When you complete the ePO - On-prem Agent Handler software installation and configuration, your Agent Handler allows you to directly manage systems behind the DMZ.
You must have installed the Agent Handler hardware and operating system in the DMZ of your external network.
You must have access to the ePO - On-prem executable files located in the downloaded ePO - On-prem installation files.
For details about product features, usage, and best practices, click ? or Help.
Install the ePO - On-prem remote Agent Handler software. See the Trellix ePolicy Orchestrator - On-premises Installation Guide.
Use one of these methods to communicate through the Agent Handler to the ePO - On-prem server:
Create a subgroup of systems. This task uses a subgroup, NAT Systems, in the System Tree behind the DMZ.
In Agent Subnet, type IP addresses, IP address ranges, or subnet masks, separated by commas, spaces, or new lines.
To start the Agent Handler configuration on the ePO - On-prem server, select Menu → Configuration → Agent Handlers.
To open the Agent Handler Assignment page, select New Assignment.
Configure these settings:
Type an Assignment Name. For example,
NAT Systems Assignment.Next to Agent Criteria, click Add Tree Locations and the "..." to select a System Tree group (for example, NAT Systems) and click OK.
For example, select the NAT Systems group.
Next to Handler Priority, click Use custom handler list and Add Handlers.
From the list, select the Agent Handler to handle these selected systems.
Disregard the warning that appears.
Click Save.
To configure the Agent Handler as the highest priority for the systems behind the DMZ, click Edit Priority and configure these settings, from the Agent Handler Configuration page:
Move the Agent Handler to the top of the priority list by moving the Agent Handler names.
Click Save.
From the Agent Handler configuration page, in the Handler Status dashboard, click the number of the Agent Handler to open the Agent Handlers List page.
From the Agent Handler Settings page, configure these settings and click Save:
Option
Description
Published DNS Name
Type the configured name for the Agent Handler.
Published IP Address
Type the configured IP address for the Agent Handler.
From the Handlers List page, in the row for the Agent Handler in the DMZ, click Enable in the Actions column.
The systems designated to use the Agent Handler begin getting their changes during the next few agent-server communications.
Confirm that the Agent Handler in the DMZ is managing the systems behind the DMZ:
From the Agent Handlers Configuration page, in the Systems per Agent Handler dashboard, click the Agent Handler name in the list or its corresponding color in the pie chart.
From the Agents for Agent Handler page, confirm that the correct systems appear in the list.
It might take multiple instances of the agent-server communication before all systems appear in the list.
With the Agent Handlers in the DMZ and configured with the ePO - On-prem server, you can now directly manage systems with a Trellix Agent installed behind the DMZ.