Install and configure the TIE server, DXL brokers on a single appliance.
Make sure that the server extension is installed correctly and that it matches the version of the server before you deploy the OVA appliance.
Store your root password in a secure location.
Make sure that you have the following versions installed or upgraded to:
ePO - On-prem to version 5.10.0 CU 14 or later
Trellix Agent to version 5.7.8 or later
DXL to version 6.0.3 or later
See KB83368 for details about supported platforms, environments, and operating systems.
Download the OVA component for the server appliance from Software Manager (or Software Catalog on ePO - On-prem 5.10) or from the Trellix product download site, then extract.
Open the VMware vSphere client, then click File → Deploy OVF Template.
Browse to and select the *.ova file on your computer.
Click Next and complete the steps in the wizard.
Turn on the virtual machine and open a Console window.
Read and accept the license agreement. You can use scroll up and down arrows to see the details.
Select I Agree and press enter to accept the terms to continue.
Create a root password for the new server appliance.
For the root user, the username is
rootand password is whatever you have set it.Note
Root user has complete access to the server appliance. Choose the secure password accordingly.
Enter the operational account name, real name, and password for the admin user. Select Submit and click enter to continue
The account name is typically something like
jsmithand is used to log on to the server and to the managed services. The real name is your full name, for example,John Smith.Note
Admin user has access to the server appliance but not the complete access as root user.
On the Network Selection page, select a network device and continue.
On the Network Setup page, select the configuration type and continue.
Enter the host name and domain name of the computer where you are installing the new server appliance. Select OK and click enter to continue.
The host name entered here is shown on the System tree in ePO - On-prem.
Enter up to three Network Time Protocol servers to synchronize the time of the new server. Use the default servers listed, or enter the address for up to three servers.
Verify with your networking team that you can access the URLs from your network, or you can provide internal or external NTP servers. Select Submit and click enter to continue.
Caution
If the NTP servers are not synchronized, DXL and TIE handshake isn't completed immediately. The handshake process might take longer and might also fail if time isn't correctly synchronized among DXL Brokers, TIE servers, and ePO - On-prem. If NTP syncs fail, it will reboot the TIE server.
Enter the IP address, port, and account information for your ePO - On-prem server and continue. The user account must have administrator rights.
Before proceeding, verify the authenticity of the certificate fingerprint of your ePO - On-prem. In a browser, navigate to ePO - On-prem and verify that the fingerprint matches the one shown on the installation screen. If it does, select Yes and click enter to continue.
Note
In Windows, Internet Explorer and Chrome show the certificate information about using a built-in SHA-1 thumbprint. Firefox implements its own cross-platform and shows the certificate SHA-256 fingerprint.
You can select the services that you want to run on the new server.
(Applicable only if the DXL Broker is installed) Configure the DXL Broker port, select Submit and click enter to continue.
Verify that the installation finishes successfully.
All components must be in green to continue. If not, follow the suggestions to troubleshoot the issue.
When the logon screen appears, close it.
Verify that the new server is provisioned. In ePO - On-prem, select Menu → System Tree → My organization → Preset → This group and All subgroups to look in the domain where you installed the server appliance.
Verify that the registered server is provisioned correctly in ePO - On-prem as a managed system. Select Menu → Configuration → Registered Servers.
Verify that the operation modes are configured correctly. In ePO - On-prem, select Menu → Configuration → Server Settings → TIE Server Topology Management.
Important
The first two installed servers are assigned with an operation mode automatically. If you have more than two servers, the third instance is left unassigned (the operation mode of the third instance depends on your environment settings).
The appliance shows the DXLBROKER and TIESERVER tag, depending on the products installed.