MSSP deployment scenario

Prev Next

In a managed security service provider (MSSP) deployment, the MSSP deploys and maintains the IVX cluster in its premises (also referred to as a private cloud). A single physical or virtual Central Management appliance or Central Management High Availability (HA) pair manages the cluster. The MSSP also deploys and maintains the Central Management appliance. The IVX cluster and the Central Management appliance that manages the IVX cluster can be in different data centers.

MSSP customers configure their on-premises sensors to enroll with the cluster. The sensors can be standalone appliances or be managed by an on-premises Central Management appliance. The sensors can be in different locations.

Although the IVX cluster components (brokers and compute nodes) only need reliable IP connectivity, Trellix recommends that they be deployed on the same LAN.

Important

Do not use transcontinental deployments due to throughput, reliability, and latency issues.

Note

The Central Management appliance that manages sensors that submit to a cluster in a private cloud must be running a release that is compatible with the managed sensors.

A sensor can be a physical Network Security appliance or a virtual Network Security, Email Security — Server, or File Protect appliance. The physical NX 1500 model can function only as a sensor, because it does not include an on-board MVX analysis engine. Some physical Network Security appliances can be enabled as sensors, in which case their on-board MVX analysis engines are disabled. A virtual appliance can function only as a sensor.

A broker or node is a physical Virtual Execution appliance. A Virtual Execution appliance serves no purpose until it is added to a cluster.

The following diagram illustrates the basic components of an MSSP deployment.

image11.jpeg