How Trellix Agent responds to a restored ePO - On-prem server

Prev Next

Changes made to a restored ePO - On-prem server cause minimum impact to an existing Trellix Agent. Trellix Agent communication doesn't change because the Agent Handler IP addresses and FQDN didn't change.

By default, the Trellix Agent tries connecting to the ePO - On-prem server in this order, depending on the Agent Handler configuration:

  1. IP address of the Agent Handler and ePO - On-prem server.

  2. FQDN of the Agent Handler and ePO - On-prem server.

  3. NetBIOS name of the Agent Handler and ePO - On-prem server.

If you change any of these items, make sure the Trellix Agent has a way to locate the server. For example, using the CNAME record, change the existing DNS record so it directs to the new IP address. After the Trellix Agent successfully connects to the ePO - On-prem server, it downloads an updated Sitelist.xml with the current information.