Prerequisite tasks

Prev Next

SmartVision is supported in cloud and on-premises deployments of Trellix MVX. Follow these steps to verify that the MVX environment and the Network Security appliances meet the prerequisites for deploying SmartVision.

To prepare the MVX environment and appliances:
  1. Make sure the appliance models and software versions support SmartVision. See Supported appliances.

  2. Deploy and verify TrellixMVX (cloud or on-premises).

    See the appropriate guide:

    • Distributed Network Security Cloud MVX Guide

    • Distributed Network Security IVX Smart Grid Guide

  3. (As needed) Install virtual appliances.

    See the "Deploying Virtual Appliances" section in the appropriate guide:

    • Distributed Network Security Cloud MVX Guide

    • Distributed Network Security IVX Smart Grid Guide

    See Requirements for SmartVision-specific details.

  4. (As needed) Install physical appliances in TAP mode.

    See the Hardware Administration Guide for your Network Security appliance model and the "Performing the Initial Configuration" section in the appropriate guide:

    • Distributed Network Security Cloud MVX Guide

    • Distributed Network Security IVX Smart Grid Guide

    See Requirements for SmartVision-specific details. A network TAP device installed inline between the internal firewall and a server-side switch sends the appliance a real-time duplicate copy of the traffic that traverses the internal network.

    Note

    If you use a SmartVision appliance for data exfiltration detection only, you can install the appliance either at the network perimeter or in the network core, depending on the locations of the hosts and networks being monitored.

  5. (Optional) Configure integrated appliances to operate as sensors.

    For some integrated appliance models, events-per-second capacity is increased when configured to operate as sensors. See Recommended maximum EPS rates.

    For information about converting an integrated appliance to operate as a sensor, see the "Converting to Sensor Mode" section in the appropriate guide:

    • Distributed Network Security Cloud MVX Guide

    • Distributed Network Security IVX Smart Grid Guide

  6. (Optional) Add appliances to Central Management System management.

    If you installed new appliances to be managed by an on-premises Central Management System appliance, see the "Adding Sensors to the Central Management System" section in the appropriate guide:

    • Distributed Network Security Cloud MVX Guide

    • Distributed Network Security IVX Smart Grid Guide

    See Standalone or centrally managed SmartVision appliances for information specific to a deployment.

  7. As needed: Manually enroll managed appliances.

    If you added managed appliances, see the "Enrolling with an IVX Cluster" in the appropriate guide:

    • Distributed Network Security Cloud MVX Guide

    • Distributed Network Security IVX Smart Grid Guide

    See Enrollment of SmartVision appliances for information specific to a deployment.

  8. (For Cloud MVX) Verify the Trellix cloud MVX deployment.

    If using a Cloud MVX deployment, follow the procedures in the "Checking Sensor Status" in the Distributed Network Security Cloud MVX Guide

    1. Check the appliance's connection to its cloud broker.

      See "Checking the connection status using the Network Security Web UI".

    2. Check the same connection for a sensor managed by a Central Management System appliance. See "Checking the sensor status using the Central Management System Web UI".

    3. Check the sensor's enrollment status in the cloud MVX service.

      See "Checking the enrollment status using the Network Security Web UI".

  9. (For IVX cluster) Verify the on-premises IVX cluster deployment.

    If using an on-premises IVX cluster deployment, see the "Checking Sensor Status" in the Distributed Network Security Cloud MVX Guide.

    1. Check the health of the cluster and its components.

      See "Checking the cluster health".

    2. View cluster statistics from the Central Management System appliance and new sensors.

      See "Checking cluster utilization and performance".