You can pair two receivers so that each is a backup for the other. This reduces the risk of missing data collection if you have a hardware or network failure. High availability can be set up on virtual devices from version 11.5.8 and later.
Make sure your receivers are the same model and the same version.
Both receivers must have identical specifications (CPU, RAM and Disk space).
Both receivers must have 3 network interfaces.
Do not key the new receiver to the Trellix ESM.
Deploy another VM Receiver and assign it a new management IP address.
Do not key the new receiver to the Trellix ESM.
Must have three network adapters configured.
Both receivers must have identical specifications (CPU, RAM and Disk space).
All network interfaces must be using the same driver. Our recommendation is to use the e1000 driver.
The third interface on each VM must be configured into a private network dedicated to this high availability pair.
Note
As the shared IP address switches between receivers, relax any networking policies that inhibit such behavior. For example, in vSphere, the network policy MAC address changes have to be set to Accept from the default option Reject.
Caution
If you are required to comply with FIPS regulations, do not use this feature. High availability receivers are not FIPS-compliant.
Important
The Heartbeat connection requires a network latency of 75 ms or better to prevent High Availability Receivers fail over and any issues. Any network latency issue requires Customer Support to fix the high availability receiver and improve the network.
On the system navigation tree, select the receiver that is the primary high availability device, then click the Properties icon.
.png)
Click Receiver Configuration, then click Interface.
Click the HA Receiver tab, then select Setup High Availability.
The Enable HA Check dialog box appears on the screen.
Click Yes in the Enable HA Check dialog box.
Click Setup for Primary Management IP to set the Primary Receiver IP address as a new management IP address.
Note
The current Receiver IP address becomes the Shared IP.
Click Setup for Secondary Management IP to enter the IP address of the newly added receiver.
Choose the IP range from the Heart Beat Network IP drop-down list. Make sure to check any conflicts in your functions based on your IP range selection.
Click Ok to apply these settings.
The process that keys the second receiver updates the database, applies globals.conf, and syncs the two receivers.