You must perform the following steps to deploy physical appliances in your Trellix distributed Network Security.
Plan
Perform the following steps before you begin the deployment.
Decide where you want to deploy sensors, hybrid appliances, and clusters in your network.
Decide the deployment and operational mode for each Network Security sensor and each Network Security integrated appliance that will operate in sensor or hybrid mode.
Sensors and hybrid appliances can be deployed in the same modes as integrated appliances. See the Network Security System Administration Guide and Network Security User Guide for details about the modes.
Decide the deployment and operational mode for each Email Security — Server Edition sensor and integrated Email Security — Server Edition appliance that will operate in hybrid mode.
Sensors and hybrid appliances can be deployed in the same modes as integrated appliances. See the Email Security — Server Edition User Guide for information about the modes.
Decide how File Protect sensors and File Protect integrated appliances that will operate in hybrid mode will access network shares.
Sensors, hybrid appliances, and integrated appliances can access network shares in the same way. See the File Protect User Guide for information about network share access.
Gather items from your network administrator
Have the following items ready before you begin the deployment.
Static or reserved IP address, subnet mask, and default gateway address for the management interface.
IP address for each Domain Name System (DNS) server.
IP address for each Network Time Protocol (NTP) server.
Telnet or SSH client on the remote system (if the component will be managed remotely).
Physical appliances: If you plan to configure initial settings using the serial console port and a Windows or Mac laptop, obtain a USB-to-serial cable.
Gather information from Trellix
Have the following items ready before you begin the deployment.
License keys (if the license update service is not enabled).
Virtual appliances:
Activation code, which gives the virtual appliance a unique identity (its appliance ID), activates the product (FIREEYE_APPLIANCE) license, allows access to the license token server, provides access to the DTI network, protects against fraudulent use of the appliance, and allows the appliance to initialize.
Link to an OVA file containing your customer-specific system image.
Deploy virtual appliances
See the Trellix Device Deployment Guide for information about deploying virtual appliances.
Deploy physical appliances
Perform the following steps to deploy physical appliances in your network.
Install the appliances in your network.
See the Hardware Administration Guide for the appliance and the Trellix Device Deployment Guide.
Enable sensor mode on integrated Network Security appliances, as described in Enabling and disabling MVX sensor or hybrid mode.
Enable hybrid MVX mode on integrated Network Security, Email Security — Server Edition, and File Protect appliances, as described in Enabling and disabling MVX sensor or hybrid mode.
Configure the enrollment service
Enrollment is automatic for sensors and hybrid appliances that are managed by the same Central Management appliance that manages the MVX IVXcluster. Perform the procedure below based on your enrollment scenario.
If you want managed sensors to enroll directly with an IVX cluster on another Central Management appliance, configure the enrollment service on the sensors to point to the other Central Management appliance. See Enrolling a managed sensor directly.
If you want sensors to enroll through the Central Management appliance that manages the sensors, configure the enrollment service on that Central Management appliance to point to the other Central Management appliance. See Enrolling a managed sensor through a proxy .
If your sensors are standalone appliances, configure the enrollment service to point to the Central Management appliance that manages the IVX cluster. See Enrolling a standalone sensor.
Add appliances to the Central Management appliance
Add the Virtual Execution appliances, as described in Adding nodes and sensors to a Central Management appliance.
If the sensors will be managed: Add the appliances, as described in Adding sensors and hybrid appliances to a Central Management appliance.
If you are deploying hybrid appliances: Add the appliances, as described in Adding sensors and hybrid appliances to a Central Management appliance.
Complete the configuration
Complete the configuration
If the license update feature is disabled: Install FIREEYE_SUPPORT and feature licenses.
The license update feature enables your appliance to automatically download and apply licenses to which you are contractually entitled. This feature is enabled with the configuration wizard during the initial configuration, and is fully functional after the configuration wizard is completed.
See the Administration Guide or System Administration Guide for the appliance.
Configure other system administration features such as AAA, SSL certificates, SNMP, email notification recipients, and so on.
Configure detection settings, such as operational mode, policies, notifications, reports, and so on. See the Network Security User Guide and Email Security - Server User Guide.
Add storage and configure detection settings, such as scans, notifications, reports, and so on. See the File Protect User Guide.
(Optional) Define and upload custom YARA rules. See the Intelligent Virtual Execution System Administration Guide.
Create the cluster
Create the cluster, as described in Creating a cluster.
Check the cluster health and performance
Check that the cluster and its components are healthy and that the cluster utilization and performance are acceptable, as described in Viewing cluster and node status and Viewing cluster utilization.