Deploying agents in a VDI environment

Prev Next

Important

The .rpm or .deb file you use to install the agent software on your Linux endpoints must be compatible with your Linux operating system. For example, if your Linux endpoints are currently running RHEL version 6.8, you must use xagt-[xAgent version]- 1.el6.x86_64.rpm to install the agent software. If your Linux endpoints are running RHEL version 7.2 or 7.3, you must use xagt-[xAgent version]-1.el7.x86_64.rpm to install the agent software.

A virtual desktop infrastructure (VDI) is virtualization technology that allows you to host a user desktop inside a virtual machine. If you are deploying TrellixEndpoint Security Agent (HX) software in a VDI environment, Trellix recommends deploying in a persistent or semi-persistent VDI environment to prevent cloned agents.

Important

When deploying the Endpoint Security Agent (HX) software in a VDI environment, use the Specify an alternate Configuration File location option during installation.

If you need to deploy Endpoint Security Agent (HX) software in a non-persistent VDI environment, follow the recommendations in Guidelines for deploying agents in a non-persistent VDI environment to prevent cloned agents and reduce the number of duplicate hosts in your VDI environment.

Cloned agents are Endpoint Security (HX) agents that have provisioned with the Endpoint Security (HX) server using the same agent ID. Cloned agents may disrupt communication between your Endpoint Security (HX) server and host endpoints. See Agent Installation Considerations"Managing Cloned Agents" in the Endpoint Security Agent (HX) Administration Guide for more details.

Duplicate agents are Endpoint Security (HX) Agents that have provisioned with the Endpoint Security (HX) server using the same hostname.

To learn more about Endpoint Security Agent (HX) deployment in a VDI environment, see the community article on this topic.

Guidelines for deploying agents in a non-persistent VDI environment

Follow these guidelines to deploy Endpoint Security Agent (HX) software in a non-persistent VDI environment.

  • Use a Golden or master image to perform the initial installation. See Installing agents using a golden or master image.

    Important

    To perform any future updates of Endpoint Security Agent (HX) in a non-persistent VDI environment, you must uninstall the agent first and then reinstall the agent using an updated golden image.

  • From the Endpoint Security (HX) server Web UI Aging Settings page, lower your agent aging settings to reduce the number of duplicate hosts. See "Configuring Host Aging Settings" in the Endpoint Security Agent (HX) Administration Guide for more details.

    Important

    When a host endpoint is deleted, all alerts and acquisitions for that host endpoint are also deleted.

Note

If your server whitelist uses DNS names instead of IP addresses, this can cause problems in some scenarios for a contained host. Please ensure your server list (Admin > Containment Settings > Allowed IP Addresses) contains the IP address of your Endpoint Security (HX) Server.

VDI Pruning Tool

As a TrellixEndpoint Security (HX) administrator, you can remove duplicate hosts in a VDI environment with the VDI pruning tool. For more information about downloading the VDI pruning tool, see the community article on this topic.

Important

Data may be lost if you use the VDI pruning tool. To preserve all host attribute data on your Endpoint Security (HX) server, perform a manual host merge. See "Merging Hosts Manually" in the TrellixEndpoint Security Agent (HX) Administration Guide for more information on how to do this.