Add Subnets page
Use this page to add subnets to your network.
Option | Definition |
|---|---|
Choose method of adding | Provides options for adding subnets to the Trellix ePO - On‑prem server, including:
Use the following formats when importing:
|
Communication page (Trellix RSD policy pages)
Use this page to set the intervals used for sensor communication times, and configure optional active sensor election.
Option | Definition |
|---|---|
Sensor’s detected system cache lifetime | Specifies how long detected systems remain in the sensor’s memory cache. The maximum value for this field is 168 hours, or 7 days. The default is 5 minutes.
|
Reporting time for active sensors | Specifies how often the active sensors report to the server and send their detected data. Type the number and click hour(s), minute(s), or second(s) in the list. The maximum value for this field is 168 hours, or 7 days. The default is 5 minutes. |
Active sensor election | Specifies which method to use to determine the active sensors.
|
Detected Subnet Details page
Use this page to view the list of detected subnets in your network. Detected subnets are grouped in the following categories:
Contains Rogues
Covered
Ignored
Uncovered
From this location, select the checkbox next to subnets to perform actions on them. You can also click an individual subnet to view more details.
Option definitions
Option | Definition |
|---|---|
Actions | Specifies the actions you can take on this Detected Systems table, including:
|
Detected Subnets Information | Specifies information about detected subnets, including:
|
Sensor Information | Specifies the IP address of the sensor, whether it is active, its last communication time, and provides a link to the Rogue System Sensor Details page. |
Detected Subnets page
Use this page to view detected subnets. From this location, you can view details about the sensors installed on detected subnets, if any. To view subnet details, click the subnet row.
Option | Definition |
|---|---|
Actions | Specifies the actions that can be performed on selected entries in the Master Repository, including:
|
Detected System Interfaces Details page
Use this page to view details of detected system interfaces.
Option | Definition |
|---|---|
Detected System Interfaces Information | Specifies the details of the detected system interface, including:
|
Related Items | Provides links to information related to the detected system interface, including:
|
Detected Systems Details page
Use this page to view the details of an individual detected system.
Option | Definition |
|---|---|
Actions | Specifies the actions that can be performed on selected entries in the master repository, including:
|
Additional Detail for Managed Systems | Links to the ePolicy Orchestrator System Details page for this system. |
Detected System Interfaces | Specifies the detected system interface by number and details about each interface, including:
|
Option | Definition |
|---|---|
Detected Systems Information | Specifies information about the detected system you are viewing, including:
|
Detected Systems page
This is the main page for monitoring detected systems in your network. Use this page to monitor and manage the detected systems, subnets, and sensors on your network by using the following monitors and table:
Subnet Status monitor
Overall System Status monitor
Rogue System Sensor Status monitor
Top 25 Subnets table
Option | Definition |
|---|---|
Show/Hide Filter | Shows or hides the filter options |
Quick Find | Allows you to type search strings to find detected systems. Click Apply to perform the search. You can search for detected systems based on their IP address and MAC address.
|
Clear | Removes any text from the Quick find text entry box. |
Show selected rows | Displays only the rows you have selected. |
Actions | Specifies the actions you can perform on the selected rogue systems, including:
|
Detected Systems page
Use this page to view the list of detected systems on your network by category. Detected systems are grouped in the following categories:
Exceptions
Inactive
Managed
Rogue
From this location, select the checkbox next to systems to perform actions on them. You can also click an individual system to view more details.
Option | Definition |
|---|---|
Actions | Specifies the actions you can perform on detected systems, including:
|
Detection page (Trellix RSD policy pages)
Use this page to specify detection settings for Trellix RSD.
Option | Definition |
|---|---|
DHCP monitoring | Specifies the settings for Configuration Protocol (DHCP) monitoring. When you enable DHCP monitoring, a single sensor installed on a DHCP server can monitor all systems and subnets that it serves:
|
Device details detection | Specifies the settings for Subnet Port Scanning, which scans the ports your network uses to detect specific information about the devices connected to it: Note: This section is relevant for 4.x sensors only.
|
Report on self-configured subnets | Select the Enabled box to enable reporting on self-configured subnets. This setting prevents subnets that have a netmask of /32 from being ignored.
|
Sensor Scanning | Select Use active zero-configuration resolution to enable the sensor to send multicast DNS requests. This setting is enabled by default. Select Use DNS queries for DNS name resolution to enable the sensor to query DNS servers for DNS names. This setting is enabled by default.
|
Edit Detected System Compliance page
Use this page to edit the compliance settings for Trellix RSD. Compliance settings affect how Trellix RSD categorizes detected systems, and how coverage information is displayed in status monitors on the Detected Systems page.
Option | Definition |
|---|---|
Covered Subnets | Specifies the required coverage levels for covered subnets so that the color codes represent your requirements. These color codes affect the Subnet Status monitor on the Detected Systems page. |
Detected System definitions | Defines the categories for detected systems and specifies the time periods used in each category, including:
|
ePO Servers | Allows you to specify additional Trellix ePO - On-prem servers whose systems might come onto your network, that you don't want to be detected as rogue systems. |
Sensor Health | Specifies the ratio of active to missing sensors for sensor health, so that the color codes represent your requirements. These color codes affect the Rogue System Sensor Status monitor on the Detected Systems page. |
System Compliance | Specifies the required levels for compliant systems so that the color codes represent your requirements. These color codes affect the Overall System Status monitor on the Detected Systems page. |
Edit Detected System Matching page
Use this page to edit the matching settings for Trellix RSD. Matching settings affect how Trellix RSD determines if newly detected interfaces are on an existing system, and how Trellix RSD handles them when they are found.
Option | Definition |
|---|---|
Alternative McAfee Agent Ports | Specifies alternate ports to use when querying a detected system for a Trellix Agent. |
Matching Detected Systems | Defines the properties that determine when to match newly detected system interfaces to an existing detected system. |
Matching Managed Systems | Defines the properties that determine when to match newly detected system interfaces to an existing managed system. |
Static IP Ranges for Matching | Specifies the static IP address ranges for use when matching static IP addresses.
|
Edit Detected System OUIs page
Use this page to specify how your OUI (Organizationally Unique Identifier) file is updated. The OUI file allows ePolicy Orchestrator to identify product information about managed systems, such as manufacturer.
Option | Definition |
|---|---|
Last Updated | Specifies the last time Trellix ePO - On-prem server updated your OUI file. |
Update from | Specifies the source used to update the OUI file, including:
|
Edit Detected Systems Exceptions Categories page
Use this page to edit, add, or remove detected system exception categories.
Option | Definition |
|---|---|
Categories | Add new categories — Allows you to add new exception categories for detected systems.
|
Name | Name — Displays the name of any previously configured exception categories for detected systems. Description — Displays the description of any previously configured exception categories for detected systems. Change — Edits the detected system exception category. Delete — Deletes the detected system exception category. |
Edit Permission Set: Trellix RSD page
Use this page to select permissions for Trellix RSD.
Option | Definition |
|---|---|
Create and edit Rogue System information; manage Rogue Sensors | Grants the ability to deploy sensors, create and edit Trellix RSD configuration, and other data. |
Create and edit Rogue System information; manage Rogue Sensors; Deploy Agents and Add to System Tree | Grants full access to Trellix RSD.
|
No permissions | Grants no access to Trellix RSD. A user with this level of permissions cannot access any Trellix RSD assets. |
View Rogue System information | Grants only the ability to view Trellix RSD information. A user granted this level of permissions cannot create, edit, or modify information. |
Edit Permission Set: Rogue System Sensor page
Use this page to select permissions for the Rogue System Sensor.
Option | Definition |
|---|---|
Rogue System Detection : Policy | Controls access to the Rogue System Sensor. Choose from the following access levels:
|
Rogue System Detection : Tasks | Controls access to tasks generated by the Rogue System Sensor. Choose from the following access levels:
|
Edit Rogue System Sensor page
Use this page to edit the settings for the Rogue System Sensor.
Sensor settings affect how many sensors can be active on a subnet at one time, how long sensors stay active, and how long the Trellix ePO - On-prem server waits for a sensor to call in before designating it as missing.
Option | Definition |
|---|---|
Active Period | Specifies the maximum amount of time before the server asks a sensor to sleep, to allow a new sensor to become active. The maximum active period for a sensor is 24 hours (1,440 minutes). |
Sensors per Subnet | Specifies the maximum number of active sensors on a subnet at any time. Active sensors report system detections and other information during their active period. |
Sensor Scanning | Specifies a list of MAC addresses or OUIs that sensors do not scan, regardless of the sensor's policy. For version 5.0 sensors, you can add a list of IP addresses or subnet masks that sensors do not scan actively. The sensor does not scan these systems regardless of the sensor's policy settings. |
Sensor Timeout | Specifies the maximum amount of time a sensor can be out of contact before being designated as missing. The maximum sensor timeout period is 7 days (168 hours or 10,080 minutes). |
Server Settings Revision ID | Specifies the revision number of the setting. The ID is incremented every time the Server Settings are saved. |
Deploy McAfee Agent page
Use this page to send and install agents to selected managed systems.
Option | Definition |
|---|---|
Target systems | Displays the names of the systems that were selected when you clicked Deploy Agents. |
Agent version | Specifies the version of the agent to send and install on the selected systems. Agent versions that are available depends on which agent installation packages are checked in to the Master Repository. |
Installation options | Specifies the agent installation options available, including:
|
Installation path | Specifies the path on the client system (default is <system_drive>\McAfee\Common Framework) where you want to install the agent. The location you specify must exist on managed systems. |
Credentials for agent installation | Specifies the domain name, user name, and password of the user account with which to install the agent on selected systems. |
Number of attempts | Specifies the number of deployment attempts before it quits. Type 0 for continuous attempts. |
Retry interval | Specifies the interval in seconds between deployment attempts. |
Abort after | Specifies the number of minutes after the start of the agent deployment before the deployment quits. |
Import/Export Exceptions page
Use this page to import or export exceptions. From this location, you can import exceptions by MAC address or from a file, and export exceptions to a file.
Option definitions
Option | Definition |
|---|---|
Import Exceptions tab | Choose method of Importing — Specifies the method used for importing systems to the exceptions category in different formats, including:
|
Export Exceptions tab | Exporting — Exports a list of systems, categorized as exceptions, to a file. |
Add to System Tree page
Use this page to add a system to the ePolicy Orchestrator System Tree.
Option definitions
Option | Definition |
|---|---|
Systems to Add | Specifies the detected systems that you have selected to be added to the System Tree. |
System Tree Location | Specifies the location on the System Tree where you want to add the selected systems. Click Browse to open the Select System Tree Group dialog box, which allows you to navigate to the location where you want to add the selected systems. |
Duplicate System Names | Allows duplicate entries to be added to the System Tree. For example, you might have two systems with the same name. Allowing duplicate entries permits you to add the system with the duplicate name to the System Tree. |
Managed System for Subnet page
View the list of managed systems on the selected subnet. From this location, select the checkbox next to systems to perform actions on them. You can also click an individual system to view more details.
Option definitions
Option | Definition |
|---|---|
Apply Tag | Applies tag names that are used for sorting systems on your network.
|
Assign Policy | Opens the Assign Policy page for the selected systems. |
Change Sorting Status | Allows you to disable or enable System Tree sorting on the selected systems. |
Clear Tag | Removes previously applied tags from the selected systems. |
Delete | Removes the selected systems from the Detected Systems list. Deleting systems removes all references to them from the Trellix ePO - On-prem database. The next time ePolicy Orchestrator detects the systems, they are detected as new systems. |
Edit Description | Allows you to edit the user-defined description of the selected systems. |
Option | Definition |
|---|---|
Exclude Tag | Specifies system tags that can be used to exclude groups of systems when sorting.
|
Export Systems | Exports the selected systems to an external file. |
Filter | Specifies which managed systems in this subnet are shown in the table.
|
Modify Policies on a Single System | Opens the Policy Assignment page for the selected system. |
Modify Tasks on a Single System | Opens the Client Tasks page for the selected system. |
Move Systems | Opens the Select the New Group page to move the selected systems. |
Options | Specifies the available options.
|
Show Agent Log | Opens the Agent Log page. |
Sort Now | Sorts the selected systems according to their tags. |
Test Sort | Performs a test sort on the selected systems, and opens the Test Sort page. |
Merge Systems page
Use this page to manually merge detected systems into a single detected system. The detected systems listed in the Source System columns are combined into a single record with the properties listed in the Target System column.
Option | Definition |
|---|---|
Agent GUID | Specifies the globally unique identifier (GUID) of the agent deployed to the system. |
Canonical Name | Displays the friendly name of the system. The friendly name of a system is the least complex unique name available to identify the system. For example, a DNS name is less complex than an MAC address. Therefore, the DNS name is displayed instead of the MAC address, if it is available. |
Close | Cancels the merge operation and reopens the previous page. |
Comments | Displays user comments about the system. |
Computer Name | Specifies the name of the system. |
DNS Name | Specifies the domain name of the system. |
Domain | Specifies the domain the system is on. |
Exception | Specifies whether the system is selected as an exception. |
Ignored | Specifies whether the system has been ignored. |
Option | Definition |
|---|---|
Last Detected IP Address | Specifies the last detected IP address of the system. |
Last Detected IPv6 Address | Specifies the last detected IPv6 address of the system. |
Last Detected MAC Address | Specifies the last detected MAC address of the system. |
Last Detected Time | Specifies the date and time of the last detection of the system. |
Merge | Merges the systems detailed in the Source System columns into one detected system, with the details listed in the Target System column. |
NetBIOS Comment | Specifies the NetBIOS comment for the detected system. |
OS Family | Specifies the family of the operating system. |
OS Platform | Specifies the operating system installed on the system. |
OS Version | Specifies the version number of the operating system installed on the system. |
Users | Specifies the user logged on to the system at the last detected time. |
General page (Trellix RSD policy pages)
Use this page to configure general policy settings for Trellix RSD.
Option | Definition |
|---|---|
Rogue System Sensor | Enables sensors when they are deployed. |
Server name or IP address | Specifies the name or IP address of the system where your Trellix ePO - On-prem server is installed. Trellix RSD treats agents managed by any other Trellix ePO - On-prem server as alien agents. Therefore, the systems where those alien agents are deployed are identified as rogue systems. The default value in this field is the IP address of the system where Trellix RSD is installed. When changing this value, use standard IP address format (xxx.xxx.xxx.xxx), DNS name, or the FQDN. |
Log File Settings | Specifies whether the software logs only messages with Error and Critical priority or logs all messages.
|
Policy Revision ID | Specifies the revision number of the policy, which is incremented every time you save the policy.
|
Import Sensor Blacklist page
Use this page to import systems to the Rogue Sensor Blacklist.
Option | Definition |
|---|---|
Choose method of importing | Specifies the method for importing systems into the Rogue Sensor Blacklist, including:
|
Interfaces page (Trellix RSD policy pages)
Use this page to specify which interfaces sensors listen to.
Note
This page is relevant for 4.x sensors only.
Option | Definition |
|---|---|
Initial Interface Binding | Select this box to tell sensors to listen only to the interfaces whose IP addresses were present at the time of installation. |
Listen only on interfaces with IP addresses in these networks | Tells sensors to listen to interfaces only in user-specified networks. Type a network address and click Add To List to specify a network. Select a network from the list and click Remove From List to stop listening to interfaces on that network. IP addresses must use standard IP address format followed by the two-digit Classless Inter-Domain Routing (CIDR) that specifies the subnet mask. |
Do not listen on interfaces with IP addresses in these networks | Tells sensors not to listen to interfaces in user-specified networks. Type a network address and click Add To List to specify a network. Select a network from the list and click Remove From List to allow sensors to listen to interfaces on that network. IP addresses must use standard IP address format followed by the two-digit CIDR number that specifies the subnet mask. |
Overall System Status monitor
Use the Overall System Status monitor to view the status of all detected systems on your network by category. From this location, you can view the list of systems that make up a category by clicking it. You can also import or export systems from the Exceptions list by clicking Import/Export Exceptions.
The color-coded title bar across the top of the status monitor displays the percentage of total systems on your network that are compliant. This percentage represents the ratio of systems that are managed or designated as exceptions, to total detected systems. User-configured options based on this ratio determine the color of the title bar. There are three color codes: green, orange, and red. They represent good, marginal, and poor status, respectively. Only managed systems are compliant.
Option | Definition |
|---|---|
Exceptions | Specifies the number of systems on your network that are designated as exceptions. Exceptions are systems that you don’t want ePolicy Orchestrator to manage. |
Import/Export Exceptions | Displays the Import and Export Exceptions page. |
Inactive | Specifies the number of systems on your network identified as rogues not detected by a sensor in a specified time period. |
Managed | Specifies the number of systems on your network that ePolicy Orchestrator manages. |
Rogue | Specifies the number of systems on your network that ePolicy Orchestrator does not manage. |
Query Trellix Agent Results page
Use this page to view results from a Trellix Agent query.
Option | Definition |
|---|---|
Detected System | Specifies the names of systems on which the Trellix Agent query was performed. |
Agent Details | Specifies details about the agents deployed to selected detected systems, including:
When the query is unsuccessful, you can click Retry, which performs another query on this agent. |
Rogue Sensor Blacklist Details page
Use this page to view details about a sensor in the Rogue Sensor Blacklist. From this location, you can view information about the sensor, the system it is on, and remove the sensor from the blacklist.
Option | Definition |
|---|---|
Rogue Sensor Blacklist Information | Provides information about the selected system on the Rogue Sensor Blacklist, including:
|
Actions | Specifies the actions you can perform on the system, including:
|
Rogue Sensor Blacklist page
Use this page to view the list of rogue systems placed on the Rogue Sensor Blacklist.
Option | Definition |
|---|---|
Show/Hide Filter | Shows or hides the filter options. |
Show selected rows | Select this box to display only the rows you have selected. |
Selected Row Actions | Specifies the actions that can be performed on selected systems in the Rogue Sensor Blacklist, including:
|
Table Actions | Specifies the actions that you can perform on the Rogue Sensor Blacklist page, including:
|
Rogue System Sensor Details page
Use this page to view Rogue System Sensor details.
Option definitions
Option | Definition |
|---|---|
Action | Specifies the actions that you can perform on this sensor, including:
|
Option | Definition |
|---|---|
Rogue System Sensor Information | Specifies details about the Rogue System Sensor installed on this system, including:
|
Sensor's Managed System Information | Specifies the name of the system where the sensor is installed, and links to the ePolicy Orchestrator system details for the system. |
Sensor's Subnet Information | Specifies information about systems detected by the sensor, including:
|
Rogue System Sensor page
Use this page to view the list of Rogue System Sensors on your network, which are grouped in the following categories:
Active
Missing
Passive
Uninstalled
From this location, select the checkbox next to sensors to perform actions on them. You can also click an individual sensor to view more details.
Option | Definition |
|---|---|
Selected Row Actions | Specifies the actions that you can perform on Rogue System Sensors, including:
|
Table Actions | Specifies the available options, including:
|
Subnet Status monitor
Use the Subnet Status monitor to view the status of subnets in your network by category. From this location, you can view the list of subnets that make up a category by clicking it. You can also add subnets to your Trellix ePO - On-prem server by clicking Add Subnet.
The software displays the percentage of covered subnets using a color-coded title bar across the top of the status monitor. This percentage represents the ratio of covered subnets to uncovered subnets. The software determines the color of the title bar based on this ratio. There are three color-codes: green, orange, and red. They represent good, marginal, and poor status, respectively.
Option | Definition |
|---|---|
Add Subnet | Displays the Add Subnet page. |
Contains Rogues | Specifies the number of covered subnets on your network that contain rogue systems. |
Covered | Specifies the number of subnets on your network that are covered. Covered subnets have 2 active sensors. |
Uncovered | Specifies the number of subnets on your system that do not have two active sensors. |
Top 25 Subnets table
Use the Top 25 Subnets table to view the 25 subnets on your network that contain the most rogue systems.
Note
The systems in the highlighted subnet in the Top 25 Subnets list appear to the right in the Rogue System Interfaces by Subnet pane.
Option definitions
Option | Definition |
|---|---|
Ignore | Designates as ignored the highlighted subnet in the Top 25 Subnets list. ePolicy Orchestrator does not monitor ignored subnets. |
Option | Definition |
|---|---|
Selected Row Actions | Specifies the actions that can be performed on entries in Rogue System Interface by Subnet table, including:
|
Table Actions | Specifies the actions you can take on the Top 25 Subnets table, including:
|

Note: This section is relevant for 4.x sensors only.

Note