How agent-server communication works

Prev Next

Trellix Agent communicates with ePO - On-prem periodically to send events and make sure that all client system settings are up to date.

These communications are referred as agent-server communication. During each agent-server communication, Trellix Agent collects its current system properties, as well as events that have not yet been sent, and sends them to the server. The server sends new or changed policies and tasks to Trellix Agent, and the repository list if it has changed since the last agent-server communication. Trellix Agent enforces the new policies locally on the managed system and applies any task or repository changes.

Note

Repository is not available on McAfee ePO Cloud.

ePO - On-prem uses an industry-standard Transport Layer Security (TLS) network protocol for secure network transmissions.

When Trellix Agent is first installed, it calls into the server in 45 seconds. After, Trellix Agent calls in when one of the following occurs:

  • The agent-server communication interval (ASCI) elapses.

    Note

    After upgrading Trellix Agent extension on ePO - SaaS, the minimum ASCI value changes to 60 minutes for existing customer policies if its earlier ASCI value is less than 60 minutes. For more information, see KB94254. There is no change in the minimum ASCI value for the On-premise ePO.

  • Wake-up calls are sent from ePO - On-prem or Agent Handlers.

  • A scheduled wake-up task runs on the client systems.

  • Communication is initiated manually from the managed system (using the Agent Status monitor or command line).

  • A "Run Immediately" client task runs on the client systems.

Note

For details about how to troubleshoot agent-server communication failures in Trellix Agent 5.x.x, see KB90603.