Server roles and order

Prev Next

Endpoint Security (HX) software can be deployed on the following appliance forms:

  • on-premises (physical) appliances

  • virtual servers (VMware ESXi or Windows Hyper-V)

  • cloud servers

You can optionally install DMZ servers and connect them to a single Endpoint Security (HX) server. DMZ servers are installed in public or Internet-facing network locations and are used to maintain connectivity with externally connected host endpoints. Installation and setup steps for DMZ servers are the same as for an Endpoint Security (HX) server. Requests from agents to a DMZ server are proxied to the Endpoint Security (HX) server.

Note

A single Endpoint Security (HX) ecosystem, which includes the Endpoint Security (HX) server and its attached DMZ servers, can support up to 100,000 agents.

Your Endpoint Security (HX) (and DMZ) servers must run the same version of Endpoint Security (HX) software. If they use different versions, communication between them will fail.

In each Endpoint Security (HX) ecosystem, provisioning and primary servers must be identified. Provisioning servers are the servers to which Trellix xAgent connects to provision and establish their cryptographic agent identity. Trellix xAgents with version numbers less than 20 can only provision against the primary server. xAgents with version numbers of 20 or later can provision against multiple servers, including a DMZ server.

Important

You must identify the servers that will be your provisioning servers before you download and deploy the Trellix xAgent installation software to your host endpoints. When agent installation software is downloaded, the IP addresses or DNS names of the provisioning Endpoint Security (HX) servers are identified in the agent download package.

The Central Management System platform can be used to upgrade and manage Endpoint Security (HX) (and DMZ) servers.