Enable relay capability

Prev Next

Configure and assign policies on an agent to convert it to a RelayServer.

Note

If enabling a non-Windows system as a RelayServer, make sure that you manually add an exception for the macmnsvc, masvc, macompatsvc, and Mue_InUse processes and the service manager port to the iptables and ip6tables.

  1. Select MenuSystemsSystem TreeSystems tab, then select the required group under System Tree.

    All systems in this group appear in the details pane.

  2. Select the required system, then click ActionsAgentEdit Policies on a Single System.

    The Policy Assignment page for that system appears.

  3. From the Product drop-down list, select Trellix Agent.

    The policy categories are listed with the system’s assigned policies.

  4. Click Edit Assignment under Actions corresponding to the General policy category.

  5. Next to the Inherit from option, select Break inheritance and assign the policy and settings below to inherit the policies from.

  6. From the Assigned policy drop-down list, select My Default policies, then click Edit Policy.

    Note

    You can also create a policy by clicking New policy.

  7. On the SuperAgent tab, select these Relay Client options as appropriate:

    • Select Enable Relay Communication to allow agents to discover RelayServers in the network.

    • Select Disable Discovery to disable UDP broadcast (discovery) in the client network to detect RelayServer.

      • Specify the RelayServer IP address or Host name and Port number through which the agent communicates with ePO - On-prem in the network.

  8. Select these ReleayServer options as appropriate:

    • Select Enable RelayServer to enable relay capability on an agent.

      • Configure the Service Manager port to 8083

        Note

        Enable relay capability in the organization's network. A RelayServer can't connect to ePO - On-prem using proxy settings.

    Note

    To disable the relay capability on Trellix Agent, deselect Enable Relay Communication and Enable RelayServer respectively.

  9. Click Save.

  10. Send a wake-up call.

After the first ASCI, the status of the RelayServer is updated in the Trellix Agent Properties page or the McTray UI on the client system.

The log file macmnsvc_<hostname>.log is saved in these locations:

  • On a Windows client system — <ProgramData>\McAfee\Agent\Logs

  • On a non-Windows client system — /var/McAfee/agent/logs