The following tables describe the questions the configuration wizard prompts you to answer. As noted in the table, the wizard skips some steps based on your answers to previous steps.
Note
Press Ctrl+C to exit the configuration wizard. After the management interface is configured, an administrator can use the configuration jump-start CLI command to run the wizard again.
Network Security steps
The following table describes the wizard steps for a Network Security appliance.
Step | Response |
|---|---|
Hostname? | Enter the hostname for the appliance. |
Admin password? | (Optional) Enter a new administrator password. |
Confirm admin password? | Re-enter the new administrator password. |
Enable remote access for 'admin' user? | Enter yes to enable the administrator to log in to the appliance remotely. Enter no to disable remote access. |
Enable IPv4 for the management interface (ether1) | Enter yes to enable the IPv4 protocol. If you enter no, IPv4 setup is skipped and you are redirected to the IPv6 configuration, where you can enable or configure IPv6 instead. |
Use DHCP on ether1 interface? | Enter no to manually configure your IP address and network settings. |
Use zeroconf on ether1 interface? | Enter yes to use zero-configuration (zeroconf) networking. Enter no to specify a static IP address and network mask. (If you specify yes, the next step is skipped.) NOTE: Do not use zeroconf on the primary interface. |
Primary IPv4 address and masklen? | Enter the IPv4 address for the management interface in A.B.C.D format and enter the network mask (for example, 1.1.1.2 /24). |
Default gateway? | Enter the gateway IP address for the management interface. |
Primary DNS server? | Enter the IP address of the DNS server. |
Include HOMENET private IP range | Enter yes to configure the following homenet IP range for Snort rules. For further configuration, use the CLI homenet command or Web UI.
HOMENET is a default variable in the Snort rules (snort.conf) supported by the standard libpcap library where you can specify IP addresses that are to be protected. The Network Security appliance allows the configuration of the HOME_NET variable the CLI and WebUI. |
Include HOMENET private IPv6 range | Enter yes to configure the following homenet IP range for Snort rules. For further configuration, use the CLI homenet command or Web UI.
HOMENET is a default variable in the Snort rules (snort.conf) supported by the standard libpcap library where you can specify IP addresses that are to be protected. The Network Security appliance allows the configuration of the HOME_NET variable the CLI and WebUI. |
Enable IPv6 on management interface (ether1) | Enable IPv6 on management interface (ether1) NoteEnable Incident Response or Compromise Assessment features are not supported when IPv6 is selected as yes. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable DHCPv6 on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Primary IPv6 address and masklen (connection may be lost upon change)? | Enter the IPv6 address in X:X:X:X:X:X:X:X format and the prefix length. Example: 2001:db8::1/64. |
IPv6 Default gateway | Enter the gateway IPv6 address for the management interface. |
Primary DNS server? | Enter the IPv6 address in X:X:X:X:X:X:X:X format. Example: 2001:db8::1. |
IPv6 Primary DNS server | Enter the IPv6 address of the DNS server. |
Domain name? | Enter the domain for the management interface (for example, it.acme.com). |
Enable Incident Response or Compromise Assessment? | Enter no. These features are not supported in virtual NX deployments. |
Enable fenet service? | Enter yes to enable access to the DTI network. |
Enable fenet license update service? | Enter yes to enable the licensing service to automatically download your licenses from the DTI network and install them. (If licenses are downloaded and installed successfully, the wizard skips the step that prompts for the product license key and the step that prompts for the security-content updates key.) |
Sync appliance time with fenet? | Enter yes to synchronize the appliance time with the DTI server time. If you enabled the licensing service, synchronization prevents a feature from being temporarily unlicensed due to a time gap. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Update licenses from fenet? | Enter yes to download and install your licenses. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Enable NTP? | Enter yes to enable automatic time synchronization with one or more Network Time Protocol (NTP) servers. Enter no to manually set the time and date on the appliance. (This step is skipped if you entered yes in the "Sync appliance time with fenet?" step.) If you enter no, specify the time and date in subsequent steps. |
Set date(<yyyy>/<mm>/<dd>)? | Enter the appliance date in Greenwich Mean Time (GMT) (UTC+0). |
Set time (<hh>:<mm>:<ss>)? | Enter the appliance time in Greenwich Mean Time (GMT) (UTC+0). (This step and the next step are skipped if you entered yes in the "Sync appliance time with fenet?" or "Enable NTP?" step.) |
Submission: Configure Interface? | Press Enter to accept ether1 as the interface through which sensors and brokers communicate. Otherwise, enter the name of the other interface. (If you accept ether1, the next three steps are skipped.) |
Submission: Interface? | Enter the name of the other interface. NoteTo keep management and data traffic separate, Trellix recommends that you use another management interface, such as ether2, and not a monitoring interface. |
Submission: Use DHCP on <name> interface? | Enter yes to use Dynamic Host Configuration Protocol (DHCP) to configure the submission interface IP address and other network parameters. Enter no to manually configure the IP address and network settings. (If you enter yes, the static IP addressing steps are skipped.) |
Submission: IP address and masklen? | Enter the IP address for the submission interface in A.B.C.D format and enter the network mask (for example, 10.1.1.1 /24). |
Submission: Default IPv4 gateway? | Enter the gateway IP address for the submission interface. |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. |
Send a request to be managed by CMS | Enter yes to add Network Security to Central Management System. |
CMS Address | Enter Central Management System IPv4 or IPv6 address. |
CMS Server username | Enter the Central Management System server username. (Example: admin) |
CMS Server password | Enter the admin password for Central Management System server. |
CMS Port? | Enter the port number for the Central Management System appliance |
Appliance Reachable to CMS? | Enter yes/no. |
Authetication type | Choose the required authentication type.
|
Email Security steps
The following table describes the wizard steps for an Email Security — Server appliance.
Step | Response |
|---|---|
Hostname? | Enter the hostname for the appliance. |
Admin password? | (Optional) Enter a new administrator password. |
Confirm admin password? | Re-enter the new administrator password. |
Enable remote access for 'admin' user? | Enter yes to enable the administrator to log in to the appliance remotely. Enter no to disable remote access. |
Enable IPv4 for the management interface (ether1)? | Enter yes to enable the IPv4 protocol. If you enter no, IPv4 setup is skipped and you are redirected to the IPv6 configuration, where you can enable or configure IPv6 instead. |
Use zeroconf on ether1 interface? | Enter no to manually configure your IP address and network settings. |
Primary IP address and masklen? | Enter the IP address for the management interface in A.B.C.D format and enter the network mask (for example, 1.1.1.2 /24). |
Default gateway? | Enter the gateway IP address for the management interface. |
Primary DNS server? | Enter the IP address of the DNS server. |
Enable IPv6 on management interface (ether1)? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable DHCPv6 on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Primary IPv6 address and masklen (connection may be lost upon change)? | Enter the IPv6 address in X:X:X:X:X:X:X:X format and the prefix length. Example: 2001:db8::1/64. |
Primary DNS server? | Enter the IPv6 address in X:X:X:X:X:X:X:X format. Example: 2001:db8::1. |
Domain name? | Enter the domain for the management interface (for example, it.acme.com). |
Enable fenet service? | Enter yes to enable access to the DTI network. (If you enter no, the next three steps are skipped.) |
Enable fenet license update service? | Enter yes to enable the licensing service to automatically download your licenses from the DTI network and install them. (If licenses are downloaded and installed successfully, the wizard skips the step that prompts for the product license key and the step that prompts for the security-content updates key.) |
Sync appliance time with fenet? | Enter yes to synchronize the appliance time with the DTI server time. If you enabled the licensing service, synchronization prevents a feature from being temporarily unlicensed due to a time gap. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Update licenses from fenet? | Enter yes to download and install your licenses. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Enable NTP? | Enter yes to enable automatic time synchronization with one or more Network Time Protocol (NTP) servers. Enter no to manually set the time and date on the appliance. (This step is skipped if you entered yes in the "Sync appliance time with fenet?" step.) If you enter no, specify the time and date in subsequent steps. |
Enable FaaS VPN? | Enter yes to enable the appliance to connect to Managed Defense (formerly called FireEye as a Service) over the Internet using a secure SSL VPN connection. (This step is skipped if no MD_ACCESS license is installed. This step is performed automatically if you entered yes in the "Enable Incident Response or Compromise Assessment?" step. |
Set time (<hh>:<mm>:<ss>)? | Enter the appliance time in Greenwich Mean Time (GMT) (UTC+0). (This step and the next step are skipped if you entered yes in the "Sync appliance time with fenet?" or "Enable NTP?" step. |
Set date (<yyyy>/<mm>/<dd>)? | Enter the appliance date in Greenwich Mean Time (GMT) (UTC+0). |
Enable IPv6? | Enter yes to enable IPV6 protocol, which changes network routing from IPv4 to IPv6. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable IPv6 autoconfig on the ether1 (management interface) port. (This step is skipped if you entered no in the "Enable IPv6" step.) |
Enable DHCPv6 on ether1 interface? | Enter yes to use DHCPv6 to configure IPv6 hosts with IP addresses. (This step is skipped if you entered no in the "Use DHCP on ether1 interface" or "Enable IPv6" step.) |
Submission: Interface? (This step appears on integrated Email Security — Server appliances after MVX hybrid mode is enabled.) | Press Enter to accept ether1 as the interface through which sensors and brokers communicate. Otherwise, enter the name of the other interface. (If you accept ether1, the next three steps are skipped.) NOTE: To keep management and data traffic separate, Trellix recommends that you use another management interface, such as ether2, and not a monitoring interface. |
Submission: Use DHCP on <name> interface? | Enter yes to use Dynamic Host Configuration Protocol (DHCP) to configure the submission interface IP address and other network parameters. Enter no to manually configure the IP address and network settings. (If you enter yes, the static IP addressing steps are skipped.) |
Submission: IP address and masklen? | Enter the IP address for the submission interface in A.B.C.D format and enter the network mask (for example, 10.1.1.1 /24). |
Submission: Default Ipv4 gateway? | Enter the IP address for the submission interface default gateway in A.B.C.D format. |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. |
File Protect steps
The following table describes the wizard steps for a File Protect appliance.
Step | Response |
|---|---|
Hostname? | Enter the hostname for the appliance. |
Admin password? | (Optional) Enter a new administrator password. |
Confirm admin password? | Re-enter the new administrator password. |
Enable remote access for 'admin' user? | Enter yes to enable the administrator to log in to the appliance remotely. Enter no to disable remote access. |
Enable IPv4 for the management interface (ether1)? | Enter yes to enable the IPv4 protocol. If you enter no, IPv4 setup is skipped and you are redirected to the IPv6 configuration, where you can enable or configure IPv6 instead. |
Use DHCP on ether1 interface? | Enter yes to use Dynamic Host Configuration Protocol (DHCP) to configure the appliance IP address and other network parameters. Enter no to manually configure your IP address and network settings. (If you enter yes, the zeroconf and static IP addressing steps are skipped.) |
Use zeroconf on ether1 interface? | Enter yes to use zero-configuration (zeroconf) networking. Enter no to specify a static IP address and network mask. (If you specify yes, the next step is skipped.) NOTE: Do not use zeroconf on the primary interface. |
Primary IP address and masklen? | Enter the IP address for the management interface in A.B.C.D format and enter the network mask (for example, 1.1.1.2 /24). |
Default gateway? | Enter the gateway IP address for the management interface. |
Primary DNS server? | Enter the IP address of the DNS server. |
Enable IPv6 on management interface (ether1)? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable DHCPv6 on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Primary IPv6 address and masklen (connection may be lost upon change)? | Enter the IPv6 address in X:X:X:X:X:X:X:X format and the prefix length. Example: 2001:db8::1/64. |
Primary DNS server? | Enter the IPv6 address in X:X:X:X:X:X:X:X format. Example: 2001:db8::1. |
Domain name? | Enter the domain for the management interface (for example, it.acme.com). |
Enable fenet service? | Enter yes to enable access to the DTI network. (If you enter no, the next three steps are skipped.) |
Enable fenet license update service? | Enter yes to enable the licensing service to automatically download your licenses from the DTI network and install them. (If licenses are downloaded and installed successfully, the wizard skips the step that prompts for the product license key and the step that prompts for the security-content updates key.) |
Sync appliance time with fenet? | Enter yes to synchronize the appliance time with the DTI server time. If you enabled the licensing service, synchronization prevents a feature from being temporarily unlicensed due to a time gap. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Update licenses from fenet? | Enter yes to download and install your licenses. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Enable NTP? | Enter yes to enable automatic time synchronization with one or more Network Time Protocol (NTP) servers. Enter no to manually set the time and date on the appliance. (This step is skipped if you entered yes in the "Sync appliance time with fenet?" step.) If you enter no, specify the time and date in subsequent steps. |
Enable FaaS VPN? | Enter yes to enable the appliance to connect to Managed Defense (formerly called FireEye as a Service) over the Internet using a secure SSL VPN connection. (This step is skipped if no MD_ACCESS license is installed.) |
Set time (<hh>:<mm>:<ss>)? | Enter the appliance time in Greenwich Mean Time (GMT) (UTC+0). (This step and the next step are skipped if you entered yes in the "Sync appliance time with fenet?" or "Enable NTP?" step. |
Set date (<yyyy>/<mm>/<dd>)? | Enter the appliance date in Greenwich Mean Time (GMT) (UTC+0). |
Enable IPv6? | Enter yes to enable IPV6 protocol, which changes network routing from IPv4 to IPv6. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable IPv6 autoconfig on the ether1 (management interface) port. (This step is skipped if you entered no in the "Enable IPv6" step.) |
Enable DHCPv6 on ether1 interface? | Enter yes to use DHCPv6 to configure IPv6 hosts with IP addresses. (This step is skipped if you entered no in the "Use DHCP on ether1 interface" or "Enable IPv6" step.) |
Submission: Interface? (This step appears on integrated File Protect appliances after MVX hybrid mode is enabled.) | Press Enter to accept ether1 as the interface through which sensors and brokers communicate. Otherwise, enter the name of the other interface. (If you accept ether1, the next three steps are skipped.) NOTE: To keep management and data traffic separate, Trellix recommends that you use another management interface, such as ether2, and not a monitoring interface. |
Submission: Use DHCP on <name> interface? | Enter yes to use Dynamic Host Configuration Protocol (DHCP) to configure the submission interface IP address and other network parameters. Enter no to manually configure the IP address and network settings. (If you enter yes, the static IP addressing steps are skipped.) |
Submission: IP address and masklen? | Enter the IP address for the submission interface in A.B.C.D format and enter the network mask (for example, 10.1.1.1 /24). |
Submission: Default Ipv4 gateway? | Enter the IP address for the submission interface default gateway in A.B.C.D format. |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. |
Virtual Execution steps
The following tables describes the wizard steps for a Intelligent Virtual Execution - Server appliance.
Step | Response |
|---|---|
Hostname? | Enter the hostname for the appliance. |
Admin password? | (Optional) Enter a new administrator password. |
Confirm admin password? | Re-enter the new administrator password. |
Enable remote access for 'admin' user? | Enter yes to enable the administrator to log in to the appliance remotely. Enter no to disable remote access. |
Use DHCP on ether1 interface? | DHCP is not supported on the management interface. Enter no to manually configure your IP address and network settings. |
Use zeroconf on ether1 interface? | Enter yes to use zero-configuration (zeroconf) networking. Enter no to specify a static IP address and network mask. (If you specify yes, the next step is skipped.) NOTE: Do not use zeroconf on the primary interface. |
Primary IPv4 address and masklen? | Enter the IP address for the management interface in A.B.C.D format and enter the network mask (for example, 1.1.1.2 /24). |
Default gateway? | Enter the gateway IP address for the management interface. |
Primary DNS server? | Enter the IP address of the DNS server. |
Enable IPv6 on management interface (ether1)? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable DHCPv6 on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Primary IPv6 address and masklen (connection may be lost upon change)? | Enter the IPv6 address in X:X:X:X:X:X:X:X format and the prefix length. Example: 2001:db8::1/64. |
Primary DNS server? | Enter the IPv6 address in X:X:X:X:X:X:X:X format. Example: 2001:db8::1. |
Domain name? | Enter the domain for the management interface (for example, it.acme.com). |
Enable fenet service? | Enter yes to enable access to the DTI network. (If you enter no, the next three steps are skipped.) |
Enable fenet license update service? | Enter yes to enable the licensing service to automatically download your licenses from the DTI network and install them. (If licenses are downloaded and installed successfully, the wizard skips the step that prompts for the product license key and the step that prompts for the security-content updates key.) |
Sync appliance time with fenet? | Enter yes to synchronize the appliance time with the DTI server time. If you enabled the licensing service, synchronization prevents a feature from being temporarily unlicensed due to a time gap. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Update licenses from fenet? | Enter yes to download and install your licenses. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Enable NTP? | Enter yes to enable automatic time synchronization with one or more Network Time Protocol (NTP) servers. Enter no to manually set the time and date on the appliance. (This step is skipped if you entered yes in the "Sync appliance time with fenet?" step.) |
Set time (<hh>:<mm>:<ss>)? | Enter the appliance time in Greenwich Mean Time (GMT) (UTC+0). (This step and the next step are skipped if you entered yes in the "Sync appliance time with fenet?" or "Enable NTP?" step. |
Set date (<yyyy>/<mm>/<dd>)? | Enter the appliance date in Greenwich Mean Time (GMT) (UTC+0). |
Enable IPv6? | Enter no. IPv6 is not supported on Intelligent Virtual Execution - Server appliances that are nodes in an MVX cluster. |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. |
Submission: Interface? | Press Enter to accept ether1 as the interface through which sensors and brokers communicate. Otherwise, enter the name of the other interface. (If you accept ether1, the next three steps are skipped.) NOTE: To keep management and data traffic separate, Trellix recommends that you use another management interface, such as ether2, and not a monitoring interface. |
Submission: Use DHCP on <name> interface? | DHCP is not supported on the submission interface. Enter no to manually configure the IP address and network settings. |
Submission: IP address and masklen? | Enter the IP address for the submission interface in A.B.C.D format and enter the network mask (for example, 10.1.1.1 /24). |
Submission: Default IPv4 gateway? | Enter the IP address for the submission interface default gateway in A.B.C.D format. |
Cluster: Configure interface? | Press Enter to accept ether1 as the interface through which brokers and compute nodes communicate. Otherwise, enter the name of another interface. (If you accept ether1, the next three steps are skipped.) NOTE: To keep management and data traffic separate, Trellix recommends that you use another management interface such as ether2, and not a monitoring interface. |
Cluster: Use DHCP on <name> interface? | DHCP is not supported on the cluster interface. Enter no to manually configure the address settings. |
Cluster: IP address and masklen? | Enter the IP address for the cluster interface in A.B.C.D format and enter the network mask (for example, 10.1.1.2 /24). |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. |
Central Management steps
The following table describes the wizard steps for a Central Management System appliance.
Step | Response |
|---|---|
Hostname? | Enter the hostname for the appliance. |
Admin password? | (Optional) Enter a new administrator password. |
Confirm admin password? | Re-enter the new administrator password. |
Enable remote access for 'admin' user? | Enter yes to enable the administrator to log in to the appliance remotely. Enter no to disable remote access. |
Use DHCP on ether1 interface? | Enter yes to use Dynamic Host Configuration Protocol (DHCP) to configure the appliance IP address and other network parameters. Enter no to manually configure your IP address and network settings. (If you enter yes, the zeroconf and static IP addressing steps are skipped.) |
Use zeroconf on ether1 interface? | Enter yes to use zero-configuration (zeroconf) networking. Enter no to specify a static IP address and network mask. (If you specify yes, the next step is skipped.) NOTE: Do not use zeroconf on the primary interface. |
Primary IP address and masklen? | Enter the IP address for the management interface in A.B.C.D format and enter the network mask (for example, 1.1.1.2 /24). |
Default gateway? | Enter the gateway IP address for the management interface. |
Primary DNS server? | Enter the IP address of the DNS server. |
Enable IPv6 on management interface (ether1)? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable DHCPv6 on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Primary IPv6 address and masklen (connection may be lost upon change)? | Enter the IPv6 address in X:X:X:X:X:X:X:X format and the prefix length. Example: 2001:db8::1/64. |
Primary DNS server? | Enter the IPv6 address in X:X:X:X:X:X:X:X format. Example: 2001:db8::1. |
Domain name? | Enter the domain for the management interface (for example, it.acme.com). |
Enable fenet service? | Enter yes to enable access to the DTI network. (If you enter no, the next three steps are skipped.) |
Enable fenet license update service? | Enter yes to enable the licensing service to automatically download your licenses from the DTI network and install them. (If licenses are downloaded and installed successfully, the wizard skips the step that prompts for the product license key and the step that prompts for the security-content updates key.) |
Sync appliance time with fenet? | Enter yes to synchronize the appliance time with the DTI server time. If you enabled the licensing service, synchronization prevents a feature from being temporarily unlicensed due to a time gap. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Update licenses from fenet? | Enter yes to download and install your licenses. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Enable NTP? | Enter yes to enable automatic time synchronization with one or more Network Time Protocol (NTP) servers. Enter no to manually set the time and date on the appliance. (This step is skipped if you entered yes in the "Sync appliance time with fenet?" step.) If you enter no, specify the time and date in subsequent steps. |
Set time (<hh>:<mm>:<ss>)? | Enter the appliance time in Greenwich Mean Time (GMT) (UTC+0). (This step and the next step are skipped if you entered yes in the "Sync appliance time with fenet?" or "Enable NTP?" step. |
Set date (<yyyy>/<mm>/<dd>)? | Enter the appliance date in Greenwich Mean Time (GMT) (UTC+0). |
Enable IPv6? | Enter yes to enable IPV6 protocol, which changes network routing from IPv4 to IPv6. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable IPv6 autoconfig on the ether1 (management interface) port. (This step is skipped if you entered no in the "Enable IPv6" step.) |
Enable DHCPv6 on ether1 interface? | Enter yes to use DHCPv6 to configure IPv6 hosts with IP addresses. (This step is skipped if you entered no in the "Use DHCP on ether1 interface" or "Enable IPv6" step.) |
Configure CMS HA? | Enter yes to configure the Central Management System appliance in a high availability (HA) environment. (For the remaining HA configuration steps, see the Central Management System High Availability Guide.) |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. |
Malware Security steps
Step | Response |
|---|---|
Hostname? | Enter the hostname for the appliance. |
Admin password? | (Optional) Enter a new administrator password. |
Confirm admin password? | Re-enter the new administrator password. |
Enable remote access for 'admin' user? | Enter yes to enable the administrator to log in to the appliance remotely. Enter no to disable remote access. |
Use DHCP on ether1 interface? | Enter yes to use Dynamic Host Configuration Protocol (DHCP) to configure the appliance IP address and other network parameters. Enter no to manually configure your IP address and network settings. (If you enter yes, the zeroconf and static IP addressing steps are skipped.) |
Use zeroconf on ether1 interface? | Enter yes to use zero-configuration (zeroconf) networking. Enter no to specify a static IP address and network mask. (If you specify yes, the next step is skipped.) NOTE: Do not use zeroconf on the primary interface. |
Primary IP address and masklen? | Enter the IP address for the management interface in A.B.C.D format and enter the network mask (for example, 1.1.1.2 /24). |
Default gateway? | Enter the gateway IP address for the management interface. |
Primary DNS server? | Enter the IP address of the DNS server. |
Enable IPv6 on management interface (ether1)? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable DHCPv6 on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Primary IPv6 address and masklen (connection may be lost upon change)? | Enter the IPv6 address in X:X:X:X:X:X:X:X format and the prefix length. Example: 2001:db8::1/64. |
Primary DNS server? | Enter the IPv6 address in X:X:X:X:X:X:X:X format. Example: 2001:db8::1. |
Domain name? | Enter the domain for the management interface (for example, it.acme.com). |
Enable fenet service? | Enter yes to enable access to the DTI network. (If you enter no, the next three steps are skipped.) |
Enable fenet license update service? | Enter yes to enable the licensing service to automatically download your licenses from the DTI network and install them. (If licenses are downloaded and installed successfully, the wizard skips the step that prompts for the product license key and the step that prompts for the security-content updates key.) |
Sync appliance time with fenet? | Enter yes to synchronize the appliance time with the DTI server time. If you enabled the licensing service, synchronization prevents a feature from being temporarily unlicensed due to a time gap. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Update licenses from fenet? | Enter yes to download and install your licenses. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Enable FaaS VPN? | Enter yes to enable the appliance to connect to Managed Defense (formerly called FireEye as a Service) over the Internet using a secure SSL VPN connection. (This step is skipped if no MD_ACCESS license is installed.) |
Enable IPv6? | Enter yes to enable IPV6 protocol, which changes network routing from IPv4 to IPv6. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable IPv6 autoconfig on the ether1 (management interface) port. (This step is skipped if you entered no in the "Enable IPv6" step.) |
Enable DHCPv6 on ether1 interface? | Enter yes to use DHCPv6 to configure IPv6 hosts with IP addresses. (This step is skipped if you entered no in the "Use DHCP on ether1 interface" or "Enable IPv6" step.) |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. |