Licenses for virtual appliances are based on a unique appliance ID. Trellix sends you two secure emails. One email contains the appliance ID, a unique activation code, and a link to download the software image for the virtual appliance. The other email contains the license keys for the virtual appliance.
The FIREEYE_APPLIANCE (product) license for a virtual appliance must be continually validated by a token server. The token server uses a time-limited token to activate the product license on the virtual appliance. The token also provides a short-term lease on the product license. The virtual appliance must continually renew this lease to keep its product license active. If the product license becomes inactive, malware detection is disabled on the appliance.
Note
The start and stop dates for the product license also govern whether the license remains active.
How it works
After the virtual appliance has been activated, it connects to the token server and requests a license token for its product license. If the DTI credentials the appliance presents are valid, the token server sends the appliance a token that allows the product license to be active for the duration of the lease.
The duration of a lease is one hour, so the license token must be renewed every hour. The appliance applies for the lease renewal with enough lead time to keep the appliance functioning if an event such as a brief network outage occurs. The lead time is 15 minutes by default and can be changed with the assistance of Trellix Technical Support.
The token server grants grace periods to allow for token server failures and network outages. Initially there is no grace period. After the virtual appliance has been continually licensed for three hours, the token server grants the appliance six hours of grace time. If the current token expires and the token renewal fails, the product license will remain active for up to six hours while the appliance continues to send a renewal request every minute to the token server. The grace period is extended to three days if Trellix determines that your network is down and unable to contact the DTI network. When connectivity is restored, the appliance automatically requests a new license token.
Trellix takes the following measures to guard against accidental or malicious abuse of the product license.
Hourly validation. Authentication and authorization take place every hour, because each token request must be validated against the virtual appliance's DTI credentials.
Duplicate detection. The token server detects duplicate virtual appliances based on the appliance ID in the activation code, the universal unique identifier (UUID) of the virtual appliance, and the last license token renewal request that was presented to the server. A brief period of overlap is allowed to support a legitimate migration of the virtual appliance to another ESXi server, or a database backup and restore operation.
Time service. The token server provides a time service to prevent appliance clock manipulation.
SNMP and email event notifications warn you if the product license becomes inactive, if the token server cannot be reached, or if a duplicate virtual appliance is detected. The identity of the duplicate appliance is kept confidential for security.
Monitor, Operator, or Admin access to view licensing information