ESM 11.6.x Hardware Guide

Prev Next

Appliance setup

Inspect packaging and appliance

     
  1. Inspect the packaging for damage.
  2.  
  3. After unpacking the product, inspect the appliance for damage.
Note:

If there is any sign of damage, mishandling, or tampering contact Trellix Support immediately for instructions, and do not install the product.

Install rail set and chassis (Generation 6)

     
  1. Install the inner rails on the chassis.    
           
    1. Locate the inner rails and attach them to the sides of the chassis.
    2.      
    3. Slide the inner rails forward until they click into place.
    4.      
    5. Verify the inner rails are securely attached.
    6.    
     
  2.  
  3. Install the outer rails in the rack.    
           
    1. Align the outer rails with the rack posts.
    2.      
    3. Secure the outer rails to the rack posts using the provided screws.
    4.      
    5. Verify the outer rails are level and secure.
    6.    
     
  4.  
  5. Install the chassis in the rack.    
           
    1. With two people, lift the chassis and align the inner rails with the outer rails.
    2.      
    3. Slide the chassis into the rack until it is fully seated.
    4.      
    5. Secure the chassis to the rack using the captive screws on the front panel.
    6.    
     
  6.  
  7. Connect the cables as described in the network ports section.
Caution:

Always load the rack from the bottom up to prevent the rack from tipping.

Caution:

At least two people are required to lift and install the chassis into the rack.

Install rail set and chassis (Generation 5.5/5)

     
  1. Install the rails.    
           
    1. Attach the front brackets to the front rack posts.
    2.      
    3. Attach the rear brackets to the rear rack posts.
    4.      
    5. Slide the intermediate rail member into the outer rail.
    6.      
    7. Lock the ball retainer on each intermediate rail member.
    8.      
    9. Verify all rail components are securely attached.
    10.    
     
  2.  
  3. Install the chassis.    
           
    1. With two people, lift the chassis.
    2.      
    3. Align the chassis with the inner rails.
    4.      
    5. Slide the chassis into the rack.
    6.      
    7. Verify the chassis is fully seated.
    8.      
    9. Secure the chassis to the rack.
    10.      
    11. Verify all connections are secure.
    12.    
     
Caution:

Make sure that the ball retainer is locked on each intermediate rail member.

Remove the chassis

     
  1. Power off the appliance and disconnect all cables.
  2.  
  3. Remove the captive screws securing the chassis to the rack front panel.
  4.  
  5. With two people, slide the chassis out of the rack.
  6.  
  7. Place the chassis on a stable flat surface.

Generation 6 Hardware - Network ports

Caution:

Do not connect cables to ports not labeled for a specific purpose.

Trellix ESM

     
  1. Power supply
  2.  
  3. VGA video
  4.  
  5. USB port
  6.  
  7. COM port

Port connections

                                           
Slot numbers4-port systems8-port systems (add-on only)Connections
1Port 1Port 1Management 1
2Port 2Port 2Management 2
3Port 3Port 3HA
4Port 4Port 4Data
5BMC/RMMBMC/RMMBMC/RMM
6Port 5Data
7Port 6Data
8Port 7Data
Note:

The BMC/RMM port (port 5) is used for setup and troubleshooting.

                                           
Slot numbers4-port systems8-port systems (add-on only)Connections
1Port 1Port 1Management 1
2Port 2Port 2Management 2
3Port 3Port 3HA
4Port 4Port 4Data
5BMC/RMMBMC/RMMBMC/RMM
6Port 5Data
7Port 6Data
8Port 7Data

HA connections

     
  1. Connect the HA cable from the HA port on the primary appliance.
  2.  
  3. Connect the other end of the HA cable to the HA port on the secondary appliance.
  4.  
  5. Verify the HA link is established in the management interface.

Generation 5.5 Hardware - Network ports

Caution:

Do not connect cables to ports not labeled for a specific purpose.

Trellix ESM

     
  • Management 1
  •  
  • Management 2
  •  
  • VGA video
  •  
  • Data (not used)
  •  
  • MGMT

1U chassis

Note:

For 1U chassis, you must use the VGA port for monitor as the DisplayPort is not supported.

                                           
SlotPorts and connectorsAdditional informationFor Non-HAFor HA
1Management 1YesYes
2Management 2OptionalOptional
3HANoYes
4DataYesYes
5DataOptionalOptional
6DataOptionalOptional
7DataOptionalOptional
8IPMIOut-of-band managementOptionalOptional
                                           
SlotPorts and connectorsAdditional informationFor Non-HAFor HA
1Management 1YesYes
2Management 2OptionalOptional
3HANoYes
4DataYesYes
5DataOptionalOptional
6DataOptionalOptional
7DataOptionalOptional
8IPMIOut-of-band managementOptionalOptional

1U chassis HA connections

     
  1. Connect the HA cable to the HA port on the primary ESM.
  2.  
  3. Connect the other end of the HA cable to the HA port on the secondary ESM.
  4.  
  5. Verify the HA link LED is active.

2U chassis

                                           
SlotPorts and connectorsAdditional informationFor Non-HAFor HA
1Management 1YesYes
2Management 2OptionalOptional
3HANoYes
4DataYesYes
5DataOptionalOptional
6DataOptionalOptional
7DataOptionalOptional
8IPMIOut-of-band managementOptionalOptional

2U chassis HA connections

     
  1. Connect HA cable from primary ESM HA port.
  2.  
  3. Connect HA cable to secondary ESM HA port.
  4.  
  5. Connect management cable from primary ESM Management 1 port.
  6.  
  7. Connect management cable to secondary ESM Management 1 port.
  8.  
  9. Connect data cables to the appropriate data ports.
  10.  
  11. Connect the IPMI cable if out-of-band management is required.
  12.  
  13. Connect power cables to both power supplies.
  14.  
  15. Verify all connections before powering on.

Generation 5 Hardware - Network ports

Caution:

Do not connect cables to ports not labeled for a specific purpose.

Trellix ESM

Note:

Port assignments are the same on 1U and 2U chassis.

     
  • Management 1
  •  
  • Management 2
  •  
  • VGA video
  •  
  • Data (not used)
  •  
  • IPMI

1U chassis

                                           
SlotPorts and connectorsAdditional informationFor Non-HAFor HA
1Management 1YesYes
2Management 2OptionalOptional
3HANoYes
4DataYesYes
5DataOptionalOptional
6DataOptionalOptional
7DataOptionalOptional
8IPMIOut-of-band managementOptionalOptional

1U chassis HA connections

     
  1. Connect the HA cable to the HA port on the primary ESM.
  2.  
  3. Connect the other end of the HA cable to the HA port on the secondary ESM.
  4.  
  5. Connect management cables.
  6.  
  7. Connect data cables.
  8.  
  9. Connect IPMI cables if required.
  10.  
  11. Verify all connections before powering on.

2U chassis

                                           
SlotPorts and connectorsAdditional informationFor Non-HAFor HA
1Management 1YesYes
2Management 2OptionalOptional
3HANoYes
4DataYesYes
5DataOptionalOptional
6DataOptionalOptional
7DataOptionalOptional
8IPMIOut-of-band managementOptionalOptional

2U chassis HA connections

     
  1. Connect the HA cable to the HA port on the primary ESM.
  2.  
  3. Connect the other end of the HA cable to the HA port on the secondary ESM.
  4.  
  5. Connect management cables.
  6.  
  7. Connect data cables.
  8.  
  9. Connect IPMI cables if required.
  10.  
  11. Verify all connections before powering on.

Connect power and start appliances

     
  1. Connect the power cords to the power supplies on the rear of the appliance.
  2.  
  3. Connect the power cords to the power source.
  4.  
  5. Press the power button to start the appliance.
Important:

Connecting redundant power cords and power modules operating at normal conditions balances the load share, resulting in a more reliable power system.

Generation 6 LEDs

Power supply status LED

                               
ColorStateStatus
GreenSolidPower supply is operating normally
AmberSolidPower supply has failed
AmberBlinkingPower supply warning condition
OffNo power connected or power supply failure
Green/AmberAlternatingFirmware update in progress

External RJ45 NIC Port LED

                   
LED ColorDescription
GreenLink established at 1 Gbps
AmberLink established at 100 Mbps or 10 Mbps

System Status LED

                                                   
ColorStateDescription
GreenSolidSystem is on and operating normally
GreenBlinking (1 Hz)System is degraded
GreenBlinking (4 Hz)System POST in progress
AmberSolidNon-recoverable condition
AmberBlinking (1 Hz)System is in a degraded state
AmberBlinking (4 Hz)System is in a critical state
OffSystem is off
BlueSolidSystem is identified (UID on)
BlueBlinkingRemote console session is active
RedSolidSystem failure

Drive Activity and Status LED

                       
ColorStateStatus
GreenBlinkingDrive activity
AmberSolidDrive failure
OffNo drive installed or drive not in use
                                           
ColorConditionDrive TypeBehavior
GreenNormal operationAllBlinking with drive activity
AmberDrive rebuildHDD/SSDBlinking at 4 Hz
AmberDrive failureAllSolid
Amber/GreenDrive predicted failureAllAlternating
GreenIdentify modeAllBlinking at 4 Hz
OffNo driveOff
OffDrive not configuredAllOff
GreenDrive onlineAllSolid

Power button

                           
LEDStateDescription
GreenSolidSystem is powered on
GreenBlinking (1 Hz)System is in standby
OffSystem is off
AmberSolidSystem failure

BMC Boot or Reset Status LED indicators

                       
BMC Boot or Reset StateUID LEDStateStatus LED
BMC is bootingBlueSolidAmber blinking
BMC boot completeOffMatches system status
BMC reset in progressBlueBlinkingAmber blinking

Generation 5 LEDs

Power supply status LED

                                       
Power Supply ConditionLED State
Output on and OKGreen solid
No input powerOff
Power supply warningAmber blinking
Power supply failureAmber solid
Firmware updateGreen/Amber alternating
AC input detected, output offGreen blinking (1 Hz)
Power supply not installedOff

External RJ45 NIC Port LED

                                   
LEDColorLED StateNIC State
ActivityGreenBlinkingNetwork activity
ActivityOffSolidNo network activity
LinkGreenSolid1 Gbps link
LinkAmberSolid100 Mbps link
LinkOffNo link
LinkGreenBlinking10 Mbps link

System Status LED

                               
ColorStateCriticalityDescription
GreenSolidNormalSystem is on and operating normally
GreenBlinkingNormalSystem is in standby
AmberSolidCriticalSystem failure or critical event
AmberBlinkingNon-criticalSystem warning event
OffSystem is off or no power

Drive Activity and Status LED

                       
ColorStateStatus
AmberSolidDrive failure
AmberBlinking (4 Hz)Drive rebuild
OffNo drive or drive not in use
                                           
ColorConditionDrive TypeBehavior
GreenNormal operationAllBlinking with drive activity
AmberDrive rebuildHDD/SSDBlinking at 4 Hz
AmberDrive failureAllSolid
Amber/GreenPredicted failureAllAlternating
GreenIdentify modeAllBlinking at 4 Hz
OffNo driveOff
OffNot configuredAllOff
GreenDrive onlineAllSolid

Power or Sleep button

                           
StatePower ModeLEDDescription
OnFull powerGreen solidSystem is powered on
StandbyStandbyGreen blinkingSystem is in standby mode
OffOffOffSystem is powered off
FailureAmber solidSystem failure

BMC Boot or Reset Status LED indicators

                               
BMC Boot or Reset StateID LEDStatus LEDDescription
BMC is bootingBlue solidAmber blinkingBMC is initializing
BMC boot completeOffMatches systemNormal operation
BMC resetBlue blinkingAmber blinkingBMC is resetting
BMC firmware updateBlue solidAmber solidFirmware update in progress
BMC failureBlue blinkingAmber solidBMC failed to boot

Install Trellix Direct Attached Storage (DAS) appliance

     
  1. Power off the Trellix ESM appliance.
  2.  
  3. Mount the DAS appliance in the rack below the ESM appliance.
  4.  
  5. Connect the Mini SAS HD cable from port 1 of the ESM appliance to port 1 of the DAS appliance.
  6.  
  7. Connect the power cable to the DAS appliance.
  8.  
  9. Connect the power cable to the power source.
  10.  
  11. Power on the DAS appliance.
  12.  
  13. Power on the ESM appliance.
  14.  
  15. Log in to the ESM management interface.
  16.  
  17. Verify that the DAS appliance is recognized by the ESM.
Note:

Ensure the cable is attached from Mini SAS HD port 1 of Trellix ESM appliance to Mini SAS HD port 1 of DAS.

Caution:

Do not plug into any other ports unless directed by Trellix support.

Install qLogic 2460 or 2562 Storage Area Network (SAN) adapters

     
  • Verify the system is powered off before installing the adapter.
  •  
  • Ensure you have the correct adapter model for your system.
     
  1. Power off the ESM appliance.
  2.  
  3. Install the qLogic adapter into the appropriate PCIe slot.
  4.  
  5. Secure the adapter with the retaining screw.
  6.  
  7. Connect the fiber cables to the adapter ports.
  8.  
  9. Power on the appliance and verify the adapter is recognized.

Reset a Trellix SIEM appliance

     
  • Hardware failure requiring replacement
  •  
  • Forgotten administrator password
  •  
  • Corrupted operating system
  •  
  • Returning a device to factory defaults
Important:

Do not try to reset your device without consulting Trellix Support. This process deletes all event data on the device.

     
  1. Insert the recovery USB drive into the appliance USB port.    
           
    1. Power on the appliance.
    2.      
    3. Press F11 at the boot screen to enter the boot menu.
    4.      
    5. Select the USB drive as the boot device.
    6.      
    7. At the prompt, type -usb and press Enter.
    8.      
    9. Follow the on-screen instructions to complete the reset.
    10.      
    11. Remove the USB drive when prompted.
    12.    
     
  2.  
  3. After the reset completes, the appliance restarts automatically.    
           
    1. Wait for the appliance to fully boot.
    2.      
    3. Log in using the default credentials.
    4.      
    5. Reconfigure the appliance as needed.
    6.      
    7. Restore data from backup if available.
    8.      
    9. Verify the appliance is operating normally.
    10.      
    11. Contact Trellix Support to confirm the reset was successful.
    12.    
     
Important:

Make sure that you enter -usb even if the prompt asks you to press Enter.

Replace a Trellix SIEM appliance

     
  1. Back up all data and configuration from the existing appliance.
  2.  
  3. Power off the existing appliance and disconnect all cables.
  4.  
  5. Remove the existing appliance from the rack.    
           
      Note:

      For some types of rails, you might need to remove a stud from the side of the chassis.

         
     
  6.  
  7. Install the new appliance in the rack.
  8.  
  9. Connect all cables to the new appliance.
  10.  
  11. Power on the new appliance and restore the configuration from backup.

Replace Trellix Direct Attached Storage (DAS) appliance

     
  1. Back up all data from the DAS appliance.
  2.  
  3. Power off the ESM appliance.
  4.  
  5. Power off the DAS appliance.
  6.  
  7. Disconnect all cables from the DAS appliance.
  8.  
  9. Remove the DAS appliance from the rack.
  10.  
  11. Install the new DAS appliance in the rack.
  12.  
  13. Connect all cables to the new DAS appliance.
  14.  
  15. Power on the DAS appliance.
  16.  
  17. Power on the ESM appliance and verify the new DAS is recognized.
Note:

Ensure the Mini SAS HD cable is connected from port 1 of the ESM to port 1 of the replacement DAS.

Caution:

Do not connect cables to ports not intended for the DAS connection.

Configure the IPMI interface on the HA Receiver

     
  1. Log in to the HA Receiver management interface.
  2.  
  3. Navigate to the IPMI configuration section.
  4.  
  5. Select either DHCP or Manual configuration.
  6.  
  7. Configure the IPMI interface settings.                                                        
    SettingDHCPManual
    IP AddressAssigned automaticallyEnter static IP address
    Subnet MaskAssigned automaticallyEnter subnet mask
     
Tip:

Configure both interfaces to check the functioning interface.

Change Password on the HA receiver

     
  1. Connect to the HA Receiver via SSH or console.
  2.  
  3. Run the following command to list users:    
    ERCHA2-ERC-2650 ~ # ipmitool user list 3
     
  4.  
  5. Change the password for the appropriate user.                                                                                
    IDNameCallinLink AuthIPMI MsgChannel Priv Limit
    1anonymousfalsefalsefalseNO ACCESS
    2rootfalsetruetrueADMINISTRATOR
    3adminfalsetruetrueADMINISTRATOR
    4(empty)falsefalsefalseNO ACCESS
    5(empty)falsefalsefalseNO ACCESS
     

Configure appliance network connections

Configure the network interface for Trellix SIEM appliance

     
  1. Log in to the appliance console.
  2.  
  3. Access the terminal configuration menu.
  4.  
  5. Select Network Configuration.
  6.  
  7. Enter the IP address, subnet mask, and default gateway.
  8.  
  9. Enter the DNS server addresses.
  10.  
  11. Save the configuration.
  12.  
  13. Verify network connectivity.
Important:

The terminal menu doesn't prompt you to save changes when exiting. Save your changes before exiting or you'll lose your work.

Update the BIOS on Trellix SIEM Gen5.5 2U appliances

Important:

Make sure that you log in using the administrator password to remove the BIOS password from the appliance.

     
  1. Download the BIOS update file from the Trellix Support portal.
  2.  
  3. Copy the BIOS update file to the appliance.
  4.  
  5. Apply the BIOS update.    
           
    1. Log in to the appliance as root.
    2.      
    3. Navigate to the directory containing the BIOS update files.
    4.      
    5. Verify the files are present at the root level.
    6.      
    7. Run the BIOS update script.
    8.      
    9. Wait for the update to complete.
    10.      
    11. Do not interrupt the update process.
    12.      
    13. Note any messages displayed during the update.
    14.    
     
  6.  
  7. Restart the appliance to apply the BIOS update.    
           
    1. Initiate a system restart.
    2.      
    3. Enter the BIOS setup during POST if required.
    4.      
    5. Verify the new BIOS version is shown.
    6.      
    7. Configure BIOS settings as needed.
    8.      
    9. Save and exit the BIOS setup.
    10.      
    11. Wait for the system to boot completely.
    12.      
    13. Verify the appliance is operating normally after the update.
    14.    
     
Important:

Make sure that the BIOS update files are at the root level before proceeding.

Appliance certifications and specifications

SuperMicro-based platforms

                   
CertificationTrellix 1UTrellix 2U or 3U
Electromagnetic emissions/immunityFCC, CE, VCCI, KCC, BSMI, RCMFCC, CE, VCCI, KCC, BSMI, RCM
SafetyUL, CB, TUV, CE, BIS, KCUL, CB, TUV, CE, BIS, KC

DAS

                           
CertificationValue
Electromagnetic emissions/immunityFCC, CE, VCCI, KCC, BSMI, RCM
SafetyUL, CB, TUV, CE, BIS, KC
RoHSCompliant
Energy StarNot applicable
                                               
SpecificationDAS-120DAS-250
Form factor2U rack2U rack
Drive bays12 x 3.5"25 x 2.5"
InterfaceMini SAS HDMini SAS HD
Operating temperature10–35°C10–35°C
Shipping temperature-40–60°C-40–60°C
Operating humidity20–80% RH non-condensing20–80% RH non-condensing
Power supplyRedundantRedundant
Dimensions (H x W x D)3.5" x 17.2" x 21.5"3.5" x 17.2" x 21.5"
WeightContact Trellix SupportContact Trellix Support

Intel-based platforms

                                                       
ParameterLimits
Operating temperature10–35°C (50–95°F)
Shipping temperature-40–60°C (-40–140°F)
Operating altitude0–3048 m (0–10000 ft)
Shipping altitude0–12192 m (0–40000 ft)
Operating humidity8–90% RH non-condensing
Shipping humidity5–95% RH non-condensing
Operating shock6G/11ms half sine
Unpackaged shock15G/11ms half sine
Packaged shockPer ISTA 2A
Packaged vibrationPer ISTA 2A
AC voltage100–240V
                                                           
ParameterLimits
Operating temperature10–35°C (50–95°F)
Shipping temperature-40–60°C (-40–140°F)
Operating altitude0–3048 m (0–10000 ft)
Shipping humidity5–95% RH non-condensing
Operating shock6G/11ms half sine
Unpackaged shock15G/11ms half sine
Packaged shockPer ISTA 2A
Packaged vibrationPer ISTA 2A
AC voltage100–240V
AC frequency50–60 Hz
Source interrupt20ms at 100V
SurgePer ISTA 2A