Architecture

Prev Next

Trellix provides three Distributed Network Security deployment options:

  • The same Central Management appliance manages both the sensors and hybrid appliances and the IVX cluster.

    With this option, a single physical or virtual Central Management appliance or a physical Central Management High Availability (HA) pair manages the IVX cluster components. All sensors, brokers, and compute nodes must be connected to the same Central Management appliance.

    Note

    This is the only option for an MVX hybrid appliance.

  • The sensors are managed by a local Central Management appliance and submit to a remote IVX cluster that is managed by a different Central Management appliance. With this option, the brokers and compute nodes must be connected to the same Central Management appliance.

  • The sensors are standalone appliances, and submit directly to an IVX cluster.

A Central Management appliance can manage both the MVX components and other appliances, such as integrated Network Security appliances and Email Security — Server Edition appliances.

The IVX cluster components (brokers and compute nodes) must be deployed on the same LAN. The IVX cluster, the sensors, and the Central Management appliance can be in different physical locations.

Important

Do not use transcontinental deployments due to throughput, reliability, and latency issues.

A sensor can be a physical or virtual Network Security appliance, a virtual Email Security - Server appliance, or a virtual File Protect appliance. Some Network Security appliance models can function only as sensors, because they do not include an MVX analysis engine. Some physical Network Security appliances can be enabled as sensors, in which case the analysis engine is disabled. A virtual appliance can function only as a sensor.

A hybrid appliance is a physical Network Security, Email Security — Server Edition, or File Protect appliance. A hybrid appliance has an on-board analysis engine, but stops using it when a predefined threshold is exceeded. The appliance then essentially acts as a sensor, because it sends all submissions to an IVX cluster until the capacity falls below this threshold.

A broker or node is a physical Virtual Execution appliance. A Virtual Execution appliance serves no purpose until it is added to a cluster.

The following diagrams show an architecture in which the Central Management appliance manages both physical and virtual sensors, one IVX cluster, and integrated appliances that are not sensors or IVX cluster components.

image3.jpeg
image4.jpeg