Link ePO - On-prem with ePO - SaaS Cloud Bridge

Prev Next

After you install DXL and Trellix EDR extensions, you must configure the ePO - SaaS Cloud Bridge to establish a connection between the ePO - On-prem environment and Trellix EDR Cloud. You use a token to establish this connection.

Note

Use this procedure to connect ePO - On-prem to the EDR workspace. This applies to hybrid environments.

Obtain a cloud token using XConsole

  1. Log in to XConsole.

  2. Select the profile icon and click Appliance and Server Registration.

    IAM_credentials.png
  3. Click Add.

  4. Select Trellix ePolicy Orchestrator - SaaS client type and enter 1 under Number of clients.

  5. Click Save.

  6. Once you expand the Trellix ePolicy Orchestrator - SaaS section, the token required to establish a connection between ePO - On-prem and Trellix EDR Cloud is displayed.

    IAM_Token.png

    Note

    The Appliance and Server Registration settings can also be accessed from ePO - SaaS menu.

Add the cloud token to the ePO server

  1. Log in to ePO - On-prem.

  2. Navigate to MenuConfigurationServer Settings. Under Setting Categories, search for ePO - SaaS Cloud Bridge.

  3. Click Edit and paste the token obtained earlier from step 6 in the Registration Token field.

  4. Click Restore default URL in the ePO Logon URL field.

  5. Click Save.

  6. The Status displays This server is linked.

  7. To verify ePO server settings, search for Trellix EDR Settings under Server Settings.

  8. View the connection status under Trellix EDR Cloud Services.

    Now the DXL on ePO - On-prem server is connected with the ePO - SaaS Cloud Bridge.

  9. To view the connected servers in Trellix ePO - SaaS, go to MenuConfigurationAppliance and Server Registration.

    1. Click Trellix ePolicy Orchestrator - SaaS under Servers.

    2. The Used Clients column displays the number of clients connected to ePO - SaaS.

    Important

    If your tenant is hosted in US-West, US-East, Frankfurt, Sydney, Canada, or Asia Pacific South data center, go to ePO - On-prem and navigate to MenuConfigurationServer SettingsDXL Cloud Databus and add the URL based on the data center location where your tenant is hosted.

    • US-West data center — https://api.soc.trellix.com/cloudproxy/databus/produce

    • US-East data center — https://api.soc.us-east-1.trellix.com/cloudproxy/databus/produce

    • Sydney data center — https://api.soc.ap-southeast-2.trellix.com/cloudproxy/databus/produce

    • Canada data center — https://api.soc.can-central-1.trellix.com/cloudproxy/databus/produce

    • Asia Pacific South data center — https://api.soc.ap-south-1.trellix.com/cloudproxy/databus/produce

    An incorrect URL configuration in the DXL Cloud Databus causes EDR workspace features to become non-functional or display incomplete data.

    If you are unsure of your data center location, contact Trellix Support and provide your tenant ID.