Deploy an on-premises appliance by completing the following steps.
Task | Instructions |
|---|---|
1. Verify that your environment meets the necessary requirements. | See . |
2. Gather license information from Trellix. | Get license keys from Trellix if the license update service is not enabled. See . |
3. Configure your Endpoint Security (HX) physical appliance. |
|
4. Install the required Trellix licenses. | Install the FIREEYE_SUPPORT and other licenses (if the license update feature is disabled). See . The license update feature enables your appliance to automatically download and apply licenses to which you are contractually entitled. This feature is enabled with the configuration wizard during the initial configuration and is fully functional after the configuration wizard is completed. |
5. Configure other system administration features such as AAA, SSL certificates, and SNMP data access | See the Trellix System Security Guide and the Endpoint Security (HX) System Administration Guide. |
6. Verify that the Endpoint Security (HX) appliance is connected to Trellix's Dynamic Threat Intelligence (DTI) cloud. | If the validation fails, verify that the DTI configuration is set up correctly. See the Endpoint Security (HX) System Administration Guide. |
7. Attach your HXD (DMZ) appliances to the internal Endpoint Security (HX) appliance. | See .
|
8. Set up the server address list. | See . |
9. Identify your provisioning appliances. | Agents earlier than version 20 can only provision against a single primary appliance. Agents version 20 or later can provision against multiple appliances. By default, your internal Endpoint Security (HX) hardware appliance is a provisioning appliance. A virtual appliance can be used as a provisioning appliance. See .
|
10. Obtain the agent installation package. | If your Endpoint Security (HX) appliance is connected to DTI, the most recent Windows, macOS and Linux agent images are automatically downloaded to the appliance after the DTI connection is established. If your Endpoint Security (HX) appliance is not connected to DTI or if you need an older agent image than the ones that have been downloaded, you will need to manually download the agent image you need.
See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide. |
11. Install the agent software on your host endpoints. | See the appropriate version of the Endpoint Security Agent (HX) Deployment Guide.
|
12. Optionally connect your Endpoint Security (HX) appliance to Helix. | After you have deployed your Endpoint Security (HX) appliance and installed the agent software on your endpoints, you can integrate the Endpoint Security (HX) appliance with Helix. If you connect your Endpoint Security (HX) appliance to Helix, see the Helix Getting Started Guide for information on how to get started with Helix. See also the Trellix System Security Guide for information on Helix's Identity Access Management (IAM) and single sign-on (SSO) authentication.
|
13. Optionally, connect your Endpoint Security (HX) appliance to the Central Management System appliance or to a Network Security appliance. | After you have deployed your Endpoint Security (HX) appliance and installed the agent software on your endpoints, you can integrate the Endpoint Security (HX) appliance with Central Management System and Network Security appliances. For more information, see . Additional information for managing your Endpoint Security (HX) appliance through the Central Management System appliance is provided in the Endpoint Security (HX) System Administration Guide. |