Deployment tasks

Prev Next

You must perform the following tasks to deploy Trellix Distributed Network Security.

Plan

Perform the following steps before you begin the deployment.

  1. Decide where you want to deploy sensors in your network.

  2. Decide the deployment and operational mode for each Network Security sensor and each Network Security integrated appliance that will operate in sensor mode.

    Sensors can be deployed in the same modes as integrated appliances. See the Network Security System Administration Guide and Network Security User Guide for details about the modes.

  3. Decide the deployment and operational mode for each Email Security — Server sensor.

    Sensors and integrated appliances can access network shares in the same way. See the File Protect User Guide for information about network share access.

  4. Decide how File Protect sensors will access network shares.

    Sensors and integrated appliances can access network shares in the same way. See the File Protect User Guide for information about network share access.

Gather items from your network administrator

Have the following items ready before you begin the deployment.

  • Static or reserved IP address, subnet mask, and default gateway address for the management interface.

  • IP address for each Domain Name System (DNS) server.

  • IP address for each Network Time Protocol (NTP) server.

  • Telnet or SSH client on the remote system (if the component will be managed remotely).

  • Physical appliances: If you plan to configure initial settings using the serial console port and a Windows or Mac laptop, obtain a USB-to-serial cable.

Gather information from Trellix

Have the following items ready before you begin the deployment.

  • License keys (if the license update service is not enabled).

  • Virtual appliances:

    • Activation code, which gives the virtual appliance a unique identity (its appliance ID), activates the product (FIREEYE_APPLIANCE) license, allows access to the license token server, provides access to the DTI network, protects against fraudulent use of the appliance, and allows the appliance to initialize.

    • Link to an OVA file containing your customer-specific system image.

Deploy virtual appliances

See the Trellix Device Deployment Guide for information about deploying virtual appliances.

Deploy physical appliances

Perform the following steps to deploy physical appliances in your network.

  1. Install the appliances in your network.

    See the Hardware Administration Guide for the appliance and the Trellix Device Deployment Guide.

  2. Enable sensor mode on integrated Network Security appliances, as described in Enabling and disabling MVX sensor mode.

Add appliances to the Central Management appliance

Your sensors can be managed by a Central Management appliance or can be standalone appliances. Perform the procedure in Adding sensors to a Central Management System appliance if you want them to be managed.

Complete the configuration

Perform the following steps to complete the configuration.

  1. If the license update feature is disabled: Install FIREEYE_SUPPORT, CLOUD_MVX, and feature licenses.

    The license update feature enables your appliance to automatically download and apply licenses to which you are contractually entitled. This feature is enabled with the configuration wizard during the initial configuration, and is fully functional after the configuration wizard is completed.

    See the Administration Guide or System Administration Guide for the appliance.

  2. Configure detection settings, such as operational mode, policies, notifications, reports, and so on. See the Network Security User Guide and Email Security — Server User Guide.

  3. Add storage and configure detection settings, such as scans, notifications, reports, and so on. See the File Protect User Guide.

Check the sensor status

Check that the sensor is connected to and enrolled with the IVX cluster, as described in Checking sensor status .