Guest images are virtual machine snapshots used to evaluate suspicious traffic for a variety of environments, applications, and files. They let you test traffic and software, analyze results, and detonate malware in a controlled environment where malware activity cannot damage your assets. The number of virtual environments you can run can depends on the appliance model you have.
In a TrellixNetwork Security deployment, guest images reside on the Intelligent Virtual Execution - Server appliances (compute nodes and brokers) that compose an MVX cluster. Sensors enrolled with the MVX cluster submit suspicious traffic samples to the MVX cluster, which uses the guest images to detonate the sample and perform further analysis.
If a Intelligent Virtual Execution - Server node is part of a cluster, use the Central Management System appliance to update the guest images. The Central Management System appliance ensures that all VX nodes in a cluster use the same guest images. The Central Management System appliance orchestrates the upgrade to ensure that at least one broker and one compute node are running during the upgrade, so there is no interruption in service. (This assumes more than one broker is enabled.) For details, see the Distributed Network Security IVX Smart Grid Guide.
Important
Within an MVX cluster, all compute nodes and brokers must run the same software image, security content, and guest images.
Guest images are installed and tested on the Intelligent Virtual Execution - Server appliance during the manufacturing process.
Important
Trellix provides an updated set of guest images with each new release and strongly recommends you use the full set of guest images provided in each release without modifying the set.
IVX nodes that are part of a cluster should not be upgraded individually. Upgrade clusters using the Central Management System Web UI only. See the Distributed Network Security IVX Smart Grid Guide.