Migrating between on-premises HX appliances and cloud Endpoint Security (HX) servers

Prev Next

If your organization has used an on-premises HX appliance and you are moving to a cloud Endpoint Security (HX) server, you need to migrate the agents that have provisioned with the on-premises appliance to the cloud server. This migration is critical to ensuring that your agents continue to communicate with an Endpoint Security (HX) server.

You may also need to migrate some appliance settings from the on-premises appliance to the cloud server.

Note

Trellix does not recommend that you simply change the domain name server (DNS) record of the on-premises appliance to point to the cloud server. While this can be done, the migration cut-over time may be uncertain due to long delays between DNS cache updates. This delay can make it difficult to diagnose migration problems.

A cloud Endpoint Security (HX) server is an instance of the Endpoint Security (HX) system image deployed in the Amazon Web Services (AWS) cloud. A single cloud Endpoint Security (HX) environment includes an Endpoint Security (HX) (master) server in the AWS cloud. The cloud Endpoint Security (HX) server is the provisioning appliance in a cloud Endpoint Security (HX) environment and all agent communication is with this server.

Prerequisites
  • Administrator access

  • The on-premises HX appliance and cloud Endpoint Security (HX) servers must both be the primary appliances in your Endpoint Security (HX) environment. When you run the show hx ecosystem command on each appliance, the output must include this line: Appliance Role: master.

  • All Endpoint Security (HX) controllers should be running the same operating system.

Migration steps

Follow these steps to migrate your agents from an on-premises HX appliance to a cloud Endpoint Security (HX) server.

Task

Instructions

1. Remediate all contained hosts in your environment and stop containing them.

Resolve all containment issues and uncontain all host endpoints before performing any further migration steps.

Contained host endpoints are blocked from communicating with other host endpoints and can only communicate with the Endpoint Security (HX) server that manages them. Consequently, any contained hosts managed by your on-premises HX appliance will not be able to communicate with the cloud Endpoint Security (HX) appliance if you migrate your agents without resolving the issues that required the hosts to be contained.

See "Containing Host Endpoints" in the Endpoint Security (HX) Server User Guide for more information about containment.

2. Confirm connectivity between the on-premises HX appliances and cloud Endpoint Security (HX) servers.

The on-premises HX appliance and cloud Endpoint Security (HX) servers must be able to connect to each other.

Do not attempt the migration if connectivity between the on-premises and cloud appliances cannot be established.

See Testing connectivity between the on-premises appliances and cloud Endpoint Security servers.

3. Verify that the on-premises and cloud appliances are running the same versions of Endpoint Security (HX) software.

Verify that the versions of the Endpoint Security (HX) software installed on your on-premises and cloud appliances are the same.

For each appliance, use the procedure described in Identifying the Endpoint Security software version on an appliance to identify the installed Endpoint Security (HX) software versions.

If the on-premises and cloud appliances are not running the same versions of Endpoint Security (HX) software, upgrade the appliance running the older version of the Endpoint Security (HX) software. See "Upgrading the Trellix Software" in the Endpoint Security (HX) System Administration Guide.

4. Enable quiesce mode for the on-premises HX series appliance.

The on-premises appliance must be put into quiesce mode. Enabling quiesce mode causes the HX appliance to stop generating tasks and aborts any queued tasks that have not yet completed on the agent, including file, data, and triage acquisitions and it stops the appliance from accepting new alerts. See Enabling and disabling Endpoint Security server Quiesce Mode.

5. Ensure that all agents have completed or aborted any outgoing jobs to the appliance.

After putting the on-premises HX appliance into quiesce mode, you must ensure that all of the agents have completed or aborted any ongoing jobs to the appliance. You can verify that the show hx app-proc command states the appliance is running quiesced and verify that the show hx messagebus command states that Quiesce mode is enabled.

6. Collect information and CA certificates for the cloud ecosystem.

Collect information about the cloud Endpoint Security (HX) server IP address, the server address list (SAL), and the CA certificates in your cloud Endpoint Security (HX) ecosystem. See Collecting cloud server information and CA certificates.

You will need to restore these later in this procedure.

7. Detach any on-premises HXD (DMZ) appliances or convert the HXD appliances to TCP relays.

If all of your host endpoints can communicate directly with the on-premises HX appliance, detach your on-premises HXD appliances. See Detaching on-premises HXD appliances.

If this is not possible, convert your on-premises HXD appliances into TCP relays to the on-premises HX appliance. See Converting an on-premises HXD appliance Into a TCP relay.

NOTE: Trellix recommends that you detach your on-premises HXD appliances, rather than use them as TCP relays.

8. Create a full backup of the on-premises HX appliance.

Create a full backup of the on-premises HX appliance. If you use the CLI, use the backup profile full to local command. Verify you have enough disk space before attempting the backup.

See "Backing Up the Database" in the Endpoint Security (HX) System Administration Guide.

9. Create a full backup of the cloud Endpoint Security (HX) (primary) server the cloud ecosystem.

Create a full backup of the cloud Endpoint Security (HX) (primary) server in your cloud Endpoint Security (HX) ecosystem. This will ensure your system can be restored to its original state if a problem in the migration should occur.

See "Backing Up the Database" in the Endpoint Security (HX) System Administration Guide.

10. (Optional) Download the full backup of the on-premises HX appliance.

Download the full backup of the on-premises appliance you created in Step 8.

See "Downloading Backup Files" in the Endpoint Security (HX) System Administration Guide.

11. (Optional) Upload the backup of the on-premises HX appliance onto the cloud Endpoint Security (HX) server.

Upload the full backup of the on-premises HX appliance onto the cloud Endpoint Security (HX) server using either the Web UI or the CLI.

Trellix recommends using the CLI restore profile full from local backup <backup file name> command so any problems that occur are more easily identified.

See "Restoring the Database from a Backup File" in the Endpoint Security (HX) System Administration Guide.

12. (Mandatory if you performed steps 10 and 11) Restore your original cloud configuration.

Restore the configuration from the Cloud Endpoint Security (HX) full backup to restore cloud specific configuration. You can use the command restore profile config from local backup <backup file name> to restore the configuration.

13. (Optional) Reset the password of the cloud Endpoint Security (HX) server

Reset the cloud Endpoint Security (HX) server password. It was set to the password of the on-premises appliance when you uploaded the backup in Step 11. See "Authentication" in the System Security Guide.

Caution

You can use the on-premises appliance password, but bear in mind that cloud passwords should be stronger passwords due to the number of illegal attempts to log in to cloud (Amazon Web Services) servers.

14. Verify the defined users and user roles are set appropriately for the cloud Endpoint Security (HX) server.

Verify the cloud Endpoint Security (HX) server users and user role (AAA) settings. These were overwritten with the on-premises appliance AAA settings when you uploaded the backup in Step 11. See Authorization" in the System Security Guide.

15. Set up the server address list in the cloud Endpoint Security (HX) ecosystem

Using the cloud Endpoint Security (HX) Web UI, set up the server address list for the cloud Endpoint Security (HX) ecosystem. See Setting up the server address list for the cloud Endpoint Security ecosystem.

16. Restore the cloud ecosystem certificates.

Restore the cloud Endpoint Security (HX) ecosystem certificates that you downloaded in Downloading the root and intermediate CA certificates of the cloud Endpoint Security ecosystem. See "Certificates" in the System Security Guide.

17. Disable quiesce mode for the cloud Endpoint Security (HX) appliance.

The cloud Endpoint Security (HX) server entered quiesced state when the on-premises HX backup was uploaded to it in Step 11. Disable quiesce mode for the cloud server. See Enabling and disabling Endpoint Security server Quiesce Mode.

18. Convert the on-premises HX appliance to a TCP relay for the cloud Endpoint Security (HX) server.

Convert the on-premises HX appliance into a TCP relay for the cloud Endpoint Security (HX) server. See Converting the on-premises HX appliance into a TCP relay.

When you complete these steps, the agents will initially connect to the on-premises HX appliance, but will be relayed to the cloud Endpoint Security (HX) server. In time, the cloud server will send the agents a new configuration file that includes provisioning information for the cloud Endpoint Security (HX) server. After the agents receive the new configuration file, they will connect directly to the cloud Endpoint Security (HX) server.

When all agents are connected directly to the cloud Endpoint Security (HX) server, the on-premises HX appliance will no longer be needed and can be shut down.