You can update managed appliances with the latest appliance system image and guest images from the Central Management System Web UI or CLI. When the Central Management System appliance is in "online" mode (that is, connected to the DTI network), checks for newer available versions are automatically performed for managed appliances that have the appropriate licenses installed. In online mode, the Central Management System appliance stores the images in a DTI cache on the Central Management System appliance. If an update is requested, and the requested image is not already in the cache, the Central Management System appliance downloads it. A Central Management System administrator can manually download images to the cache when it is convenient instead of waiting for an update request. This can save bandwidth and shorten the maintenance window for updating appliances. For details, see Understanding the DTI cache and Downloading software updates to the DTI cache.
You can update multiple appliances at the same time. Each appliance is updated independently and does not depend on updates being completed on other appliances. However, if the images are not already in the cache, and if the DTI source server is very busy or if the connection to it is slow, the update could time out.
System images should be updated before you install guest images. If you request system image and guest images updates at the same time, the system image is updated first. However, if the appliance is rebooted before the guest images are downloaded (for example, if you choose to automatically reboot the appliance after the system image update), the request to download guest images is lost, so you must request it again.
You could instead stagger the updates to minimize the impact to the system. For example, you could update the appliance software images, but then wait until off-hours or a maintenance window to update the guest images, because guest images take longer to download and install.
Caution
If an appliance is running a system image version that your Central Management System appliance no longer supports, a message is displayed on the Central Management System Dashboard, and you should update the appliance immediately. Data will not be aggregated from that appliance to the Central Management System appliance until you update, and you will be unable to make configuration changes on behalf of the appliance.
Note
These procedures show how to update managed appliances when the Central Management System appliance is in "online" mode and connected to the DTI network. When the Central Management System appliance is not connected to the DTI network, it can be in "local" or "URL" mode, in which it downloads the updates from a file that is either stored locally or hosted on a local site identified by a URL. For details, see the Trellix DTI Offline Update Portal Guide.
Note
These procedures show how to update software images and guest images. By default, security content is automatically downloaded to the cache and updated on managed appliances. For details about changing the update settings, see the System Administration Guide or Administration Guide for the managed appliance.
Admin access
DTI network access
FIREEYE_SUPPORT license on each managed appliance for system image updates
CONTENT_UPDATES license on each managed appliance for security content updates