Restore ePO - On-prem from the snapshot stored in a ePO - On-prem database. You can do this by reinstalling the ePO - On-prem software on a server with the Restore ePO from an existing database option enabled and configuring the installation to use an existing ePO - On-prem database.
Gather this information and complete these steps before beginning your installation. These steps make sure that your ePO - On-prem software can communicate with the SQL Server hosting the ePO - On-prem database.
If you are using dynamic ports for your SQL Server, verify that the SQL Browser Service is running.
If you are not using dynamic ports for your SQL Server, make sure that you know the ports that your SQL instance is using.
Make sure that the TCP/IP Protocol is enabled in the SQL Server Configuration Manager.
Note
Trellix Agent uses either the last known IP address, DNS name, or NetBIOS name of the ePO - On-prem server. If you change any one of these values, make sure that Trellix Agent has a way to locate the server. The easiest way to do that is to retain the existing DNS record, and change it later to direct the ePO - On-prem server's new IP address. After Trellix Agent successfully connects to the ePO - On-prem server, it downloads an updates
Sitelist.xmlwith the current information.
Note
We recommend that you change the FQDN first, and use the same IP address so that Trellix Agent on the end nodes communicates to the Agent Handler or the ePO - On-prem server using the last known IP address. After successful communication, Trellix Agent will update the new FQDN of the server. Once all systems communicate successfully using the IP address, you can change the IP address as Trellix Agent knows the new FQDN.
Note
Monitor the process because you might need to restart your system.
If you have Agent Handlers configured, log on to the systems where the Agent Handlers are installed, then open the Windows Services panel and stop the Trellix Event Parser and Trellix Apache services.
See your Microsoft software product documentation for more information about using the Windows Services panel.
Using an account with local administrator permissions, log on to the Windows Server that you want to restore ePO - On-prem to.
Extract the files to a temporary location, and double-click Setup.exe.
The version of ePO - On-prem being restored must be the same as the version used to create the snapshot in the database. You can download the correct version from the Trellix website.
Important
If you try to run Setup.exe without first extracting the contents of the .zip file, the installation fails.
The Trellix ePolicy Orchestrator-On-prem - InstallShield Wizard starts.
Select Restore ePO from an existing database snapshot and click Next to begin the installation process.
In the Install additional software step, any remaining prerequisites are listed. To install them, click Next.
In the Destination Folder step, click either:
Next — Install your ePO - On-prem software in the default location (C:\Program Files (x86)\Trellix\ePolicy Orchestrator - On-premises).
Change — Specify a custom destination location for your ePO - On-prem software. When the Change Current Destination Folder window opens, browse to the destination and create folders as needed. When finished, click OK → Next.
In the Database Information step, either select the SQL Server name from the Database Server drop-down list or manually enter the name of the SQL Server.
In the Database Name field, enter the name of the existing ePO - On-prem database containing the snapshot, specify the type of Database Server Credentials to use, then click Next.
Windows authentication — From the Domain menu, enter the domain of the user account you're going to use to access the SQL Server. Enter the user name and password for an account with sufficient permissions to access the SQL Server hosting the ePO - On-prem database.
SQL authentication — Enter the user name and password for an account with sufficient permissions to access the SQL Server hosting the ePO - On-prem database.
The Domain menu is grayed out when using SQL authentication.
You might need to specify the SQL Server TCP port to use for communication between your ePO - On-prem server and database server. The ePO - On-prem installation tries to connect using the default TCP port 1433, and to determine if a dynamic port is in use by querying the SQL Browser service on UDP port 1434. If those ports fail, you are prompted to provide a SQL Server TCP port.
In the HTTP Port Information step, review the default port assignments, then click Next to verify that the ports are not already in use on this system.
In the Administrator Information step, type the user name and password you used for your previously existing ePO - On-prem global administrator account.
Type the Keystore Encryption passphrase (also known as the Snapshot passphrase) for the snapshot in the ePO - On-prem database.
Click Install to begin the installation.
When installation is complete, click Finish to exist the InstallShield wizard.
If you restored ePO - On-prem to a server with a different IP address and DNS name than your previously existing server, configure a way to allow your managed systems to connect to your new ePO - On-prem server.
There are several ways to achieve this depending on your DNS vendor. The most common way is to create a CNAME record in DNS that redirects requests to the old DNS name to the IP address of the new ePO - On-prem server. For more information about this process, see Microsoft documentation.
If you stopped the Agent Handlers in step 1, and restored ePO - On-prem to a system with the same server name and IP address that it had previously, log on to the systems where the Agent Handlers are installed, then open the Windows Services panel and start the Trellix Event Parser and Trellix Apache services.
If you restored ePO - On-premto a system with a different name or IP address, see Restore Agent Handler connections.
Your ePO - On-prem software is now restored. If needed, double-click the Launch Trellix ePolicy Orchestrator-On-prem icon on your desktop to start using your ePO - On-prem server, or browse to the server from a remote web console (https:// <server_name>:<port>).