SuperAgent wake-up calls

Prev Next

SuperAgent contacts all agents in the same subnet using the SuperAgent wake-up call.

SuperAgent distributes the bandwidth load of concurrent wake-up calls. Instead of sending wake-up calls from the server to every Trellix Agent, the server sends the SuperAgent wake-up call to SuperAgents in the selected System Tree segment.

The process is:

  1. Server sends a wake-up call to all SuperAgents.

  2. SuperAgents broadcast a wake-up call to Trellix Agent in the same broadcast domain.

  3. All notified Trellix Agent (Trellix Agent notified by a SuperAgent and all SuperAgents) exchange data with ePO - On-prem or Agent Handler.

When you send a SuperAgent wake-up call, Trellix Agent without an operating SuperAgent on their broadcast domain are not prompted to communicate with the server.

SuperAgent deployment tips

To deploy enough SuperAgents to the appropriate locations, first determine the broadcast domains in your environment and select a system (preferably a server) in each domain to host a SuperAgent. If you use SuperAgents, make sure that every Trellix Agent is assigned a SuperAgent.

Trellix Agent and SuperAgent wake-up calls use the same secure channels. Make sure that the following ports are not blocked by a firewall on the client:

  • Trellix Agent wake-up communication port (8081 by default).

  • Trellix Agent broadcast communication port (8083 by default).