The Central Management System appliance is an easy-to-deploy, network-based platform that serves as both a security event storehouse and a central management device for Trellix appliances. The Central Management System Web UI or CLI is used to configure, manage, and upgrade its managed devices.
For objects that are determined to be malicious, the managed Intelligent Virtual Execution - Server appliance automatically generates rules in real time. The auto-generated rules are automatically passed to the Central Management System appliance for distribution to all other managed appliances. The "Submit to MAS" Central Management System feature allows analysts to select an incident on any managed appliance and submit it to a managed Malware Analysis appliance for further forensics.
The connection between the managed appliance and the Central Management System appliance can be initiated by either the appliance (a client-initiated connection) or the Central Management System appliance (a server-initiated connection). For information about client-initiated connections, see Requesting management by a Central Management appliance . For information about server-initiated connections, and about accepting a client-initiated connection request, see the Central Management System Administration Guide.
By default, a managed appliance uses the Central Management System platform as its source server for software downloads from the DTI network. In this configuration, both management and DTI network traffic use a single port. You can change this configuration, as described in Changing the address type for DTI network service requests .
Important
If the Intelligent Virtual Execution - Server appliance is managed by the Central Management System appliance, you should generally avoid changing shared configuration settings from the appliance Web UI or CLI. If you do so, the changes could be overwritten by commands and actions issued from the Central Management System appliance. Trellix recommends that you configure managed appliances using the Central Management System Web UI. For information about using the Central Management System Web UI to configure managed appliances, see the "Configuring Managed Appliances" section of the Central Management System Administration Guide.
Important
Trellix recommends that, after you have completed initial configuration of the Intelligent Virtual Execution - Server appliance (as described in Initial configuration ), you use the Central Management System Web UI to add the Intelligent Virtual Execution - Server appliance to the Central Management System appliance and then add it as a node to an MVX cluster.
You should generally avoid using the Intelligent Virtual Execution - Server CLI to change shared configuration settings. If you do so, the changes could be overwritten by commands and actions issued from the Central Management System appliance.
Note
See CM integration for additional information and implementation details.