On-premises Endpoint server

Prev Next

Important

There are two versions of IAM. If the URL you use to access the IAM UI ends with fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends with trellix.com, see the Trellix IAM Guide for information regarding IAM.

Task

Information

Done

Verify that the customer ID on the Endpoint Security (HX) appliance matches the ID in the IAM Web UI.

  1. Run the show version command in the Endpoint Security (HX) CLI and locate the Customer ID field.

  2. Log into your Trellix Cloud Account and click My Settings > My Organization. Locate the Oracle Customer ID field on the Organization Settings page.

Standalone servers: Prevent the Endpoint Security (HX) server from automatically discovering and connecting to a Helix Enterprise-enabled cloud Central Management System appliance (if any).

Run the no cmc client enable command in the Endpoint Security (HX) CLI.

See Preventing connections to a cloud Central Management appliance.

Enable Helix Enterprise mode on the Endpoint Security (HX) server.

Run the helix mode on-premises command to enable Helix Enterprise and allow Single Sign-On (SSO).

Run the helix mode on-premises with-sso command to enable Helix Enterprise and enforce SSO.

See Enabling Helix mode.

Central Management System-connected servers: Ensure that alerts and health statistics are sent directly to Helix Enterprise and not through the Helix Enterprise-enabled Central Management System appliance.

Run the show datastreaming helix command on each connected server and verify that the Helix data-streaming enabled field is yes.

Run the show helix health-stats status command on each connected server and verify that the Enabled field is yes.

Run the no fenet dti helix service override command on each connected server.

See Sending alerts and health stats directly from appliances.

Configure the HelixConnect Client on each server.

The HelixConnect Client is enabled automatically when Helix Enterprise mode is enabled, but additional steps may be required.

See Establishing HelixConnect connectivity.

If your servers use an HTTP proxy for outbound communication: Enable the servers to communicate with Helix Enterprise through the proxy.

Run the helix proxy preference fenet-proxy command on the servers.

See Enabling HTTP proxy communication.

Verify that the Endpoint Security (HX) controller can reach Helix Enterprise.

Enable access to <customer Helix ID>.receiver.apps.fireeye.com over port TCP 443.