The submission interface is used for communication between sensors or hybrid appliances and brokers. The cluster interface is used for communication between broker nodes and compute nodes, and between compute nodes. By default, both the submission interface and cluster interface are defined to be ether1.
Trellix recommends that you configure another management interface (such as ether2), not a monitoring interface, for the submission and cluster interfaces. This prevents the ether1 management interface from becoming too busy, and keeps management and data traffic separate. However, ether2 cannot be used as both the submission interface and the
URL Dynamic Analysis interface on an Email Security — Server Edition sensor.
If the sensor or hybrid appliance and broker are in different subnets, you must define the default gateway for the interface.
Note
DHCP is not currently supported on the submission or cluster interface.
Ether1 is the only supported submission interface on File Protect sensors and hybrid appliances.
Prerequisites
Operator or Admin access