Run the Cluster installation on each of the nodes.
Log on to the Windows Server system to be used as the first node of the ePO - On-prem server cluster.
Use an account with local administrator permissions.
Locate the software you downloaded from the Trellix website and extract the files to a temporary location. Right-click Setup.exe and select Run as Administrator.
The executable is located in the downloaded ePO - On-prem installation folder.
Caution
If you try to run
Setup.exewithout first extracting the contents of the .zip file, the installation fails.The Trellix ePolicy Orchestrator-On-prem- InstallShield Wizard starts. Click Next.
On the Setup Type page, select the Cluster option, then click Next.
In the Choose Destination Location page, specify the path for the shared data drive, then click Next.
Use the same path for each node.
On the first node in the Set Virtual Server Settings page, provide this identifying information for the ePO - On-prem cluster:
ePO - On-prem Virtual Server IP address
ePO - On-prem Virtual Cluster name
ePO - On-prem Virtual Cluster FQDN
On subsequent nodes, the Virtual Server IP address, Virtual Cluster name, and Virtual Cluster FQDN are automatically provided. You must add the Cluster Configuration Passphrase to each subsequent node.
The installer searches for SQL Servers. If the installer finds any SQL Servers, it automatically moves to the next stage and the servers that it finds can be selected from a drop-down list.
If it doesn't find any SQL Servers, a dialog box appears asking if you want to search again. Click No to continue to the next step where the SQL Server information can be entered manually.
In the Database Information step, specify information for your database, then click Next.
Specify the Database Server and Database Name.
Database Server
If the installer found the SQL Server in the previous step, select your server from the drop-down list. If the server is not listed, enter the information manually by typing the name of the SQL Server.
If you are using dynamic SQL ports, enter the name of the SQL Server and the name of the SQL instance separated by a backslash. For example, if your SQL Server is called SQL Server and you are using the default instance name of MSSQLSERVER, enter
SQLServer\MSSQLSERVER.Database Name
This value is automatically populated with the name of the database. Enter a new database name to change the value.
Specify which type of Database Server Credentials to use.
Windows authentication
From the Domain menu, select the domain of the user account for accessing the SQL Server from the drop-down list. If the required domain is not listed, type the domain name, user name, and password.
SQL authentication
Type the user name and password for your SQL Server. Make sure that credentials you provide represent an existing user on the SQL Server with appropriate rights.
Note
The Domain menu is grayed out when using SQL authentication.
Click Next.
The installer attempts to connect to the SQL Server using the credentials given. If the installer can't automatically determine the port, this message appears: Setup was unable to access the SQL UDP port 1434. Click OK to return to the Database Information page. However, the SQL Server TCP port field is now available. Enter the port and click Next.
The Pre-Installation Auditor automatically starts. Review the results and correct any failures, then click Rerun. Once all checks have passed, click Finish.
In the HTTP Port Information step, review the default port assignment, then click Next to verify that the ports are not already in use on this system.
Important
You can change some of these ports now. When your installation is complete, you can change only the Agent wake-up communication port and Agent broadcast communication port.
In the Administrator Information step, type this information, then click Next.
Type the user name and password you want to use for your primary administrator account.
Type the server recovery passphrase.
The passphrase includes 14–200 characters, must not contain leading or trailing backslashes (\), spaces, double quotation marks ("), or characters below ASCII 32 or above ASCII 65535.
Important
Keep a record of this passphrase; you need it to restore ePO - On-prem using the Disaster Recovery Snapshot records and Trellix can't recover it.
In the Type License Key step, type your license key, then click Next.
If you don't have a license key, you can select Evaluation to continue installing the software in evaluation mode. The evaluation period is limited to 90 days. You can enter a license key after installation is complete from the ePO - On-prem Settings or Software Catalog. Optionally, if you want ePO - On-prem to automatically download the products you are licensed for after the installation completes, select Enable Automatic Product Installation. For more information, see Automatic Product Installation.
Note
The Enable Automatic Product Installation option is enabled by default and only available if you have a license key.
Accept the End-User License Agreement and click OK.
From the Ready to install the Program dialog box, decide if you want to allow Trellix to collect system and software telemetry data, then click Install to begin installing the software.
When the installation is complete, do not select Yes, I wish to launch Trellix ePolicy Orchestrator-On-prem now. Click Finish to exit the Setup program on the first cluster node.
In Failover Cluster Manager, move the ePO application role to the second node of the cluster by right-clicking the role, then select Move → Select Node. Select the second node of the cluster and click OK.
The role moves to the second node of the cluster.
Alternatively, shut down the first cluster node server: this automatically moves the role to the second node.
Log on to the Windows Server computer to be used as the second node of the ePO - On-prem server cluster.
Use an account with local administrator permissions.
Locate the software you downloaded from the Trellix website and extract the files to a temporary location. Right-click Setup.exe and select Run as Administrator.
The executable is located in the downloaded ePO - On-prem installation folder.
Caution
If you try to run
Setup.exewithout first extracting the contents of the .zip file, the installation fails.The Trellix ePolicy Orchestrator-On-prem - InstallShield Wizard starts. Click Next.
On the Setup Type page, select the Cluster option, then click Next.
In the Choose Destination Location page, click Change, and browse to the location on the shared drive where ePO - On-prem was installed in step 4, then click OK → Next.
In the Set Virtual Server Settings step, the details for the ePO - On-prem Virtual Server IP address, ePO - On-prem Virtual Cluster name, and ePO - On-prem Virtual Cluster FQDN are already populated. Enter the Cluster Configuration Passphrase that you chose in step 5 and click Next.
From the Ready to install the Program dialog box, decide if you want to allow Trellix to collect system and software telemetry data, then click Install to begin installing the software.
The install process on the second node completes much more quickly than on the first node.
When the installation is complete, do not select Yes, I wish to launch Trellix ePolicy Orchestrator-On-prem now. Click Finish to exit the Setup program on the first cluster node.