You can securely erase (wipe) proprietary and confidential data from the persistent media on an appliance before you return it to Trellix at the end of an evaluation or when you need to use a Return of Materials Authorization (RMA) to replace the appliance. The secure erase operation overwrites every addressable byte of the media device at least once, and then verifies that the operation succeeded.
You use the Tools (also known as Boot) menu in the boot manager to perform these actions. The boot manager requires serial or physical console access and a password. You can either wipe the appliance media only or wipe the appliance media and manufacture the appliance. These options are described in Boot manager utilities .
The media wipe operation could take from six to ten hours, depending on the disk size. The status of the current operation is displayed in the console so you can monitor the progress, which is refreshed periodically.
Make sure the requirements for the Tools menu are met. See System requirements .
Wiping persistent media using the Tools menu
Use the procedure in this section to wipe persistent media from the appliance.
Go to the Tools (displayed as Boot) menu as described in Accessing the Tools Menu .
Boot Menu --------------------------------------------------------------- 0: Reset admin Password 1: Wipe Appliance Media 2: Manufacture Appliance 3: Wipe Appliance Media and Manufacture Appliance 4: Return to Image Boot Menu ---------------------------------------------------------------
To only wipe the media, use the ^ and v keys to select 1: Wipe Appliance Media.
Caution
This option will leave the appliance unusable.
To both wipe the media and then manufacture the appliance, select 3: Wipe Appliance Media and Manufacture Appliance.
Press Enter.
Example
The following example from a Network Security appliance accesses the Tools menu, and then wipes the appliance media and manufactures the appliance. For brevity, some console output is omitted.
nx-03 (config) # reload Configuration changed: save changes? Configuration changes saved. Rebooting... ... boot: Booting from local disk... PXE-MOF: Exiting Intel Boot Agent. Booting default image in 3 seconds. ... This terminal is not active for input or output while booting. Booting default image in 1 seconds. Boot Menu --------------------------------------------------------------- 0: wmps wMPS (wMPS) 8.0.0... 1: wmps wMPS (wMPS) 7.9.4... 2: Tools Menu --------------------------------------------------------------- Use the ^ and v keys to select which entry is highlighted. Press enter to boot the selected image or 'p' to enter a password to unlock the next set of features. Highlighted entry is 2: Booting: 'Tools Menu' Password: ******** ....... Boot Menu --------------------------------------------------------------- 0: Reset admin Password 1: Wipe Appliance Media 2: Manufacture Appliance 3: Wipe Appliance Media and Manufacture Appliance 4: Return to Image Boot Menu --------------------------------------------------------------- Use the ^ and v keys to select which entry is highlighted. Press enter to boot the selected image or 'p' to enter a password to unlock the next set of features. Highlighted entry is 3: Booting: 'Wipe Appliance Media and Manufacture Appliance' ... Running /etc/init.d/rcS.d/S33diskwipe - Preparing to run diskwipe... *** WARNING: DO NOT POWER OFF! *** == Detecting disks to wipe == Wiping system disks scrub: using NNSA NAP-14.1-C patterns scrub: please verify that device size below is correct! scrub: scrubbing /dev/sda 1919313510400 bytes (~1787GB) scrub: random |.......| ..................
Note
The
'p'option cited in the console instructions is not available.