Deploy an on-premises appliance by completing the following steps.
Task | Instructions |
|---|---|
1. Verify that your environment meets the necessary requirements. | See System Requirements. |
2. Gather license information from Trellix. | Get license keys from Trellix if the license update service is not enabled. See About License Keys. |
3. Configure your Endpoint Security (HX) physical appliance. |
|
4. Install the required Trellix licenses. | Install the FIREEYE_SUPPORT and other licenses (if the license update feature is disabled). See License Management. The license update feature enables your appliance to automatically download and apply licenses to which you are contractually entitled. This feature is enabled with the configuration wizard during the initial configuration and is fully functional after the configuration wizard is completed. |
5. Configure other system administration features such as AAA, SSL certificates, and SNMP data access | See the Trellix System Security Guide and the Endpoint Security (HX) System Administration Guide. |
6. Verify that the Endpoint Security (HX) appliance is connected to Trellix's Dynamic Threat Intelligence (DTI) cloud. | If the validation fails, verify that the DTI configuration is set up correctly. See the Endpoint Security (HX) System Administration Guide. |
7. Attach your HXD (DMZ) appliances to the internal Endpoint Security (HX) appliance. | See Attaching and Detaching HXD Appliances. NoteYour Endpoint Security (HX) and HXD appliances must run the same version of the Endpoint Security (HX) software. If they use different versions, communication between them will fail. |
8. Set up the server address list. | |
9. Identify your provisioning appliances. | Agents earlier than version 20 can only provision against a single primary appliance. Agents version 20 or later can provision against multiple appliances. By default, your internal Endpoint Security (HX) hardware appliance is a provisioning appliance. A virtual appliance can be used as a provisioning appliance. See Understanding Provisioning. NoteYou must decide which appliances (Endpoint Security (HX) or DMZ) will be your provisioning appliances before you download the Trellix Endpoint Security (HX) Agent installation software to your host endpoints. When agent installation software is downloaded, the IP addresses or DNS names of the provisioning appliances are identified in the agent download package. |
10. Obtain the agent installation package. | If your Endpoint Security (HX) appliance is connected to DTI, the most recent Windows, macOS and Linux agent images are automatically downloaded to the appliance after the DTI connection is established. If your Endpoint Security (HX) appliance is not connected to DTI or if you need an older agent image than the ones that have been downloaded, you will need to manually download the agent image you need. ImportantIf you obtain your agent image manually, it must be uploaded to the Endpoint Security (HX) appliance before it can be deployed to your host endpoints. This ensures that the correct agent configuration file and agent certificates are included in the agent installation package and ensures that proper agent-appliance communication is established after the installation package is deployed on your endpoints. See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide. |
11. Install the agent software on your host endpoints. | See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide. NoteA single on-premises Endpoint Security (HX) ecosystem, which includes the Endpoint Security (HX) appliance and any attached HXD (DMZ) appliances, can support up to 100,000 agents. |
12. Optionally connect your Endpoint Security (HX) appliance to Helix. | After you have deployed your Endpoint Security (HX) appliance and installed the agent software on your endpoints, you can integrate the Endpoint Security (HX) appliance with Helix. If you connect your Endpoint Security (HX) appliance to Helix, see the Helix Getting Started Guide for information on how to get started with Helix. See also the Trellix System Security Guide for information on Helix's Identity Access Management (IAM) and single sign-on (SSO) authentication. ImportantThere are two versions of IAM. If the URL you use to access the IAM UI ends with |
13. Optionally, connect your Endpoint Security (HX) appliance to the Central Management System appliance or to a Network Security appliance. | After you have deployed your Endpoint Security (HX) appliance and installed the agent software on your endpoints, you can integrate the Endpoint Security (HX) appliance with Central Management System and Network Security appliances. For more information, see Integration. Additional information for managing your Endpoint Security (HX) appliance through the Central Management System appliance is provided in the Endpoint Security (HX) System Administration Guide. |