The server address list is a list of Endpoint Security (HX) and DMZ servers installed in your enterprise. If your enterprise deploys both Endpoint Security (HX) and DMZ servers on the network, you need to consider the deployment topology when you configure agent communication. For example, if a host endpoint will be used outside the enterprise network and its agent is expected to communicate with a DMZ server, the DMZ server’s address needs to be included in the server address list. Trellix recommends that the first server in the server address list be the most accessible to the largest number of hosts.
Appliance Address Order
Agents attempt to connect to the first Endpoint Security (HX) server listed in the server address list. If the first server is unavailable, the agent then attempts to reach the second server, and so on.
Note
The address order is set by the order in which you add the servers to the server address list. The first server added is the first one in the list. The second server added is the second in the list.
Provisioning Appliance
Endpoint Security (HX) versions 3.0 and later support the use of multiple provisioning servers for endpoints running Agent software version 20 or later and a single provisioning server for endpoints running TrellixEndpoint Security Agent (HX) software version 11 or earlier. Agents use provisioning servers to connect and complete their installation by establishing their cryptographic agent identity. Any Endpoint Security (HX) server, including a DMZ server, can be enabled to do provisioning. Endpoint Security (HX) provisioning servers must be accessible by agents within your company's network. DMZ provisioning servers must be accessible inside and outside your company's network.
Primary Appliance
If the endpoints in your environment have agent software versions earlier than version 20 installed, a single Endpoint Security (HX) server needs to be designated as the primary server. This server must be accessible within the network by all agents when they are initially installed on hosts. The primary server manages the initial provisioning of the agents. You can use either your internal Endpoint Security (HX) server or a DMZ server as your primary server.
The server address policy is available in the Agent Default Policy only. To update the settings for this policy you must access the default policy. You cannot access the Server Address policy category through any other policy.
Endpoint Security (HX) server administrators and operators can add or remove servers on the server address list.
Admin or Operator access when using the Web UI
The Endpoint Security (HX) server is physically installed on the network for agent access