Communicating with devices uses the public and private interfaces of the traffic paths. This means that the device is invisible in the network because it doesn't require an IP address.
Management interface
Alternately, network administrators can configure a management interfaces with IP addresses for communication between Trellix ESM and the device. These device features require the use of a management interface:
Full control of bypass network cards
Use of NTP time synchronization
Device-generated syslog
SNMP notifications
Devices equipped with at least one management interface gives the device an IP address. With an IP address, Trellix ESM can access devices directly without directing communication toward another target IP address or host name.
Important
Do not attach the management network interface to a public network because it's visible to the public network and its security could be compromised.
Trellix ESM interface bonding
Trellix ESM tries to auto-enable bonded NIC mode when it detects two management interfaces that both use the same IP address. Ethernet bonding allows two (or more) ethernet interfaces to be combined so that they act like a single ethernet link. This allows for load sharing, load balancing and fault tolerance. When bonded mode is enabled, both interfaces are assigned the same IP address and MAC address. By default, the bonding mode used is mode 0 (round-robin), which provides fault tolerance.
To disable NIC bonding, change the IP address of one of the interfaces so that it no longer matches the other. The system then automatically disables bonded NIC mode.