Intelligent Sandbox 5.0.x Hardware Guide

Prev Next

Trellix Intelligent Sandbox 5.0.x Hardware Guide

Last Updated: September 17, 2023

   

Multicolored dashed wave pattern spanning the page with the Trellix logo positioned at the bottom-right

Contents


Setting up the Intelligent Sandbox Appliance ......................................................... 3

Intelligent Sandbox Appliances ............................................................... 3

Functions of a Intelligent Sandbox Appliance ......................................... 3

Before you install the Intelligent Sandbox Appliance ................................ 4

Warnings and cautions ..................................................................... 4

Usage restrictions ......................................................................... 5

Unpack the shipment .................................................................... 5

Check your shipment .................................................................... 6

Hardware specifications .............................................................. 15

Default ports used in Intelligent Sandbox communication ................. 18

Set up the hardware ...................................................................... 20

Install or remove rack handles ..................................................... 20

Rack mount the appliance .......................................................... 21

Turn on the Intelligent Sandbox Appliance ..................................... 23

Handling the front bezel ............................................................. 24

Enable RMM ................................................................................. 25

Connect the management port ..................................................... 25

Configure the Intelligent Sandbox Appliance network information ...... 26

1 | Setting up the Intelligent Sandbox Appliance


Setting up the Intelligent Sandbox Appliance

Prepare the Intelligent Sandbox Appliance for installation and integration in the network.

Intelligent Sandbox Appliances

Depending on the model, the Intelligent Sandbox Appliance is a 1-U or 2-U rack dense chassis with Intel® Xeon® E5-2600, E5-4600 or Xeon Scalable family processor.

The Intelligent Sandbox Appliance runs on a pre-installed, hardened Linux kernel 3.6.0 and comes preloaded with the Intelligent Sandbox software.

The Intelligent Sandbox Appliance is available in the following models:

       
  • ATD-3000 — Standard model is a 1U chassis
  •    
  • ATD-6000 — High-end model is a 2U chassis
  •    
  • ATD-3100 — Standard model is a 1U chassis
  •    
  • ATD-6100 — High-end model is a 1U chassis
  •    
  • ATD-3200 — Standard model is a 1U chassis
  •    
  • ATD-6200 — High-end model is a 1U chassis

The Intelligent Sandbox Appliances are purpose-built, scalable, and flexible high-performance servers designed to analyze suspicious files for malware.

The following are the primary functions of the Intelligent Sandbox Appliance:

       
  • Host the Intelligent Sandbox software that analyzes files for malware.
  •    
  • Host the Intelligent Sandbox web interface.
  •    
  • Host the virtual machines used for dynamic analysis of suspicious files.
   
       

Blue note icon with pencil

       

Note

   
   

For the performance values related to the appliances, contact Support.

1 | Setting up the Intelligent Sandbox Appliance


       
  •        

    Host the virtual machines used for dynamic analysis of suspicious files.

       
   
       
           

Note

       
       

For the performance values related to Intelligent Sandbox Appliances, contact Trellix support.

   

Before you install the Intelligent Sandbox Appliance

This section describes the tasks that you must complete before you begin to install a Intelligent Sandbox.

       
  •        

    Read all the provided documentation before installation.

       
  •    
  •        

    Make sure that you have selected a suitable location for installing the Intelligent Sandbox Appliance.

       
  •    
  •        

    Check that you have all the necessary equipment and components outlined in this document.

       
  •    
  •        

    Familiarize yourself with the Trellix Intelligent Sandbox Appliance network access card ports and connectors as described in this document.

       
  •    
  •        

    Make sure you have the following information available when you configure the Intelligent Sandbox Appliance:

           
                 
    • IPv4 address that you want to assign to the Appliance.

    •            
    • Network mask.

    •            
    • Default gateway address.

    •        
       

Warnings and cautions

Read and follow these safety warnings when you install the Intelligent Sandbox Appliance.

   
       
           

⚠️ Caution

       
       

Failure to observe these safety warnings could result in serious physical injury.

   

Power Supply

       
  •        

    The push-button on/off power switch on the front panel of the Intelligent Sandbox Appliance does not turn off the AC power. To remove AC power from the Intelligent Sandbox Appliance, you must unplug the AC power cord from either the power supply or wall outlet for both the power supplies.

       
  •    
  •        

    If you press the push-button on/off power switch on the front panel of the Intelligent Sandbox Appliance while the appliance is running, it shuts down. If you want to power off the appliance, use CLI command — shutdown, then after the system halts—press the power button until the appliance turns off.

       
  •    
  •        

    The power supplies in your system might produce high voltages and energy hazards, which can cause bodily harm. Only trained service technicians are authorized to remove the covers and access any of the components inside the system.

       
  •    
  •        

    Hazardous electrical conditions might be present on power, telephone, and communication cables. Turn off the Intelligent Sandbox Appliance and disconnect telecommunications systems, networks, modems, and both the power cords attached to the Intelligent Sandbox Appliance before opening it. Otherwise, personal injury or equipment damage can result.

       

4          Trellix Intelligent Sandbox 5.0.x Hardware Guide

1 | Setting up the Intelligent Sandbox Appliance


       
  • This equipment is intended to be grounded. Ensure that the host is connected to earth ground during normal use.
  •    
  • To avoid electric shock, do not connect safety extra-low voltage (SELV) circuits to telephone-network voltage (TNV) circuits. LAN ports contain SELV circuits, and WAN ports contain TNV circuits. Some LAN and WAN ports both use RJ-45 connectors. Use caution when connecting cables.

Avoid Injuries

Lifting the Intelligent Sandbox Appliance and attaching it to the rack is a two-person job.

Appliance outer shell

       
  • Do not remove the outer shell of the Intelligent Sandbox Appliance. Doing so invalidates your warranty.
  •    
  • Do not operate the system unless all cards, faceplates, front covers, and rear covers are in place. The faceplates and cover panels prevent exposure to hazardous voltages and currents inside the chassis. The components might produce high electromagnetic interference (EMI) that might disrupt other nearby equipment.
  •    
  • Ensure that the appliance is placed in such a manner that flow of cooling air through the chassis is not blocked.

Usage restrictions

The following restrictions apply to the use and operation of Intelligent Sandbox Appliance:

       
  • You should not remove the outer shell of the Intelligent Sandbox Appliance. Doing so invalidates your warranty.
  •    
  • The Intelligent Sandbox Appliance is not a general-purpose server.
  •    
  • Trellix prohibits the use of Intelligent Sandbox Appliance for anything other than operating the Intelligent Sandbox solution.
  •    
  • Trellix prohibits the modification or installation of any hardware or software on the Intelligent Sandbox Appliance that is not part of the normal operation of Intelligent Sandbox.

Unpack the shipment

       
  1. Place the packaging box as close to the installation site as possible.
  2.    
  3. Position the box with the text upright and then open the top flaps of the box.
  4.    
  5. Remove the content of the box, including the Intelligent Sandbox Appliance.
  6.    
  7. Locate the accessory kit bag.

Verify that you have received all the parts as listed in Content Sheet.

       
  1. Pull out the packing material surrounding the Intelligent Sandbox Appliance.
  2.    
  3. Remove the Intelligent Sandbox Appliance from the anti-static bag.
  4.    
  5. Save the box and packing materials for later use in case you need to move or ship the Intelligent Sandbox Appliance.

Trellix Intelligent Sandbox 5.0.x Hardware Guide

1 | Setting up the Intelligent Sandbox Appliance


Check your shipment

Each product ships with all the items needed to install the appliance on a network.

To verify that you received all the necessary items, verify that you have received the following:

       
  • Intelligent Sandbox Appliance
  •    
  • Accessories itemized on the Content Sheet
  •    
  • Set of tool-less slide rails
  •    
  • Front bezel with key
  •    
  • Country or region specific power cords

Trellix Intelligent Sandbox Appliance front and back panels

ATD-3000 and ATD-6000 front panel

Front panel of ATD-3000/ATD-6000 appliance with numbered callouts 1 through 10

                                                                                                                                                                                                                                                                                                                    

Label

Description

1

System ID button with integrated indicator light

2

NMI button (recessed, tool required for use)

3

NIC 1 activity indicator light

4

               
                       
  • ATD-3000: NIC 3 activity indicator light
  •                    
  • ATD-6000: Not used
  •                
           

5

System cold reset button

6

System status indicator light

1 | Setting up the Intelligent Sandbox Appliance


                                                                                                                                                                                                                                            
LabelDescription
7Power button with integrated indicator light
8Hard drive activity indicator light
9                
                       
  • ATD-3000: NIC 4 activity indicator light
  •                    
  • ATD-6000: Not used
  •                
           
10NIC 2 activity indicator light

ATD-3000 Appliance back panel

ATD-3000 rear panel image showing connectors and ports with numbered callouts 1 through 12

                                                                                                                                                                                                                                            
LabelDescription
1Power supply module 1
2Power supply module 2
3                

Management port (NIC 1). This is the eth-0 interface. The set appliance and set mgmtport commands apply to this interface. For example, when you use the set appliance ip command, the corresponding IP address is assigned to this interface.

           
4                

NIC 2. This is the eth-1 interface. This interface is disabled by default.

               
                       
  • To enable or disable this interface, use the set intfport command. For example, set intfport 1 enable
  •                    
  • To assign the IP details to this interface use set intfport <eth 1, 2, or 3> ip <IPv4 address> <subnet mask>
  •                
           

Trellix Intelligent Sandbox 5.0.x Hardware Guide7

1 | Setting up the Intelligent Sandbox Appliance


                                                                                                                                                                                                                                                                                                                                                                                                                                            
               

Label

           
               

Description

           
               

           
               

For example, set intfport 1 ip 10.10.10.10 255.255.255.0

               
                       
  • You cannot assign the default gateway to this port. However, you can configure a route on this interface to route the traffic to the desired gateway. To configure a route, use route add network <IPv4 subnet> netmask <netmask> gateway <IPv4 address> intfport 1
  •                
               

For example, route add network 10.10.10.0 netmask 255.255.255.0 gateway 10.10.10.1 intfport 1. This command routes all traffic from the 10.10.10.0 command to 10.10.10.1 through NIC 2 (eth-1).

           
               

5

           
               

NIC 3. This is the eth-2 interface. The note described for NIC 2 applies to this interface as well.

           
               

6

           
               

NIC 4. This is the eth-3 interface. The note described for NIC 2 applies to this interface as well.

           
               

7

           
               

Video connector

           
               

8

           
               

RJ45 serial-A port

           
               

9

           
               

USB ports

           
               

10

           
               

RMM4 NIC port

           
               

11

           
               

I/O module ports/connectors (not used)

           
               

12

           
               

Add-in adapter slots from riser card 1 and riser card 2

           

Setting up the Intelligent Sandbox Appliance


ATD-6000 Appliance back panel

Rear view of ATD-6000 appliance back panel with numbered callouts pointing to ports and connectors (callouts 1 through 14).

                                                                                                                                                                                                                                    
               

Label

           
               

Description

           
               

1

           
               

USB ports

           
               

2

           
               

USB ports

           
               

3

           
               

Management port. This is the eth-0 interface. The set appliance and set mgmtport commands apply to this interface. For example, when you use the set appliance ip command, the corresponding IP address is assigned to this interface.

           
               

4

           
               

Additional I/O module ports/connectors. These are the eth-1, eth-2, and eth-3 interfaces respectively. These interfaces are disabled by default.

               
                       
  • To enable or disable an interface, use the set intfport command. For example, set intfport 1 enable to enable eth-1.
  •                    
  • To assign the IP details to an interface use set intfport <eth 1, 2, or 3> ip <IPv4 address> <subnet mask>. For example, set intfport 1 ip 10.10.10.10 255.255.255.0.
  •                    
  • You cannot assign the default gateway to this port. However, you can configure a route on this interface to route the traffic to the desired gateway. To configure a route, use: route add network <IPv4 subnet> netmask <netmask> gateway <IPv4 address> intfport 1.
  •                
           

Trellix Intelligent Sandbox 5.0.x Hardware Guide

1 | Setting up the Intelligent Sandbox Appliance


                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            
               

Label

           
               

Description

           
               

           
               

For example, route add network 10.10.10.0 netmask 255.255.255.0 gateway 10.10.10.1 intfport 1. This command routes all traffic from the 10.10.10.0 command to 10.10.10.1 through eth-1.

           
5Video connector
6NIC 1 (currently not used)
7NIC 2 (currently not used)
8RJ45 serial-A port
9I/O module ports/connectors (not used)
10Add-in adapter slots from riser card
11RMM4 NIC port
12Power supply module 2
13Power supply module 1
14Add-in adapter slots from riser card

1 | Setting up the Intelligent Sandbox Appliance


ATD-3100, and ATD-6100 Appliance Front panel

Front panel of ATD-3100/ATD-6100 appliance showing numbered indicators 1 through 8 and power button on the right

                                                                                                                                                                                                                                                                                                                                                                                                            
LabelDescription
1System ID button with integrated indicator light
2NMI button (recessed, tool required for use)
3INTF2 activity indicator light
4System status indicator light
5Power button with integrated indicator light
6Hard drive activity indicator light
7System cold reset button
8INTF3 activity indicator light

Trellix Intelligent Sandbox 5.0.x Hardware Guide 11

1 | Setting up the Intelligent Sandbox Appliance


ATD-3100, and ATD-6100 Appliance back panel

   

Rear panel photo of the ATD-3100 and ATD-6100 appliance showing labeled callouts 1 through 10 over ports and power modules

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            

Label

Interface port

1

Power supply module 1

2

Power supply module 2

3

Ethernet interface 2 (intf2)

4

Ethernet interface 3 (intf3)

5

VGA connector

6

Serial console interface

7

USB 3.0 ports

8

BMC port (RMM)

9

Ethernet interface 0 (ATD Management Interface)

10

Ethernet interface 1 (intf1)

1 | Setting up the Intelligent Sandbox Appliance


ATD- 3200, ATD-6200 Appliance Front panel

   

Front panel of ATD-3200 / ATD-6200 appliance showing a row of indicators and buttons with red numbered callouts 1 through 8 pointing to each element, left-to-right

                                                                                                                                                                                                                                                                                                                                                                                                            

Label

Description

1

System ID button with integrated indicator light

2

NMI button (recessed, tool required for use)

3

NIC 1 activity indicator light

4

System status indicator light

5

Power button with integrated indicator light

6

Hard drive activity indicator light

7

System cold reset button

8

NIC 2 activity indicator light

Trellix Intelligent Sandbox 5.0.x Hardware Guide 13

1 | Setting up the Intelligent Sandbox Appliance


ATD- 3200, ATD-6200 Appliance Back panel - Configuration A

   

Rear view of ATD-3200 / ATD-6200 back panel — Configuration A — a full-width photograph showing the appliance rear with numbered red callouts 1 through 10 pointing to power modules, Ethernet ports, VGA, USB ports, and other interface connectors.

ATD- 3200, ATD-6200 Appliance Back panel - Configuration B

   

Rear view of ATD-3200 / ATD-6200 back panel — Configuration B — a full-width photograph similar to Configuration A showing alternate port arrangement with numbered red callouts 1 through 10.

                                                                                                                                                                                                                                                                                                                                                            
               

Label

           
               

Interface port

           
               

1

           
               

Power supply module 1

           
               

2

           
               

Power supply module 2

           
               

3

           
               

Ethernet interface 0 (ATD Management Interface)

           
               

4

           
               

Ethernet interface 1 (intf1)

           
               

5

           
               

VGA connector

           
               

6

           
               

Serial console interface

           
               

7

           
               

USB 3.0 ports (3)

           

1 | Setting up the Intelligent Sandbox Appliance


                                                                                                                                                                                            
               

Label

           
               

Interface port

           
               

8

           
               

BMC port (RMM)

           
               

9

           
               

Ethernet interface 3 (intf3)

           
               

10

           
               

Ethernet interface 2 (intf2)

           

If an item is missing or damaged, contact your supplier.

Hardware specifications

Before you set up the Intelligent Sandbox Appliance, review the hardware specifications.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       
               

Specification

           
               

ATD-3200

           
               

ATD-6200

           
               

Packaging Dimension

           
               

Length = 38", Width = 24", Height = 8"

           
               

Length = 38", Width = 24", Height = 8"

           
               

Chassis

           
               

Intel R1208WFTYSR (Wolf Pass)

           
               

Intel R1208WFTYSR (Wolf Pass)

           
               

Chassis Dimension

           
               

Length = 28", Width = 17.3", Height = 1.8"

           
               

Length = 28", Width = 17.3", Height = 1.8"

           
               

Packaged Weight

           
               

21 Kg (46.5 lbs)

           
               

22 Kg (48.5 lbs)

           
               

Form Factor

           
               

1U rack mountable; fits 19-inch rack

           
               

1U rack mountable; fits 19-inch rack

           
               

Motherboard

           
               

S2600WFTR

           
               

S2600WFTR

           
               

CPU

           
               

2 x Xeon Scalable Silver 4210, 2.20 GHz Base, 13.75MB cache, 10 Cores

           
               

2 x Xeon Scalable Gold 6230, 2.10 GHz Base, 27.5MB cache, 20 Cores

           
               

Storage

           
               
                       
  • Disk space HDD: 4 x 1.2 TB, SAS, 12 GB/s, 10K RPM, 2.5", Raid-5
  •                    
  • SSD: 2 x Enterprise grade 480 GB, SATA, 2.5", Raid-0
  •                
           
               
                       
  • Disk space HDD: 6 x 1.2 TB, SAS, 12GB/s, 10K RPM, 2.5", Raid-5
  •                    
  • SSD: 2 x Enterprise grade
  •                
           

1 | Setting up the Intelligent Sandbox Appliance


                                                                                                                                                                                                                                                                                                                                                                                                               
SpecificationATD-3200ATD-6200
960 GB, SATA, 2.5", Raid-0
Memory16 x 16 GB DDR4 2933 MHz ECC16 x 32 GB DDR4 2933 MHz ECC
Remote ManagementRMM4LITE2RMM4LITE2
Power Supply1100 W or 1300 W redundant1100 W or 1300 W redundant
Network Interfaces (Copper) - Configuration ADual Integrated 10 GB/1 GB/100 MB and Dual 10 GB/1 GB/100 MB ModuleDual Integrated 10 GB/1 GB/100 MB and Dual 10 GB/1 GB/100 MB Module
Network Interfaces (Copper) - Configuration BDual Integrated 10 GB/1 GB (onboard) and Dual 10 GB/1 GB/100 MB (PCIe I/O) ModuleDual Integrated 10 GB/1 GB (onboard) and Dual 10 GB/1 GB/100 MB (PCIe I/O) Module

                                                                                                                                                                                                                                                                                                                                                                                                                                                                   
SpecificationATD-3100ATD-6100
Packaging DimensionLength = 38", Width = 24", Height = 7"Length = 38", Width = 24", Height = 7"
ChassisIntel R1208WTTGSR (Wildcat Pass)Intel R1208WTTGSR (Wildcat Pass)
Chassis DimensionLength = 28", Width = 17.3", Height = 1.7"Length = 28", Width = 17.3", Height = 1.7"
Packaged Weight22.7 Kg (50 lbs)22.7 Kg (50 lbs)
Form Factor1U rack mountable; fits 19-inch rack1U rack mountable; fits 19-inch rack
MotherboardS2600WTTS2600WTT
CPU2 x E5-2609v4, 1.7 GHz, 20M cache, 8 Cores2 x E5-2695v4, 2.1 GHz, 45M cache, 18 Cores

1 | Setting up the Intelligent Sandbox Appliance

                                                                                                                                                                                                                                                                                                                                                                   
SpecificationATD-3100ATD-6100
Storage                
                       
  • Disk space HDD: 4 x 1.2 TB, SAS, 12 GB/s, 10K RPM, 2.5", Raid-5
  •                    
  • SSD: 2 x Enterprise grade 400 GB, 2.5", Raid-0
  •                
           
               
                       
  • Disk space HDD: 6 x 1.2 TB, SAS, 12GB/s, 10K RPM, 2.5", Raid-5
  •                    
  • SSD: 2 x Enterprise grade 800 GB, 2.5", Raid-0
  •                
           
Memory16 x 16 GB DDR4 2400 MHz ECC16 x 32 GB DDR4 2400 MHz ECC
Remote ManagementRMM4LITE2RMM4LITE2
Power Supply750 W redundant750 W redundant
Network Interfaces (Copper)Dual Integrated 10 GB/1 GB/100 MB and Dual 10 GB/1 GB/100 MB ModuleDual Integrated 10 GB/1 GB/100 MB and Dual 10 GB/1 GB/100 MB Module
                                                                                                                                                                                                                                                                                                                                                                                                                                                                           
SpecificationATD-3000ATD-6000
Packaging DimensionLength = 38", Width = 24", Height = 7"Length = 36", Width = 24", Height = 7"
ChassisR1304GZ4GCR2304LH2HKC
Chassis DimensionLength = 29", Width = 17.25", Height = 1.7"Length = 29", Width = 17.25", Height = 3.43"
Packaged Weight15 Kg (33 lbs)22.7 Kg (50 lbs.)
Form Factor1U rack mountable; fits 19-inch rack2U rack mountable; fits 19-inch rack
MotherboardS2600GZ4S4600LH2
CPU2 x E5-2658, 2.10 GHz, 20M Cache, 8 Cores4 x E5-4640, 2.40 GHz, 20M Cache, 8 Cores

1 | Setting up the Intelligent Sandbox Appliance


                                                                                                                                                                                                                                                                                                                                                                   
SpecificationATD-3000ATD-6000
Storage                
                       
  • Disk space HDD: 2 x 4 TB
  •                    
  • SSD: 2 x 400 GB
  •                
           
               
                       
  • Disk space HDD: 4 x 4 TB
  •                    
  • SSD: 2 x 800 GB
  •                
           
Memory192 GB256 GB
Remote ManagementRMM4RRMM4
Power Supply2x 750 W, AC redundant, hot swappable2x 1600 W, AC redundant, hot swappable
Network Interfaces (Copper)Dual Integrated 10 GB/1 GB/100 MB and Dual 10 GB/1 GB/100 MB ModuleDual Integrated 10 GB/1 GB/100 MB and Dual 10 GB/1 GB/100 MB Module

Default ports used in Intelligent Sandbox communication

Intelligent Sandbox Appliance uses many ports for network communications.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 
ClientServerDefault portConfigurableDescription
Any (desktop and REST API client)Intelligent SandboxTCP 443 (HTTPS)NoAccess the Intelligent Sandbox web interface and REST API client.
Any (desktop)Intelligent SandboxTCP 6080 (HTTPS)NoFor VM activation process and X-mode.
Any (FTP client)Intelligent SandboxTCP 21 (FTP)NoAccess the FTP servers on Intelligent Sandbox.
Any (SFTP client)Intelligent SandboxTCP 22 (SFTP)NoAccess the SFTP servers on Intelligent Sandbox.
SensorIntelligent SandboxTCP 8505NoCommunication channel between a Sensor and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             
               

Client

           
               

Server

           
               

Default
port

           
               

Configurable

           
               

Description

           
               

           
               

           
               

           
               

           
               

Intelligent Sandbox.

           
               

Manager

           
               

Intelligent Sandbox

           
               

TCP 443
(HTTPS)

           
               

No

           
               

Communication between the Manager and Intelligent Sandbox through the RESTful APIs.

           
               

Intelligent Sandbox

           
               

McAfee ePO

           
               

TCP 8443

           
               

Yes

           
               

Host information queries.

           
               

Intelligent Sandbox

           
               

atd.repl.gti.trellix.com

           
               

TCP 443
(HTTPS)

           
               

No

           
               

File Reputation queries.

           
               

Intelligent Sandbox

           
               

List.smartfilter.com

           
               

TCP 80
(HTTP)

           
               

No

           
               

URL updates.

           
               

Intelligent Sandbox

           
               

All DXL Brokers in your environment

           
               

TCP 8883
(HTTP)

           
               

No

           
               

DXL connection from TIS to DXL broker

           
               

Intelligent Sandbox

           
               

All McAfee ePO in your environment

           
               

TCP 443
(HTTP)

           
               

No

           
               

McAfee Agent on TIS gets DXL certificates from McAfee ePO

           
               

Intelligent Sandbox (DAT updates)

           
               

wpm.webwasher.com
wpm1-2.webwasher.com
wpm1-3.webwasher.com
wpm1-4.webwasher.com
tau.skyhigh.cloud
tau1-2.skyhigh.cloud
tau1-3.skyhigh.cloud
tau1-4.skyhigh.cloud
tau-usa.skyhigh.cloud
tau-europe.skyhigh.cloud
tau-asia.skyhigh.cloud
rpns.skyhigh.cloud
mwg-update.skyhigh.cloud
(Akamai CDN)

           
               

           
               

           
               

Updates for Trellix Gateway Anti-Malware Engine and Trellix Anti-Malware Engine.

           

1 | Setting up the Intelligent Sandbox Appliance


                                                                                                                                                                                                                                                                                                                                                                                                                                                     
ClientServerDefault portConfigurableDescription
tau-manual.skyhigh.cloud
               

Intelligent Sandbox
(Software updates)

           
atdupdate.trellix.comTCP 443 (HTTPS)No                

Updates for the Intelligent Sandbox software. The update includes new detection and application package.

           
               

Intelligent Sandbox
(Telemetry)

           
atd.rest.gti.trellix.comTCP 443 (HTTPS)No                

Sends telemetry data to Trellix. For information on what data is sent, see Configure telemetry in Trellix Intelligent Sandbox Installation Guide.

           
               

Any (SSH client)

           
               

Intelligent Sandbox

           
TCP 2222 (SSH)NoCLI access.

Set up the hardware

Install and integrate the hardware in your network.

Install or remove rack handles

       
  • To install a rack handle, align it with the two holes on the side of the Intelligent Sandbox Appliance and attach the rack handle to the Appliance with two screws as shown.
   
       

Note

   
   

ATD-3100, ATD-6100, ATD-3200, and ATD-6200 comes with the handles attached out of the box.

1 | Setting up the Intelligent Sandbox Appliance


Installing the rack handle

   

Illustration showing a rack handle being attached to the front corner of a server with two screws; arrows indicate screw locations and the handle placement.

       
  • To remove a rack handle, remove the two screws holding the rack handle in place, and remove the rack handle from the server system as shown.

Removing the rack handle

   

Illustration showing the rack handle being detached from the server with screws being removed; arrows indicate the removal direction.

Rack mount the appliance

To install the Intelligent Sandbox Appliance on the four-post 19-inch rack, use the rack-mounting kit. You can use the kit with most industry-standard rack cabinets.

Task

       
  1.        

    For each mounting rail, use the following steps.

           
                 
    1. At the front of the rack, position the right or left mounting rail on the corresponding side so that the mounting bracket aligns with the rack holes.
    2.        
       
   
       

⚠️ Caution

   
   

Always load the rack from the bottom up. If you are installing multiple appliances, start with the lowest available position.

1 | Setting up the Intelligent Sandbox Appliance


Slide rail installation

   

Large black-and-white technical diagram of a slide rail and mounting bracket. The image includes two circular zoom callouts — one showing the bracket latch mechanism and another showing the rail end with rectangular mounting holes — and an arrow indicating how the bracket attaches to the rack rail.

b. At the back of the rack, pull the back mounting-bracket (extending the mounting rail) so that it aligns with the rack holes.

On each side of the rack, ensure that the mounting rails are the same level.

Install rail to rack

   

Black-and-white diagram showing the rail aligned to the rack upright, with a close-up of the rail clip engaging the rack hole and a numbered callout indicating the clip position.

   

Black-and-white diagram of the rail assembly laid out horizontally, showing the inner and outer rail pieces and how they connect to the mounting bracket on the rack upright.

c. Clip the rail to the rack and secure it with the tie wraps.

2. Slide both rails so they are fully extended.

Full extend slide

   

[IMAGE PLACEHOLDER: Black-and-white technical illustration of the full-extend slide rail pulled fully out, showing the inner sliding rail nested within the outer channel and an arrow indicating full extension direction.]

3. With help from another person, lift the Intelligent Sandbox Appliance and install the chassis to the rail on both the sides.

Drop in the rear spool first, then the middle, then the front.

1 | Setting up the Intelligent Sandbox Appliance


Install the Appliance to rail

   

Rack-mounted Intelligent Sandbox Appliance being placed on rails with a close-up inset showing the release tab/rail engagement

   

⚠️ Caution

   
       

At least two people are required to lift and attach the Intelligent Sandbox Appliance to the rack.

   

If required, attach the lockable bezel to protect the front panel.

       
  1.        

    Lift the release tab and push the Intelligent Sandbox Appliance into the rack.

       

Lift release tab and push Appliance into rack

   

Side-view diagram showing the appliance slid into the rack with numbered callouts pointing to release tab and rail components

To remove the Intelligent Sandbox Appliance from the rack, lift the release tab next to the chassis front spool, then lift it out of the rails.

Turn on the Intelligent Sandbox Appliance

The Intelligent Sandbox Appliance has redundant power supplies pre-installed.

The Intelligent Sandbox Appliance ships with two AC power cords specific to your country or region.

Task

       
  1.        

    Plug one end of the AC power cord into the first power supply module in the back panel, then plug the other end into the power source.

       
  2.    
  3.        

    Plug one end of the other AC power cord into the second power supply module in the back panel, then plug the other end into the power source.

       

Trellix Intelligent Sandbox 5.0.x Hardware Guide 23

1 | Setting up the Intelligent Sandbox Appliance


end into the power source.

Intelligent Sandbox powers up without pressing the on/off button on the front panel.

To turn off the Intelligent Sandbox Appliance AC power, you must unplug both AC power cords from the back panel or power source.

   
       

Note

   
   

The on/off button on the front panel does not turn on/off the AC power.

To restart the Intelligent Sandbox Appliance, you must press the on/off power switch on the front panel while the appliance is turned on.

To turn off the Intelligent Sandbox Appliance, use the shutdown CLI command, then press the on/off power switch.

   
       

Note

   
   

When you plug power cord to both PSUs on ATD 3200/ATD 6200 model and provide power to both PSUs, you will see one PSU LED is blinking in 1 Hz frequency in green.        This is an expected behavior. The power supply with the blinking LED is in cold redundant state, meaning it is powered down to standby mode until the other power supply fails, or until the power supplies switch roles between primary and standby.

Handling the front bezel

You can remove the front bezel if required, and then re-install it. However, before you install the bezel, you must install the rack handles.

Task

       
  1.        

    Remove the front bezel.

           
                 
    1.                

      Unlock the bezel if it is locked.

                 
    2.            
    3.                

      Remove the left end of front bezel from rack handle.

                 
    4.            
    5.                

      Rotate the front bezel anticlockwise to release the latches on the right end from the rack handle.

                 
    6.        
       
   

Technical illustration showing removal of the front bezel from the appliance. The image depicts the front bezel being pulled forward and rotated (arrow labeled A) and the bezel separated from the rack handle (arrow labeled B).

1 | Setting up the Intelligent Sandbox Appliance


       
  1.        

    Install the front bezel.

           
                 
    1. Lock the right end of the front bezel to the rack handle

    2.            
    3. Rotate the front bezel clockwise until the left end clicks into place

    4.            
    5. Lock the bezel if needed.

    6.        
       
   

Illustration showing the front bezel being installed onto the appliance with arrows indicating rotation and locking points

Enable RMM

Enable Intel RMM on your Intelligent Sandbox Appliance.

Task

       
  1. Restart the Intelligent Sandbox Appliance.

  2.    
  3. During the reboot process, press F2.

  4.    
  5. On the BIOS Setup Utility page, select the Server Management tab.

  6.    
  7. Select BMC LAN Configuration.

  8.    
  9.        

    Locate Intel (R) RMM4 LAN configuration and configure the settings.

           
                 
    1. Highlight IP Source, press Enter, then select Static.

    2.            
    3. Highlight IP Address, then enter the IP address.

    4.            
    5. Highlight Subnet Mask, then enter the subnet mask address.

    6.            
    7. Highlight Gateway IP, then enter the gateway IP address.

    8.        
       
  10.    
  11.        

    Locate User configuration and configure the settings.

           
                 
    1. Highlight User status, press Enter, then select Enabled.

    2.            
    3. Highlight User password, press Enter, then enter the root account password.

    4.            
    5. Press Enter, confirm the password, then press Enter again.

    6.        
       
  12.    
  13. Press F10, then press Enter.

  14.    
  15. Log on to the RMM interface.

Connect the management port

When you connect your network device to the Intelligent Sandbox Appliance, you can configure the appliance IP address and other parameters for integration in your network.


Trellix Intelligent Sandbox 5.0.x Hardware Guide

25

1 | Setting up the Intelligent Sandbox Appliance


Task

       
  1. On the rear panel, plug the Category 5e or 6 Ethernet cable in the Ethernet port 1.        

    The Ethernet port 1 is the ATD Management port.

       
  2.    
  3. Plug the other end of the cable into the network device.

Configure the Intelligent Sandbox Appliance network information

Manage the Intelligent Sandbox Appliance from a remote computer or terminal server.

Task

       
  1. On the Intelligent Sandbox Appliance, connect a monitor to the VGA port.
  2.    
  3. Connect a keyboard to one of the USB ports.
  4.    
  5. To log on to the Intelligent Sandbox Appliance, use the following credentials.        
                 
    • User namecliadmin
    •            
    • Passwordatdadmin
    •        
           

    To access all the built-in command syntax instructions, enter help or ?. For a list of all commands, enter list.

       
  6.    
  7. Open the command prompt and configure the Intelligent Sandbox Appliance.        
                 
    1. Enter the Intelligent Sandbox Appliance name.                

      For example, set appliance name matd_appliance_1.

                 
    2.            
    3. Enter the Intelligent Sandbox Appliance management port IP address and subnet mask.                

      For example, set appliance ip 10.34.2.8 255.255.255.0.

                 
    4.            
                     

      Blue lightbulb Tip icon Tip

                     

      Best Practice: Use an alphanumeric character string up to 25 characters. The string must begin with a letter and can include hyphens, underscores, and periods, but not spaces.

                 
                 
                     

      Small blue Note icon Note

                     

      Do not assign this class C network IP address: 192.168.55.0/24.

                 
                 
    5. Enter the default gateway IP address.                

      For example, set appliance gateway 12.34.2.1.

                 
    6.            
    7. Restart the Intelligent Sandbox Appliance.
    8.            
    9. Enter the management port speed and duplex settings using one of the following commands:                
                           
      • set mgmtport auto — Sets the management port in auto mode for speed and duplex.
      •                    
      • set mgmtport speed (10|100) duplex (full|half) — Sets the speed to 10 or 100 Mbps at full or half duplex.
      •                
                 
    10.        
       

1 | Setting up the Intelligent Sandbox Appliance


f. To change the Intelligent Sandbox Appliance password, enter passwd.

Passwords are case sensitive, must not include spaces, and must contain the following:

       
  • Between 8 and 25 characters
  •    
  • At least one uppercase letter
  •    
  • At least one lowercase letter
  •    
  • At least one digit
  •    
  • At least one alphanumeric character or symbol
   
       

Tip

   
   

Best Practice: Enter a password with a combination of characters that is easy for you to remember, but difficult for someone else to guess.

g. Verify the configuration.

       
  • To view the configuration details, enter show.
  •    
  • To check the network connectivity, enter ping <IP address>.

The success message host <ip address> is alive appears. If the host is not reachable, failed to talk to <ip address> appears.

Copyright © 2026 Musarubra US LLC.

Trellix and FireEye are the trademarks or registered trademarks of Musarubra US LLC, FireEye Security Holdings US LLC, and their affiliates in the US and /or other countries. Other names and brands are the property of these companies or may be claimed as the property of others.

   

Trellix logo — bold black Trellix wordmark with a small multicolored chevron/mark (green to blue) at the top-right, positioned at the bottom-right of the page.