Policy migration

Prev Next

The Endpoint Security (HX) server uses policies and settings to manage your xAgents. To prevent any disruptions to agent processes running on your endpoints, it is critical that your policies and settings remain the same following a Endpoint Security (HX) server upgrade to version 4.5 or later.

During an upgrade, your Endpoint Security (HX) server provides a migration path that automatically transfers and maps existing agent policies and settings to the corresponding policy type. Migrated policies retain the same host set assignments that were applied in your earlier software version.

You can view select migrated policies through the Endpoint Security (HX) Web UI or the API.

Important

Endpoint Security (HX) version 4.5 deprecate CLI commands used to set xAgent configuration.

The following table list the supported methods for viewing and editing each type of migrated policy.

Migrated Policy Type

View Method

Edit Method

Web UI

API

Web UI

API

Agent Default Policy

Yes

Yes

Yes

Yes

Migrated Exclusion and Exception Policies

Yes

Yes

No

No

Custom (Legacy) Policies

No

Yes

No

No

Migrated global policies and settings

Endpoint Security (HX) server 4.5, migrates all of your existing global policies and settings into the xAgent default policy, which is automatically assigned to all host endpoints in your environment. For example, if your existing Real-Time Indicator Detection global policy has RTID disabled, this settings is migrated and mapped to the xAgent Default Policy. RTID will remain disabled for all host endpoints in your environment, unless you assign a custom policy that enables this setting for select host sets.

You can modify settings in the xAgent default policy using the Endpoint Security (HX) xAgent Web UI or API.

Note

You cannot disable the xAgent default policy or change the policy priority level.

Migrated exclusion policies

If you have existing global exclusion policies that exclude processes, files and folders, or MD5 hashes from specific xAgent processes, these exclusion are also migrated and mapped to the xAgent default policy when you upgrade your Endpoint Security (HX) server to version 4.5 or later. For example, if you have an existing Exploit Guard exclusion policy that excludes specific files and folders, MD5 hashes, and processes from Exploit Guard processing, after you upgrade your Endpoint Security (HX) server to 4.7, you will find these exclusions in the xAgent default policy. Migrated exclusion policies apply to all host sets in your enterprise, unless you create a custom policy for select host sets that overrides the xAgent default policy.

Access your xAgent default policy in the Web UI or the API to edit your exclusion settings.

Migrated exception policy

The Endpoint Security (HX) server also migrates your existing host-set exclusions and maps them to separate exception policies when you upgrade your Endpoint Security (HX) server to version 4.5 or later. For example, if you have an existing Exploit Guard exclusion policy that excludes host sets from Exploit Guard processing, the Endpoint Security (HX) server migrates and maps your exclusion policy to a migrated_exploit_guard_protection_exception_set policy.

Important

Migrated exception policies have a higher priority level than the xAgent Default Policy.

You can view migrated exception policies in the Web UI or the API but you cannot edit the policy settings. If you need to edit a migrated exception policy you must first recreate the policy in the Web UI. The new custom policy must define values for all of the xAgent settings in the policy categories that comprised the exclusion policy. See Recreating a Migrated Policy for more information.

Migrating custom (legacy) policies

Custom polices created using an API custom configuration channel are migrated as custom (legacy) policies when you upgrade your Endpoint Security (HX) server to version 4.5 or later. Legacy policies retain their host set assignments and take priority over all other xAgent policies.

Configuration settings for legacy policies are only viewable through the API. Legacy policies are not displayed the Web UI. You cannot edit these policies, change their host set assignment, or priority level. If you need to modify a legacy policy, you must delete the policy through the API and create a custom policy in the Web UI that replaces it.

Access the Policy Details panel on the Assign Policies to Host Sets page to determine if a host set is assigned a legacy policy. If a select host set is mapped to a legacy policy, the Policy Details panel will display an alert notification indicating the host set has a custom configuration.

UI_Policy_Details_Legacy.png
Verifying xAgent policy migration

You can use the Web UI to determine if the Endpoint Security (HX) server successfully migrated your existing agent configuration to the xAgent Policy Service.

To verify policy migration:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Review all of the xAgent policies in the Policies table to ensure your global policy settings successfully migrated to the xAgent Default Policy.

    The Policies table should also list all your migrated exception policies for the correct policy category.

xAgent policy migration failure

If the xAgent policy migration process fails, all xAgent Policy Service functionality is disabled. Your xAgents will continue using the same configuration settings that existed prior to upgrading your Endpoint Security (HX) server to version 4.5. The Web UI will display an alert notification on the Policies page alerting you of the migration failure.

If you see the following alert notification, you should obtain the Syslog file from your Endpoint Security (HX) server and contact Trellix Support for assistance.

UI_Policy_Migration_Fail.png
To download the Syslog file from the Web UI:
  1. Log into the Web UI as administrator.

  2. From the Admin menu, select Appliance Settings.

  3. Click About to access the FireEye System Information page.

  4. Click Log Manager.

  5. Select the Syslog checkbox.

  6. Click Create to generate the Syslog file.

  7. After the Syslog file generation completes, click the Download button to download the file.