The Endpoint Security Agent (HX) can be configured to use an HTTPS proxy server to access the Endpoint Security (HX) or to access the Internet. You can enable or disable the use of a proxy, and you can indicate where the proxy settings should be obtained or specify the proxy setting values manually.
Proxy settings are only supported for Trellix Endpoint Security Agent (HX) running version 25 or later. They can be specified for all of your host endpoints or for select host sets using the Endpoint Security (HX) Web UI or API.
If your enterprise uses an HTTPS proxy server, configure its settings before installing the Endpoint Security Agent (HX) software on your host endpoints.
Note
Endpoint Security Agent (HX) versions 30 or later provide host containment over proxy support for Windows and macOS endpoints.
Web traffic is not blocked for Endpoint Security Agent (HX) versions 27 or earlier running on contained Windows endpoints that use a proxy server to communicate with the Endpoint Security (HX).
Host containment works only at the IP protocol layer. If your Windows or macOS host endpoints running Endpoint Security Agent (HX) versions 27 or earlier use a proxy server that has been added to the containment allow list, a contained Windows or macOS host will still be able to send and receive Web traffic and other traffic. If you are using an agent proxy and you want to be able to contain compromised hosts, you must set up the proxy server with a separate IP address that can only be used to reach the Endpoint Security (HX). Use the Endpoint Security (HX) Web UI to add the proxy server IP address to the Allowed IP Addresses on the Containment Settings page.
See the Endpoint Security Agent (HX) Deployment Guideand the Endpoint Security Agent (HX) Administration Guide for more information.