The following requirements are met onNetwork Security, Email Security — Server, and Endpoint Security (HX) appliances:
Make sure the following requirements are met on Endpoint Security (HX) appliances:
IPv6 is enabled globally on the appliances. IPv6 is enabled by default. To verify, use the
show ipv6command.SAML authentication and authorization is disabled on the appliances. To verify, use the
show aaa authentication samlcommand.Authentication through your Trellix Cloud Account is allowed. This happens automatically when Helix Enterprise mode is enabled on the appliance. To verify, use the
show aaa authentication oidccommand.
If these settings are not correct, see HelixConnect troubleshooting.
For any issues related to Endpoint Security (HX) requirements, see HelixConnect troubleshooting.
Alert streaming is disabled on Helix Enterprise-enabled Central Management System appliances. This allows managed appliance administrators to manage alerts from the Helix Enterprise Web UI. See Sending alerts directly from managed appliances.
The following entitlements in Trellix Cloud Account are granted to admin users onNetwork Security, Email Security — Server, and Endpoint Security (HX) appliances. This gives these users access to Appliance Settings pages, appliance alert actions, and remediation and data extraction actions in the Helix Enterprise Web UI:
appliance.role.admin or <appliance>.role.admin
The appliance.role.admin entitlement is included in the "Trellix Appliance Admin" role, which is for all appliance types. The <appliance>.role.admin entitlement is included in the "<appliance> Admin" role. Examples include nx.role.admin and ex.role.admin. For example, hx.role.admin
tap.appliance.management (included with all "TAP" roles and granted automatically when the appliance admin logs into the Helix Enterprise Web UI)
See the Trellix System Security Guide for details.
HelixConnect client software requirements
- Published on Sep 5, 2026
- 1 minute(s) read
Was this article helpful?