Setting up provisioning

Prev Next

Provisioning establishes unique cryptographic identities for the agents installed on your host endpoints. To complete the Trellix xAgent installation on a host endpoint, the agent connects to a provisioning Endpoint Security (HX) server that then determines the cryptographic identity for the agent. When provisioning does not occur, the server does not know about and cannot collect data from the host endpoint on which the agent is installed.

Any Endpoint Security (HX) server, including a DMZ server, can be enabled to do provisioning. Both physical and virtual Endpoint Security (HX) appliances can be enabled to do provisioning.

If the endpoints in your environment have agent software versions earlier than version 20 installed, they can only provision against a single Endpoint Security (HX) server, identified as the primary server. By default, the provisioning server is the first server listed in the agent server address list, which is usually your internal (non-DMZ) server.

If the endpoints in your environment have agent software version 20 or later installed, they can provision against multiple Endpoint Security (HX) servers. By default, your internal Endpoint Security (HX) server is a provisioning server.

Provisioning Endpoint Security (HX) servers must be accessible by agents within your company's internal network. Provisioning DMZ servers must be accessible by agents inside and outside your company's network.

Important

You must identify the servers that will be your provisioning servers before you download the Trellix xAgent installation software to your host endpoints. When agent installation software is downloaded, the IP addresses or DNS names of the provisioning Endpoint Security (HX) servers are identified in the agent download package.

To set up provisioning:
  1. Enable provisioning on the servers you might want to use for provisioning. See Enabling servers for provisioning.

  2. Designate which provisioning-enabled server you want to use. See Designating provisioning servers. This must be done before you download agent software to your host endpoints.

    You can cancel a server as a provisioning server. See Canceling provisioning servers.

Prerequisites
  • Admin or fe_services access