The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure the TIE server topology

Prev Next

TIE server appliances can run in different operation modes for scaling and fail-over capabilities.

After completing the installation, configure the operation mode of your TIE server instances that are managed by your local Trellix ePO - On-prem.

Note

In fresh installations, the operation modes of the first two appliances are configured automatically.

  1. On the Server Settings page in Trellix ePO - On-prem, configure the operation modes of the server appliances.

    • Primary — Holds and writes the TIE server database and replicates the updates to all Secondary instances.

      Caution

      We support only one Primary server per Trellix DXL fabric.

    • Write-Only Primary — Writes, maintains, and replicates the database. It includes metadata and reputation update requests since it doesn't process endpoint requests.

    • Secondary — Processes Trellix DXL requests exactly like a Primary instance using a database that is replicated from the Primary server.

    • Reporting Secondary — Improves the Trellix ePO - On-prem reporting services. It doesn't process reputation requests.

    • Reputation Cache — An in-memory cache synchronized through Trellix DXL that minimizes network requirements and provides endpoint operational reputation services. The Reputation cache rebuilds after rebooting because it resides in memory.

    In an environment with multiple Trellix ePO - On-prem servers, only TIE servers managed by a local Trellix ePO - On-prem server are editable.

    For an environment with a single Trellix ePO - On-prem server, managed TIE servers are displayed in a tree structure where the root is the instance operating in primary mode.

  2. In Trellix ePO - On-prem, select MenuConfigurationServer SettingsTIE Server Topology Management, then click Edit.

  3. For each server instance you want to edit:

    1. Select the TIE server instance to edit, then select the Operation Mode from the drop-down list.

    2. Click Save.

    Caution

    Changing a primary to a secondary operation mode during a disaster recovery might delete its database content. Always promote a secondary to primary operation mode before trying a synchronization from another primary server.

    In a single primary instance scenario, you can have only one primary instance in your fabric after the update, regardless of which Trellix ePO - On-prem manages the primary instance.

  4. After you save your changes, the background processing applies the changes on each TIE server instance. This process can take several minutes. Wait a few minutes and press F5 or click Refresh in the browser to see your new TIE server topology.

  5. If your appliance wake-up port is filtered, manually restart the Trellix Agent service. Otherwise, it takes time for the policy to reach the appliance.

    See KB52707 for details about restarting the Trellix Agent service.