Deploy a virtual server by completing the following steps.
Task | Instructions | ||
|---|---|---|---|
1. Verify that your environment meets the necessary requirements. | See System Requirements. | ||
2. Gather license information from Trellix. | Get license keys from Trellix if the license update service is not enabled. See About License Keys. | ||
3. Gather virtual server information from Trellix . | Contact Trellix to obtain:
| ||
4. Deploy your Endpoint Security (HX) virtual server. |
| ||
5. Install the required Trellix licenses. | Install the SUPPORT and other licenses (if the license update feature is disabled). See License Management. The license update feature enables your appliance to automatically download and apply licenses to which you are contractually entitled. This feature is enabled with the configuration wizard during the initial configuration and is fully functional after the configuration wizard is completed. | ||
6. Configure other system administration features such as AAA, SSL certificates, and SNMP data access | See the Trellix System Security Guide and the Endpoint Security (HX) System Administration Guide. | ||
7. Verify that the server is connected to Trellix's Dynamic Threat Intelligence (DTI) cloud. | If the validation fails, verify that the DTI configuration is set up correctly. See the Endpoint Security (HX) System Administration Guide. | ||
8. Attach your DMZ servers to the virtual Endpoint Security (HX) server. | See Attaching and Detaching DMZ Servers. NoteYour Endpoint Security (HX) and DMZ servers must run the same version of Endpoint Security (HX) software. If they use different versions, communication between them will fail. | ||
9. Set up the server address list. | |||
10. Identify your provisioning servers. | Agents earlier than version 20 can only provision against a single primary server. Agents version 20 or later can provision against multiple servers. A virtual server can be used as a provisioning server. See Understanding Provisioning. NoteYou must decide which servers (primary or DMZ) will be your provisioning servers before you download the Trellix Endpoint Security (HX) agent installation software to your host endpoints. When agent installation software is downloaded, the IP addresses or DNS names of the provisioning servers are identified in the agent download package. | ||
11. Obtain the agent installation package. | If your Endpoint Security (HX) server is connected to DTI, the most recent Windows, macOS and Linux agent images are automatically downloaded to the server after the DTI connection is established. If your primary server is not connected to DTI or if you need an older agent image than the ones that have been downloaded, you will need to manually download the agent image you need. ImportantIf you obtain your agent image manually, it must be uploaded to the server before it can be deployed to your host endpoints. This ensures that the correct agent configuration file and agent certificates are included in the agent installation package and ensures that proper agent-server communication is established after the installation package is deployed on your endpoints. See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide. | ||
12. Install the agent software on your host endpoints. | See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide.
| ||
13. Optionally, connect your Endpoint Security (HX) server to the Central Management System appliance or to a Network Security appliance. | After you have deployed your Endpoint Security (HX) server and installed the agent software on your endpoints, you can integrate the Endpoint Security (HX) server with Central Management System and Network Security appliances. For more information, see Integration on page 1. Additional information for managing your Endpoint Security (HX) server through the Central Management System appliance is provided in the Endpoint Security (HX) System Administration Guide. |
.png)