Review the items in this section before you begin your upgrade.
User Role—You must have admin access to upgrade the Network Security appliance.
Back Up the Appliance—Before performing the upgrade, back up your appliance. See Database backup and restore for more information.
Licenses—Before performing upgrades, confirm that the following licenses are installed and valid:
CONTENT_UPDATES license (needed for security content updates)
FIREEYE_SUPPORT license (needed for software updates)
Note
See License management for more information. If you need to obtain the licenses, send an email to key_request@fireeye.com.
End-User License Agreement (EULA)—The upgrade could require acceptance of the End User License Agreement (EULA). If it is required, the appliance will not function until the EULA is accepted. To review the EULA before the upgrade, download a copy from the Trellix Customer Support Portal at
http://csportal.fireeye.com.Minimum Version to Upgrade—Refer to the Release Notes to determine whether you can upgrade directly from the current release to the new release.
IPMI and BIOS Versions—The latest IPMI and BIOS firmware should be running. See IPMI and BIOS firmware updates .
Note
The NX 2550 model requires IPMI 3.11 and BIOS 1.9.
Download Time—Downloading the operating system software requires about 45 minutes when upgrading from the CLI. Downloading the guest images typically requires 2 ½ to 9 hours from the CLI, depending on connection speed and whether the full set of guest images is downloaded. A complete set can require 24 hours or more.
Network Proxy Configuration—If you have an intelligent proxy appliance that is required for access to the Internet, ensure that it does not perform secure sockets layer (SSL) terminations with certificate replacement. An example of such a proxy is the Blue Coat ProxySG appliance. If the proxy does perform SSL terminations, then you must whitelist the Central Management System appliance, the Trellix Dynamic Threat Intelligence (DTI) network server (
staticcloud.fireeye.com), or the Content Distribution Network (CDN) server (cloud.fireeye.comordownload.fireeye.com) in the proxy configuration.For integration with third-party products, such as ArcSight, Juniper STRM, Blue Coat ProxySG, or Q1 Lab QRadar, contact Trellix Technical Support. Refer to the vendor documentation for proxy configuration information.