You must use the eth-0 interfaces (management ports) of the Intelligent Sandbox Appliances for cluster communication.
Note
The eth-0 interfaces of all nodes must be in the same layer-2 network of the OSI reference model for better performance and to avoid network latency.
The nodes must be homogenous regarding the following:
Intelligent Sandbox software version. The software versions of all nodes must exactly match.
Analyzer VMs. All nodes must have the same analyzer VMs.
It is recommended that DAT and engine versions of Trellix Anti-Malware Engine are the same in all nodes.
It is recommended that DAT and engine versions of Trellix Gateway Anti-Malware Engine are the same in all nodes.
The nodes can be heterogenous regarding the following:
Hardware. That is, you can create a cluster using a combination of ATD-3100 and ATD-6100 Appliances.
FIPS compliance. Regardless of primary or secondary, some nodes can be in FIPS mode and the rest in non-FIPS mode.
Note
In Common Criteria (CC) mode, Load-balancing is not supported.
Use the IP address of the Primary node to submit files and to integrate with other products such as Trellix IPS, McAfee Email Gateway, and Web Gateway. If Backup node is present in cluster, these integrated products need to be configured with cluster IP address. The Primary node or the primary Intelligent Sandbox Appliance acts as the external interface for the cluster. That is, the Primary node is associated to the IP address of the cluster from the standpoint of configuration and file submission. If you integrate Trellix IPS, Web Gateway and Email Gateway with the secondary nodes, these nodes function like standalone Intelligent Sandbox Appliances.
Note
Integrating an Intelligent Sandbox cluster with Email Gateway is supported with release 3.4.2.
If the Primary node is down, the Backup node takes over. Backup node must be in same L2 network as Primary node.
User can view the Analysis Status and Analysis Results of all nodes in cluster from Active node, that is Primary node or Backup node.
You can wipe out all cluster-related configurations from a node and make it as a standalone box.
clearlbconfigcommand is used to destroy cluster using CLI. It is permitted to run at all nodes (Primary/ Backup/Secondary). This command can be used in scenarios where normal means of removing a node (Remove Node/ Withdraw From Cluster) does not remove that node from cluster.To delete VMs from the secondary node, make sure that you delete it through VM Synchronization. That is, do not delete the image from the Policy page of Secondary. To delete the image, delete it from the Primary, then during VM Synchronization, the image is deleted from Secondary automatically.
From the Intelligent Sandbox user interface, you can only validate, activate, and delete inactive node VMs.
Make sure the node to be added to the cluster are not in "BAD" state or in "VM creation failed" condition.
If the VM synchronization fails, an automatic re-attempt of the synchronization does not take place.
For VM Sync failure on secondary/backup node the node’s status on primary shows
VM Sync failed. In this case user has to go to each Individual node and check system log for further steps. Take corrective measures for failure scenarios, then click the Sync All VMs button, if VM synchronization starts automatically no further action is required.Sample distribution to a particular node does not take place in case the node has either of the following status messages:
VM Sync In Progress
VM Sync Failed
If secondary node’s system.log says
VMSync cannot be initiated as VM Creation has failed on this node, then execute the CLI commandreboot vmcreator.VM sync fails if Primary and Secondary nodes have images with the same name.
When adding a node to a cluster with the same hardware, VM Synchronization begins and the status of the node changes in the following order:
Option
Definition
VM Mismatch
VMs between Primary and new node do not match.
VM Sync in progress
VM Synchronization in progress.
Up and ready
All VMs and VM profiles are copied to the new node.
Hybrid cluster
In a cluster, ATD-3000, ATD-3100, ATD-3200, ATD-6000, ATD-6100 and ATD-6200 are all treated as different appliances. For example, a cluster with only ATD-3000 and ATD-3100 is considered a hybrid cluster. Similarly, a cluster with ATD-6000 and ATD-6100 is considered a hybrid cluster.
When a new node with a different hardware is added to a cluster, a warning message is displayed indicating the difference is hardware type with the Primary.
Before you add a secondary node to a hybrid cluster, make sure that you delete all images, VM profiles, and Analyzer profiles from the secondary.
Due to the difference in hardware, during VM Synchronization, the licenses are not applied.
Once the new node is successfully added to the cluster, VM Synchronization begins and the status of the node changes in the following order:
Option
Definition
VM Mismatch
VMs between Primary and new node do not match.
VM Sync in progress
VM Synchronization in progress.
SCP of all images completed
All VMs are copied successfully from Primary to the new node through Secure Copy Protocol (SCP).
Note
This status does not change to Up and ready until the VM profiles match between Primary and the new node.
Up and ready
All VMs and VM profiles are copied to the new node.
Once the node is added to the cluster, and its status changes to SCP of all images completed, manually activate the VMs and create the licenses for the VMs.
Once the status in all nodes is Up and ready, create the Analyzer profiles in the Primary node.
If the status doesn't change from SCP of all images completed, then review the following:
Verify that the licenses in the new node are activated. If not, manually activate the license in the new node.
Verify that the VM profiles in the new node match the VM profiles on Primary.
For example, the new node might be missing the default VM profile. In that case, you need to manually create the VM profile.
In a hybrid cluster, the Policy tab in your Intelligent Sandbox web UI is kept enabled which allows you to manually create or edit the VM profiles.
If the new node has more VM profiles than the Primary, the VM profiles in the new node are automatically deleted during VM Synchronization.
In a hybrid clustering environment, the Microsoft Office and analyzer VM operating system licenses have not been retained because of hardware changes.