DTI Update Portal User Guide 1.4.1

Prev Next

Getting started

This document covers the following information:

Accessing the portal

The DTI update portal can be accessed at the following URL: https://portal-dti.fireeye.com.

Prerequisites

  • You must have a user account to log in.

Procedure. To log in to the DTI update portal:

  1. In your browser, go to the DTI update portal https://portal-dti.fireeye.com).

  2. Log in to the portal with your user credentials.

DTI Update Portal login screen — dark themed page with Please sign in form showing username field populated with admin@aaa.com, a password field, and a prominent turquoise LOGIN button.

After successful login, you are directed to the DTI Update Portal home page.


Screenshot of the DTI Update Portal — dark themed header with logo and navigation items HOME, MY ACCOUNT, USERS, ACTIVITY; a centered teal FILTER RESOURCES button; and a dark panel titled Most Recent Downloads containing a narrow table header row with columns DateTime(GMT), Account, User, Resource.


Managing user accounts

All users of the DTI update portal must have a user account. As an administrator of the DTI update portal, you can create and deactivate user accounts for your portal.

User account roles

The DTI update portal supports the following two roles:

  • User—Users can log in to the DTI update portal, download content, and manage appliances and keys.

  • Admin—Administrators have the same access as other users, but can also add and deactivate users on the system.

User account password requirements

Passwords must be 8 – 30 characters long and must include the following:

  • At least one numeric digit

  • At least one lowercase letter

  • At least one uppercase letter

  • At least one of the following symbols: - + _ ! @ # $ % ^ & * . , ?

Prerequisites

  • Admin access

Creating a user account

Create DTI update portal user accounts using the portal's New User page.

Dark-themed New User form screenshot showing fields — Account (AAA), Role (user) drop-down, First name Jane, Last name Do, Email jane.doe@aaa.com highlighted, Password and Password confirmation fields, large Description text area on the right, and a teal CREATE USER button at the bottom.

Procedure. To create a DTI update portal user account:

  1. Log in to the DTI update portal as an administrator. See Accessing the Portal.

  2. On the home page, click Users. The user list page is displayed.

  3. Click New User. The New User page displays.

  4. Select the company for the new user account in the Account drop-down menu.

  5. Select the role for the new user account in the Role drop-down menu.

  6. Enter the identifying information for the account: the user's first and last names and email address.

  7. Create and confirm the initial password for the account. Rules for passwords are described in User Account Password Requirements.

  8. Optionally, enter a description for the user account.

  9. Click Create User.

Searching for a user account

You can search for an existing DTI update portal user account.

Procedure. To search for a DTI update portal user account:

  1. Log in to the portal as an administrator. See Accessing the portal.

  2. On the home page, click Users. The user list page is displayed.

3. In the search box at the top of the user list page, enter a string for the search and click Search. The string is not case-sensitive.

Dark horizontal search box with placeholder text Search Name, Email or Company and a turquoise SEARCH button on the right

The string you enter is matched against the user names, email addresses, and company names in the user list. The results display all of the user accounts that matched the string.

You can refine the filtered list by adding to your search string.

To reset the user list to show all users, clear the search box.

Editing a user account

You can edit DTI update portal user accounts after they have been created.

Procedure. To edit a DTI update portal user account:

  1. Log in to the DTI update portal as an administrator. See Accessing the portal.

  2. On the home page, click Users. The user list page is displayed.

  3. Locate the user in the user list. Click Previous, Next, or one of the listed page numbers to see different pages of the user list.

Dark pagination control showing ← Previous 1 2 3 4 Next → with page numbers in teal and arrows on either side

You can search for a user in the list. See Searching for a user account.

  1. Click the Edit button associated with the user. The Edit User page displays.


Edit User page screenshot — dark themed form titled Edit User with user name Jane Doe. The form shows Account and Role dropdowns, First, Last, Email, Password and Password confirmation fields on the left, a large Description textarea on the right, and a teal UPDATE USER button at the bottom centre of the form.

  1. Change the account, role, first name, last name, email address, password or description of the user account, as needed.

  2. Click Update User.

The user account is updated.

Deactivating a user account

The following is used to deactivate a user account on the DTI update portal:

Procedure. To deactivate a DTI update portal user account:

  1. Log in to the DTI update portal as an administrator. See Accessing the portal.

  2. On the home page, click Users. The user list page is displayed.

  3. Locate the user in the user list. Click Previous, Next, or one of the listed page numbers to see different pages of the user list.

    Pagination control screenshot showing ← Previous 1 2 3 4 Next → on a dark background for navigating user list pages.

You can search for a user in the list. See Searching for a user account.

  1. Click the Edit button associated with the user. The Edit User page displays.

Dark-themed Edit User form screenshot showing the profile for Jane Doe. The image highlights the top-left Active checkbox with a red outline and also highlights the UPDATE USER button near the bottom center with a red outline. The form displays fields for Account, Role, First, Last, Email, Password, Password confirmation, and a large Description area on the right.

  1. Clear the Active checkbox.

  2. Click Update User.

The user account is deactivated. It still appears in the user list, but is listed as inactive.

Updating content

You can download various content resource files using the DTI update portal Web UI and API.

The content resource files available for download for newer versions of appliance software differ from the content resource files available for legacy versions of appliance software. Both are described here. To determine which type of content resource files your appliance needs, see Content resource files.

To learn more about updating the security content of an Endpoint Security server without the use of a Central Management appliance, see the community article on this topic.

This section covers the following information:

Limitations and usage guidelines

  • You can use the DTI update portal to upgrade an offline appliance to release 7.5.0 or greater. The update takes effect after you reboot the appliance.

  • To upgrade an offline appliance from a Central Management appliance, the Central Management appliance must be running the 7.7.0 release or greater.

  • After upgrading an offline Central Management appliance to a new major release (such as from 7.8.1 to 7.9.0), download the new metadata files for the managed appliances.

Content resource files

This section describes the content resource files available for download from the DTI update portal to newer versions of Trellix appliance software.

Guest images

Guest images are packaged as bundles. Each bundle includes multiple files that must all be installed on the appliance. You can search for guest-image packages by product type and release.

Depending on your appliance hardware architecture, you will need to download either the AMD architecture package or the Intel architecture package.

Small triangular caution icon with exclamation mark

Caution

You must select and download the correct guest image bundle and install all of its files on your appliance.

Endpoint Security (HX) appliances do not support guest images.

Guest image files come in the following combinations:

  • Full version or patch version        

    The full version is referred to as the Guest Image Profile. This version includes the complete guest image software for the version to be installed.

    The patch version is referred to as the Guest Image Profile Patch. Patch versions are delta packages that can be downloaded and applied to the currently installed guest image version.

    The full version can be installed on any appliance requiring a guest image. You do not need to ensure you have the correct base guest image on the appliance before you install the full version. The patch version is smaller than the full version because it only includes the differences between the source and the target guest image versions.

  • AMD architecture or Intel architecture        

    Choose the correct guest image file type for your appliance's hardware architecture. Currently the following appliance versions require the Intel architecture package:

    1500, 2500, 2550, 3500, 4500, 5500, 6500, 7500, 8500, 10550

    All other appliance versions use the AMD architecture package.

    The architecture type can be identified by the profile section of the file name. The Intel package ends with an "m" within the profile section.

Guest image profiles

A guest image profile is an offline guest image package that can be downloaded and installed on any appliance (freshly remanufactured or older). You must download and install all of the files from the same guest image bundle version.

  • AMD Package:

    <PROFILE_NAME>.<PROFILE_VERSION>.img
    
    win7-sp1.17.0208.img
  • Intel Package:

    <PROFILE_NAME>m.<PROFILE_VERSION>.img
    
    win7-sp1m.17.0208.img

Guest image profile patches

Guest image profile patches are delta packages that can be downloaded and applied to the currently installed guest image version.

  • AMD package:

    <PROFILE_NAME>.img.<CURRENT_GI_VERSION>.<NEW_PROFILE_VERSION>.diff
    
    winxp-sp3.img.15.1218.16.0901.diff
  • Intel package:

    <PROFILE_NAME>m.img.<CURRENT_GI_VERSION>.<NEW_PROFILE_VERSION>.diff
    
    winxp-sp3m.img.15.1218.16.0901.diff

Yellow triangular caution icon Caution

For NX, EX, AX & CMS appliances, a user of the portal will see:

winxp-sp3m-delta-16.0901-17.0800.img downloaded from the Web UI, but the winxp-sp3m.img.16.0909.17.0800.diff package will be present at the FENET server.

Guest image manifest config package

The guest image manifest config package is a small package that includes metadata required to install an .img or .diff package on an appliance. This manifest is also required when an .img or .diff package is hosted on a Central Management appliance.

Legacy content resource files

This section describes the content resource files available for download from the DTI update portal to legacy versions of appliance software.

Femeta

Trellix metadata provides compatibility and other information used when you install the software image. You can search for femeta files by product type and release numbers.

femeta_<PROD>.xml

Blue circled i info iconImportant

Trellix recommends that you update femeta metadata file prior to installing any other update.

The femeta metadata file for Endpoint Security (HX) is called femeta_HX.ensig for all versions of HX.

Security content

The security content package is required to update detection rules for Trellix appliances. You can search for security content files based on the product type and release numbers. The latest content package can be downloaded based on the content channel as well. The content package file is named as:

sc-stable_<VERSION>.ensig

Blue circled i info iconImportant

The latest femeta metadata must be installed prior to updating or hosting an offline CMS content package.

Green triangular caution iconCaution

When renaming the OLP security content file the file name must begin with "sc-" and must not have any spaces in the name.

You must ensure that the security content acceptance level is stable. To configure the security acceptance level, use the fenet security-content acceptance-level stable command. For further information, refer to the CLI Command Reference.

System image

System images are used to upgrade the base OS to a newer version. The system image resource type can be downloaded as:

image-<product-name>_<product-release>.ensig

Important

Before installing a newer system image, Trellix highly recommends that you first download and install the latest femeta metadata and security content package.

Virtual appliances

A virtual appliance (OVA) image is required to boot a virtual appliance. The virtual appliance images can be filtered by product name and release. When available, virtual appliance images are supported primarily for major releases only. You may need to download the major release image for a virtual appliance and then upgrade it to a more recent version, if one is available. The virtual appliance models are .zip files and can be downloaded as:

image-<PRODUCT_NAME>_fireeye<MODEL_NAME>_<MAJOR_RELEASE>.zip

For example: image-wmps_fireeyenx2500v_7.9.0.zip

Guest images

Guest images are packaged as bundles. Each bundle includes multiple files that must all be installed on the appliance. You can search for guest-image packages by product type and release.

Note

Offline packages (those with a .ensig extension) are no longer supported. GI bundles (those with a .img extension) based on core version 17.0108, such as 17.0208 and 17.0308 are still supported. You can still upgrade guest images even though you previously installed using offline packages.

Depending on your appliance hardware architecture, you will need to download either the AMD architecture package or the Intel architecture package.

Green triangular caution icon Caution

You must select and download the correct guest image bundle and install all of its files on your appliance.

Endpoint Security (HX) appliances do not support guest images.

Guest image files come in the following combinations:

  • Full version or patch version

    The full version is referred to as the Guest Image Profile. This version includes the complete guest image software for the version to be installed.

    The patch version is referred to as the Guest Image Profile Patch. Patch versions are delta packages that can be downloaded and applied to the currently installed guest image version.

    The full version can be installed on any appliance requiring a guest image. You do not need to ensure you have the correct base guest image on the appliance before you install the full version. The patch version is smaller than the full version because it only includes the differences between the source and the target guest image versions.

  • AMD architecture or Intel architecture

    Choose the correct guest image file type for your appliance's hardware architecture. Currently the following appliance versions require the Intel architecture package:

    1500, 2500, 2550, 3500, 4500, 5500, 6500, 7500, 8500, 10550

    All other appliance versions use the AMD architecture package.

    The architecture type can be identified by the profile section of the file name. The Intel package ends with an "m" within the profile section.

Guest image profiles

A guest image profile is an offline guest image package that can be downloaded and installed on any appliance (freshly remanufactured or older). You must download and install all of the files from the same guest image bundle version.

  • Ensig package (oldformat):

    vxe_<GI_BUNDLE_VERSION>_<PROFILE_NAME>.ensig
    vxe_15.0202_osx-10.9.ensig
  • AMD Img package (newformat):

    <PROFILE_NAME>.<PROFILE_VERSION>.img
    win7-sp1.16.0901.img

  • INTEL Img package (newformat):

    <PROFILE_NAME>m.<PROFILE_VERSION>.img
    win7-sp1m.16.0901.img

Guest image profile patches

Guest image profile patches are delta packages that can be downloaded and applied to the currently installed guest image version.

  • AMD img patch:

    <PROFILE_NAME>.img.<CURRENT_GI_VERSION>.<NEW_PROFILE_VERSION>.diff
    winxp-sp3.img.16.1115.17.0800.diff
  • INTEL img patch:

    <PROFILE_NAME>m.img.<CURRENT_GI_VERSION>.<NEW_PROFILE_VERSION>.diff
    winxp-sp3m.img.16.1115.17.0800.diff

For NX, EX, AX and CMS appliances, if you are using of the DTI offline portal you will see winxp-sp3.img.16.0909.17.0800.diff.

Guest image manifest config package

The guest image manifest config package is a small package that includes metadata required to install an .img or .diff package on an appliance. This manifest is also required when an .img or .diff package is hosted on a Central Management appliance.

Downloading content from the DTI update portal

To locate content in the DTI update portal, it must be filtered by product name and release. This narrows the content selection.

Procedure. To locate and download content resource files from the DTI update portal:

  1. Log in to the portal. See Accessing the portal.

  2. On the home page, click Filter Resources. The Filter Resources page displays.

As you specify a filter field on this page, additional filter fields appear. Specify as many filter fields as you need.

  • Select a product in the Select Product drop-down menu.

  • Select a version of the selected product in the Select Release drop-down menu.

  • Optionally, select a resource type for that version of the product in the Select Resource (Optional) drop-down menu.

  1. Click Filter. A list of resource types for that product version appears. For information about the resource types available, see             Content resource files.

    Dark-themed resource list showing three rows — filenames (femeta_HX.ensig, sc-stable_220.103.img, image-hx_3.6.0), types (metadata, security-content, system-image), and product column showing HX-3.6.0 — with expand icons at the right of each row.

  2. In the displayed resource list, expand the row for a listed resource by clicking on the expand icon             Small circular expand icon with a downward chevron.

  3. Click one of two download buttons:

    • Click Download from CDN to download the content from a content delivery network (such as Akamai’s). Depending on your network configuration, this option is usually faster.

    • Click Download from DTI to download the content directly from Trellix servers.

    The files will be downloaded to your Downloads folder.

  4. Follow the instructions in the next section, Transferring content to offline appliances.

Transferring content to offline appliances

Transfer Trellix content from the DTI update portal to your offline appliances in one of the following ways:

Transferring content files locally

This procedure describes how to upload a local content file that was obtained from the DTI update portal.

Diagram showing two laptops and a Trellix appliance and a cloud labeled DTI Update Portal, with arrows illustrating local content transfer; USB and RS232 connections shown and the Web UI Local option highlighted

Procedure. To transfer content files locally:

  1. Bring the computer or removable storage device with the downloaded content inside your network.

  2. Directly connect the laptop to your Trellix appliance using a serial port connection, or insert the removable storage device into a directly connected, networked laptop.

  3. Log in to the Web UI on the appliance.

  4. Go to the Appliance Update page (select About > Update) in the appliance Web UI.

  5. Select the Local option, as described in the documentation for the appliance you are updating.

  6. Click Browse to locate the appliance files you downloaded.

Note

For offline guest image updates, downloads are more efficient if Source is set to URL, not Local.

The selection of the Local or URL source option on the Appliance Update page persists across all appliance reboots.

Appliance Update page screenshot showing Source options (DTI, Local, URL), a File Upload Browse button, and a table listing resources such as Security Content, Appliance Image, and Guest Images


  1. Select the content file you want to transfer and install, and then click Open.

Windows Explorer (OSDisk (C:)) window showing folders and files; a file named sc_7.1.0-eMPS_306.2_stable.ensig is selected/highlighted. The details pane shows file type ENSIG File and size approximately 160 MB (164,337 KB).

  1. On the Appliance Update page, click Save.

    The content file is saved on the appliance.

  2. Repeat these steps for every content file you need to transfer.

Transferring content files using a URL on a local site

This procedure describes how to upload a local content file that was obtained from the DTI update portal and hosted on a local computer or removable storage device identified by a URL.


Diagram showing a cloud labeled DTI Update Portal connected via arrows to a DMZ server and a Trellix appliance; a circular icon labeled URL Web UI points to the appliance and a small key/documents icon is shown near the appliance.

Procedure. To transfer content files from a local computer or removable storage device identified by a URL:

  1. Log in to the Web UI on the appliance.

  2. Go to the Appliance Update page (select About > Update) on the Web UI.

  3. Select the URL option, as described in the documentation for the appliance you are updating.

Note

Use URL for the source of guest image downloads only during offline updates. URL is not relevant if you are performing DTI source downloads.

The selection of the Local or URL source option in the Appliance Update page persists across all appliance reboots.

  1. In the File URL box on the Appliance Update page, specify the URL where the downloaded appliance files can be found.

  2. On the Appliance Update page, click Save.

    The file is saved on the appliance.

  3. Repeat these steps for every file you need to transfer.

Transferring content files using SCP

Procedure. To transfer content files using SCP:

  1. Save the update package from the DTI update portal on a UNIX-like system accessible to the Trellix appliance.

  2. Run the scp <package> <appliance_address>:/data/updates command. For example:

# scp femeta.ensig 192.168.1.100:/data/updates

The file is saved on the appliance.

Note

For offline guest image updates, downloads are more efficient if Source is set to URL, not Local.

3. Repeat these steps for every file you need to transfer.

Installing content files on an offline appliance

Procedure. To install content files on your appliance:

  1. Log on to your Trellix appliance as an administrator.

  2. Go to the Appliance Update page (select About > Update) in the appliance Web UI.

  3. Click the orange arrow next to the resource that you want to update to show details. The Status area displays information about the last check or last update action.

Appliance Update table:

Screenshot of the Appliance Update page showing the update table with columns Resource, Installed Version, Latest Version, Last Updated, Status, and Tasks. The image shows a red-bordered message box reading Security Content Status Check has completed. Prepare uploaded Security Content file for installation. with a Prepare button visible.

  1. Click the Check button or the Check For Update icon in the Tasks column of the Appliance Update table to perform the software check. If there is an update, the Check button changes into Prepare. If there is no update, a message is displayed that no new updates are available.

  2. Click Prepare to prepare the file for installation.

Appliance Update (status view):

Wider screenshot of the Appliance Update UI showing the top area with Source radio buttons (DTI / Local / URL), File Upload field, and a large table listing resources. The table highlights a security-content row with Installed Version, Latest Version, Last Updated, and a Prepare action in the Tasks column.


  1. To install the downloaded software on the appliance, click the Install button or the Install icon (gear icon) in the Tasks column.

    There is no status bar to show the progress of the installation. You can use CLI commands to monitor the status of the installation. For example, enter show guest-images download to check if the new guest images are installed or enter show fenet image status to check if the new system image is installed.

    Appliance Update interface screenshot showing Source: DTI | Local | URL options, a table row for Resource Security Content with Installed Version 336.273, Status column showing Security Content file downloaded., and a boxed area indicating Security Content Status File Preparation has completed: Install new Security Content. with an Install button. The Tasks column shows small action icons including a gear icon.

  2. When the installation is finished, you see an "Updates installed successfully" message. The status changes to "Updates installed successfully," and the installed version number changes

    Appliance Update interface screenshot showing the Security Content row with Installed Version updated to 336.296 and the Status column highlighted with Updates installed successfully. The page shows the Check for new updates. area and a Check button below the status box.

  3. Repeat these steps for every content file you want to install.

Updating Endpoint Agent images

To update the Trellix Endpoint Agent image on an Endpoint Security (HX) appliance, use the Endpoint Security (HX) appliance CLI and the DTI update portal.

Task Summary

  1. Place the Endpoint Security (HX) appliance in an offline operational mode.

  2. Obtain the following files from the DTI update portal. Use product name EP_AGENT when you filter the list:

  • femeta_HX_AGENT.ensig

  • image-hx_agent-win-<version>

  • image-hx_agent-osx-<version>

  • image-hx_agent-linux-<version>

  1. Determine the content ID of the Trellix Endpoint Agent image you need.

  2. Retrieve and install the Endpoint Agent.

  3. Use the agent image to upgrade your endpoint agents. See the Endpoint Security Agent (HX) Administration Guide for more information.

Prerequisites

  • Secure Copy (SCP) client software on your local machine.

  • Administrator credentials for the Endpoint Security (HX) appliance.

  • Administrator credentials for the DTI update portal. If you do not already have administrator credentials, contact your Trellix sales representative.

Procedure. To update the Trellix Endpoint Agent image on an Endpoint Security (HX) appliance using the CLI:

  1.         Place the Endpoint Security (HX) appliance in an offline update state:        

    1. Using the CLI, log in to the Endpoint Security (HX) appliance as an administrator.

    2. Enable CLI configuration mode on the Endpoint Security (HX) appliance:                

      host > enable
      host # configure terminal
    3. Place the appliance in an offline state:                

      host (config) # fenet op-mode local
  2.         Using your local system, copy the metafiles to the Endpoint Security (HX) appliance.        

    1. Log into the DTI update portal.

    2. Filter the portal content using product name EP_AGENT to locate the metafile.

    3. Download the following four metafiles from the portal to your local machine.


  • femeta_HX_AGENT.ensig

  • image-hx_agent-win-<version>

  • image-hx_agent-osx-<version>

  • image-hx_agent-linux-<version>

d. Use Secure Copy (SCP) to copy the file to the /data/updates directory on the appliance. For details, see Transferring content files using SCP in this document.

3. On the Endpoint Security (HX) appliance, determine the content ID of the Trellix Endpoint Agent image you need.

  1. a. Retrieve the list of Endpoint Agent images that are available for download.

    host (config) # fenet hx-agent metadata refresh
  2. b. View the supported operating system, version, and content ID associated with each available Endpoint Agent image.

    host (config) # show fenet hx-agent image available  command.
  3. c. Find the content ID of the image you need.

4. Download the femeta_HX_AGENT-<version>.img (where <version> is the version number of the agent image) from the portal to your machine. Use Secure Copy (SCP) to copy the file to the /data/updates directory on the appliance.

host (config) # fenet hx-agent image fetch content-id <contentID>
host (config) # fenet hx-agent image apply content-id <contentID>

5. After the agent software image is applied to the Endpoint Security (HX) appliance, it can be installed or upgraded on the host endpoints provisioned to the appliance. See the Endpoint Security Agent (HX) Deployment Guide and the Endpoint Security Agent (HX) Administration Guide.