be lost.