Advanced configurations

Prev Next

The following advanced configurations can be used in a Trellix Cloud MVX deployment in which a Central Management System appliance manages the sensors.

  • Network Address Translation (NAT)—The Central Management System appliance that manages the sensors can be deployed in an internal network behind a NAT gateway. In certain scenarios, you must configure an accessible address for the Central Management management interface so the managed sensors can reach it. For details, see the Administration Guide or System Administration Guide for the appliance.

  • Client-Initiated Connections—This guide shows how to add the appliances using a server-initiated connection, in which you use the Central Management appliance to directly connect appliances. Alternatively, you can use a client-initiated connection, in which the appliance administrator initiates a request to be managed, and a Central Management administrator explicitly accepts the request. For information about using a client-initiated connection, see the Administration Guide or System Administration Guide for the appliance.

  • Multiple DTI Sources—By default, a standalone sensor and the Central Management appliance use cloud.fireeye.com to download software updates from the DTI network. By default, managed appliances use the Central Management appliance as their DTI source server. In certain configurations, you can change the DTI source server for sensors to cloud.fireeye.com. For details, see the Administration Guide or System Administration Guide for the appliance.

  • Secure Shell (SSH) Authentication—The Secure Shell (SSH) protocol is used for secure communication between the Central Management appliance and the sensors. You can configure advanced options for SSH user authentication, which verifies the identity of the remote user attempting the connection. You can also configure advanced options for SSH host authentication, which verifies the identity of the Central Management appliance to the sensor, and verifies the identity of the sensor to the Central Management appliance. For details, see the FireEye System Security Guide.