If your Endpoint Security (HX) server is not managed by a Central Management appliance, you must configure the Network Security appliance to communicate with the Endpoint Security (HX) server.
The procedure described in this section is for Endpoint Security (HX) version 2.6 or later servers. If you upgrade to Endpoint Security (HX) 2.6 or later without upgrading to Central Management 7.6 or later, you need to perform these steps.
Important
Do not use this procedure if you have already integrated your Endpoint Security (HX) server with a Central Management appliance (see Integrating CM appliances and Endpoint Security servers). Using both types of integration will cause errors in the Central Management integration.
Alerts can only be sent from Malware Analysis or Email Security — Server appliance to the Endpoint Security (HX) server through a Central Management appliance. Attempts to send Malware Analysis or Email Security — Server alerts to the Endpoint Security (HX) server using the direct connection set up between a Network Security appliance and the server will fail. Trellix only provides the direct connection between Network Security and Endpoint Security (HX). Use the Central Management appliance connection with the Endpoint Security (HX) server for Malware Analysis and Email Security — Server alerts.
On your Endpoint Security (HX) server, enable CLI configuration mode.
hostname > enable hostname # configure terminal
Enable Trellix legacy appliance support for the Endpoint Security (HX) server:
hostname (config) # hx server detection legacy enable
Save your changes:
hostname (config) # write mem
Log in to the Web UI of the Network Security appliance and then click Settings. (On a Central Management appliance, click CMS Settings).
Click Notifications in the left navigation pane.
Verify that all HTTP event types are selected for the appliance.
Click the http table heading to access HTTP notification configuration fields. These fields allow you to define the HTTP connection with your Endpoint Security (HX) appliance.
Type a name for the Network Security appliance's direct connection to the Endpoint Security (HX) appliance in the Name box and then click Add HTTP Server.
Enter the Endpoint Security (HX) URL in the Server Url box:
https://<DNS-name-or-Endpoint-Security-IP>/alerts
For example:
https://123.456.78.90/alertsSelect the check box in the Enabled column for the Endpoint Security (HX) server connection. This enables HTTP notifications between the Network Security appliance and the Endpoint Security (HX) server.
Leave the Username and Password boxes for the Endpoint Security (HX) server connection empty.
Select All Events from the list in the Notifications column for the Endpoint Security (HX) server connection.
In the Delivery list for the server connection, select Per Event.
Select the SSL Enable box. Do not select the SSL Verify box for the Endpoint Security (HX) server connection.
In the Default Provider list, select Generic.
In the Message Format list, select JSON Extended.
Click Update to save the Endpoint Security (HX) server connection.