Requirements

Prev Next

This topic covers requirements for deploying SmartVision:

Trellix MVX deployment

SmartVision appliance deployment must meet the following requirements:

Cloud deployment or on-premises deployment

In a cloud MVX deployment, sensors ( Edition sensors and Network Security sensors) enroll with the cloud MVX service. In an on-premises MVX cluster deployment, sensors and broker nodes enroll with an on-premises MVX cluster. Comprehensive information about the two architectures is available in other guides (see Related documentation).

This guide describes how to deploy and operate in either architecture. Installation details and operational limitations described in this guide supersede information in guides that are not specific to SmartVision.

Broker nodes

In an on-premises MVX cluster deployment, at least one compute node must be enabled as a broker node and a maximum of two broker nodes is supported.

SmartVision appliance placement and operational mode

SmartVision appliances are typically installed behind internal firewalls on server-side traffic. This allows the appliances to capture traffic between clients and servers or between peer systems.

For general information about Network Security appliance operational modes that is not specific to a environment, see the following guides:

  • Hardware Administration Guide for your appliance model

  • Network Security System Administration Guide

TAP deployment

A Test Access Point (TAP) device provides a real-time duplicate copy of the traffic through the network, with transmit and receive signals delivered on separate ports.

Tip

For optimal accuracy and performance, Trellix recommends that you deploy appliances out-of-band using a TAP device. Packets are not dropped, even when the link is heavily utilized. To maximize throughput, whitelist known safe traffic.

SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition FIREEYE_APPLIANCE licenses, enforce TAP operational mode. The Web UI and CLI do not provide for configuring any other operational mode.

The basic steps to install an appliance in a TAP deployment are as follows:

  1. Connect a TAP device inline between the internal firewall and a server-side switch.

  2. Connect the two appliance monitoring ports to the ingress and egress ports on the TAP device.

  3. Connect the appliance primary management port to the switch.

Port mirroring for validation only

If no TAP device is available during preliminary validation of your installation, you can temporarily use a Switch Port Analyzer (SPAN) port (also called port mirroring).

Important

Trellix does not recommend SPAN deployment of SmartVision in a production environment. Depending on network utilization, SPAN packet capture can drop packets or degrade switch performance.

To use a SmartVision appliance in a SPAN deployment―which is acceptable for preliminary validation tasks only―the basic installation steps are as follows:

  1. Configure the SPAN port of a switch between the internal firewall and a server-side switch. Verify that bidirectional TCP port 80 (HTTP) traffic passes through the port.

  2. Connect one of the appliance monitoring ports to the SPAN port.

  3. Connect the appliance primary management port to the switch.

Standalone or centrally managed appliances

Like standard Network Security appliances, appliances can be managed by a Central Management System appliance or can be standalone appliances that are not managed by a Central Management System appliance. The following guidelines apply to managed appliances.

  • A managed appliance installed in an on-premises deployment can be managed by the same Central Management System appliance that manages the MVX cluster, or it can be managed by another Central Management System appliance in the cluster.

  • A managed appliance sends alerts to the Central Management System appliance, which aggregates the alerts and displays them on a single interface.

    A standalone appliance displays its own alerts.

  • By default, managed appliances use their managing Central Management System appliance as their DTI source server. The Central Management System appliance replaces the DTI server as the managed appliance's source for software updates, guest image updates, and security content updates.

    Note

    If a managed appliance communicates with the Central Management System appliance using the default single-port address type, do not change the active DTI source. Single-port communication requires the managing Central Management System appliance as the DTI source.

  • Managed appliances are typically operated using the Web UI or CLI of the managing Central Management System appliance.

Enrollment of SmartVision appliances

SmartVision appliances enroll in Trellix MVX in the same way as other Network Security appliances:

  • Before a SmartVisionappliance can send its submissions for analysis by a remote MVX engine, it must authenticate with the enrolment

    service for cloud MVX or the on-premises MVX cluster.

    The enrollment service validates the appliance's DTI credentials and appliance ID. In a cloud deployment, the enrollment service additionally verifies that the appliance has an active license for the cloud MVX service.

  • Standalone appliances automatically enroll with the cloud MVX service or the on-premises MVX cluster.

  • Centrally managed appliances must be manually enrolled.