The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

EX 3600 Hardware Guide

Prev Next

FEI-020

The EX 3600

Compliance Number: FEI-020

Trellix EX 3600 rackmount appliance front perspective photo showing Trellix branding on a black patterned front panel, rack ears visible at sides

The Trellix EX 3600 protects your network from spear phishing attacks that bypass traditional anti-spam technologies. It analyzes every attachment using a signature-less, Multi-Vector Virtual Execution engine that can identify zero-day attacks by detonating attachments in an environment that mimics operating systems, applications, and browsers in their exhaustive list of versions, configurations, and plug-ins.

The EX 3600 provides layers of dynamic malware analysis to protect your network from malicious images, PDFs, and ZIP/RAR/ TNEF archives.

The Front View

Close-up front view of Trellix EX 3600 front panel, showing drive slots, ventilation pattern, and EX 3600 label

Technical front-panel line drawing of EX 3600 showing drive bays, power/reset buttons, and labeled front connectors with a red callout box highlighting a section of the panel

Front-panel LED and button diagram: labeled schematic showing LAN2 LED, LAN1 LED, HDD LED, Power LED, Reset Button, Power Button, Information LED


4

EX 3600 Hardware Administration Guide EX 3600

1 | The EX 3600


1. Information LED

Alerts operator to several states:

Red, solid

An overheat condition has occurred

Red, blinking at 1 Hz

A fan has failed, check for an inoperative fan

Red, blinking at 0.25 Hz

A power supply has failed, check for a non-operational power supply

Red, solid, with Power LED blinking green

Fault detected

Blue and red, blinking at 10 Hz

Recovery mode

Blue, solid

UID has been activated locally to locate the server in a rack environment

Blue, blinking at 1 Hz

UID has been activated using the BMC to locate the server in a rack environment

Blue, blinking at 2 Hz

BMC is resetting

Blue, blinking at 4 Hz

BMC is setting factory defaults

Blue, blinking at 10 Hz with Power LED blinking green

BMC/BIOS firmware is updating

2. LAN 2 LED

Indicates network activity on a LAN when flashing.

3. LAN 1 LED

Indicates network activity on a LAN when flashing.

4. HDD LED

Indicates activity on the hard

1 | The EX 3600


5. Power LED

Steady on

Power on

Blinking at 4 Hz

Checking BIOS/BMC integrity

Blinking at 4Hz and "i" LED is blue

BIOS firmware updating

Two blinks at 4 Hz, one pause 2 Hz and "i" LED is blue

BMC firmware updating

Blinking at 1 Hz and "i" LED is red

Fault detected

6. Reset Button

Reboots the system.

7. Power Button

The main power switch applies or removes primary power from the power supply to the server but maintains standby power. Unplug the appliance before servicing.

8. Drive Device LED

Each drive carrier displays two status LEDs on the front of the carrier.

9. Drive Device LED

Each drive carrier displays two status LEDs on the front of the carrier.

Drive Carrier LED Indicators

The chassis includes externally accessible SAS/SATA drives.

Each drive carrier has two LED indicators: an activity indicator and a status indicator.

1 | The EX 3600


LED Type

Color

Blinking Pattern

Meaning of Blinking Pattern

Activity LED

Blue

Solid On

Idle SAS/NVMe drive installed.

Blinking

I/O activity.

Off

Idle SATA drive installed.

Status LED

Red

Solid On

Failure of drive with RSTe support.

Blinking at 1 Hz

Rebuild drive with RSTe support.

On for five seconds, then off

Power on for drive with RSTe support.

Blinking at 4 Hz

Identify drive with RSTe support.

Blinking with two blinks and one stop at 1 Hz

Hot spare for drive with RSTe support

Green

Solid Green LED

Safe to remove NVMe device.

Amber

Blinking at 1 Hz

Do not remove NVMe device.

1 | The EX 3600


Chassis

Front chassis line drawing of the EX 3600 showing multiple hot‑swappable disk drive carriers across the front

  1. Disk Drive Carrier: Each carrier can house a hot-swappable disk drive. A drive slot map displays the disk slot numbers on top of the appliance.

  2. Handle Release: Press this tab to release the handle. Use the handle to pull the disk drive carrier from the chassis.

The Rear View

Rear view of the EX 3600 back panel with numbered red callouts 1 to 11 indicating ports and components

1) Power Supply 1

7) IPMI Port

2) Power Supply 2

8) ether2/pether2 (RJ45) Live Mode Analysis 2 Port

3) Serial Console Port

9) ether1 (RJ45) Management 1 Port

4) VGA Connector

10) pether3 (RJ45) SMTP interface 3 Port

5) USB 2.0 Port

11) pether4 (RJ45) SMTP interface 4 Port

6) USB 3.2 Port

1 | The EX 3600


Power

  • Power: Connect your power source to this port to provide power to the appliance. The appliance comes with one redundant power supply unit for use if the primary unit fails.

I/O Ports

  • USB 2.0: These ports are USB 2.0 compliant.

  • Serial Console: Connect to this port to manage the appliance from your terminal.

  • Video: Connect a monitor to this port to view the appliance's command-line interface.

  • USB 3.2: These ports are USB 3.2 compliant.

Management Ports

  • ether1 (RJ45): Connect your LAN to this port to enable remote access to the CLI and Web UI. The RJ45 connector is a 10/100/1000BASE-T port.

  • IPMI: Connect for access to out-of-band management functions, including power control, console redirection, and appliance health status. The connector is a 10/100/1000BASE-T port.

Live Mode Analysis Ports

  • ether2/pether2 (RJ45): The RJ45 connector is 10/100/1000BASE-T port.

SMTP Interface Ports

  • pether3 through pether4 (RJ45): The RJ45 connectors support are 10/100/1000BASE-T ports.


EX 3600 Hardware Administration Guide EX 3600

2 | The EX 3600


Deployment

You can deploy the EX 3600 in your network in one of the following ways:

Message Transfer Agent Deployment

When the EX 3600 is in Message Transfer Agent deployment, it serves as an MTA inline with the email traffic flow and can be configured to Block Analysis Mode or Monitor Analysis Mode. In Block Analysis Mode (the default), the EX 3600 will prevent malicious emails from passing through to the mail server. In Monitor Analysis Mode, all email is passed through to the mail server and only copies of the email are analyzed.

The diagram below illustrates the MTA deployment of an EX 3600 in a typical network environment.

Note

For information about configuring the EX 3600 for MTA deployment mode, see the Email Security — Server System Administration Guide for your release.

Network diagram showing MTA deployment of an EX 3600. Diagram includes the Internet cloud connecting to an Edge Router, Firewall, Core Switch, and a LAN segment; a DMZ area contains the EX Series appliance connected via ether1/ether2/ether3 to a switch and shows SMTP traffic to a Mail Server. Components are enclosed in dashed network boundaries and labeled (Internet, Edge Router, Firewall, Core Switch, LAN, DMZ, EX Series, Mail Server).


10

EX 3600 Hardware Administration Guide EX 3600

2 | The EX 3600


Prerequisites

Before connecting the EX 3600 to your network, ensure that your network devices provide 10/100/1000BASE-T Ethernet output.

Cabling

Connect two cables to the EX 3600 appliance’s management ports as follows:

  • ether1: Connect one end of an Ethernet cable to the EX appliance’s ether1 port, and connect the other end to your LAN-facing switch. This port is the management interface.

  • pether3: Connect one end of an Ethernet cable to the EX appliance’s pether3 port, and connect the other end to your MTA or anti-spam device. This connection allows the appliance access to the upstream and downstream of traffic.

  • (For optional URL Dynamic Analysis) pether2: Connect one end of an Ethernet cable to the EX appliance’s pether2 port, and connect the other end to your Internet facing firewall device.

This connection allows the appliance to retrieve objects referred to by suspicious URLs for further analysis. Trellix recommends connecting to an isolated Internet connection to prevent the exposure of the IP address and other information about your main network.

You can monitor more network segments by connecting additional MTA or anti-spam devices to pether3-4.

Bcc: Deployment

When the EX 3600 is in Bcc: mode, it receives a copy of all emails from a Message Transfer Agent (MTA) or anti-spam device for analysis. If the results of the analysis are positive for malicious attachments or URLs, a notification is sent to a configured email alias of “admin CC:” or “Bcc:” members.

The diagram below illustrates the Bcc: deployment of an EX 3600 appliance in a typical network environment.

[IMAGE PLACEHOLDER: Diagram showing Bcc deployment of EX 3600 in a typical network environment with EX appliance, MTA/anti-spam device, firewall, and monitored network segments.]

Important

For information about configuring the EX Appliance for Bcc: mode, see the Email Security — Server System Administration Guide for your release.

2 | The EX 3600

Network diagram showing Internet cloud on the left, edge routers, firewalls, a core switch, a LAN block of workstations on the right, and a DMZ area containing an EX Series appliance connected to MTA/anti-spam and a mail server; labels include pether3, ether1, and (ether2).

Prerequisites

Before connecting the EX appliance to your network, ensure that your network devices provide 10/100/1000BASE-T Ethernet output.

Cabling

  • ether1: Connect one end of an Ethernet cable to the EX appliance’s ether1 port, and connect the other end to your LAN-facing switch. This port is the management interface.

  • pether3: Connect one end of an Ethernet cable to the EX appliance’s pether3 port, and connect the other end to your MTA or anti-spam device. This connection allows the appliance access to the upstream and downstream of traffic.

  • (For optional URL Dynamic Analysis) pether2: Connect one end of an Ethernet cable to the EX appliance’s pether2 port, and connect the other end to your Internet facing firewall device.

This connection allows the appliance to retrieve objects referred to by suspicious URLs for further analysis. Trellix recommends connecting to an isolated Internet connection to prevent the exposure of the IP address and other information about your main network.

You can monitor more network segments by connecting additional MTA or anti-spam devices to pether3-4.

SPAN/ TAP Deployment

When the EX 3600 appliance is in SPAN/TAP deployment, it is connected to a network switch capable of mirroring traffic. The EX


12

EX 3600 Hardware Administration Guide EX 3600

2 | The EX 3600


appliance extracts email from the traffic for analysis.

The diagram below illustrates the SPAN/TAP deployment of an EX appliance in a typical network environment.

ⓘ Important

For information about configuring the EX 3600 appliance for SPAN/TAP mode, see the Email Security — Server System Administration Guide for your release.

Network diagram showing SPAN/TAP deployment. Diagram includes an Internet cloud, edge routers, firewall, core switch, LAN block, a DMZ area containing a switch, mail server and an EX Series appliance with labeled ports (ether1, pether2, pether3). The diagram shows dashed network boundaries and connections between devices.

Prerequisites

Before connecting the EX appliance to your network, ensure that your network devices provide 10/100/1000BASE-T Ethernet output.

Cabling

  • ether1: Connect one end of an Ethernet cable to the EX appliance’s ether1 port, and connect the other end to your LAN-facing switch. This port is the management interface.

  • pether3: Connect one end of an Ethernet cable to the EX appliance’s pether3 port, and connect the other end to your switch. This connection allows the appliance access to the upstream and downstream of traffic.

  • (For optional URL Dynamic Analysis) pether2: Connect one end of an Ethernet cable to the EX appliance’s pether2 port, and connect the other end to your Internet-facing firewall device.


EX 3600 Hardware Administration Guide EX 3600

13

2 | The EX 3600


This connection allows the appliance to retrieve objects referred to by suspicious URLs for further analysis. Trellix recommends connecting to an isolated Internet connection to prevent the exposure of the IP address and other information about your main network.


14

EX 3600 Hardware Administration Guide EX 3600

3 | The EX 3600


Installation

This chapter provides information about the site requirements of your installation location.

Before You Begin

Follow the steps in this section before you install the appliance.

Before Opening the Box

  • Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.

  • Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.

  • If there appears to be damage to the box, file a damage claim with the carrier who delivered it.

Unpacking the Appliance

Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.

Ensure your box contains:

  • The correct appliance model

  • An accessory kit

  • Online Documents Portal Referral

  • A rail kit

Installation Site Guidelines

Follow these guidelines when you select an installation site:

  • Leave enough clearance in front of the rack for its door to open completely without obstruction.

  • Avoid environments that produce heat, electrical noise, and electromagnetic fields.

  • Only install the appliance in a restricted access location such as a service closet or dedicated equipment room.

  • Make sure the location is properly ventilated.


EX 3600 Hardware Administration Guide EX 360015

3 | The EX 3600


  • Make sure there is sufficient space for air flow.

Rack Precautions

Trellix recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements.

Consider the following before installing your appliance in the rack:

  • Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.

  • In a single-rack installation, stabilizers should be attached to the rack.

  • In a multiple-rack installation, the racks should be coupled together to increase their stability.

  • Always make sure the rack is stable before extending a component from the rack.

  • Only extend one component from the rack at a time—extending two or more simultaneously may cause the rack to become unstable.

  • Ensure your rack meets the safety requirements of UL 60950-1.

Blue exclamation warning icon Warning

STABILITY HAZARD: The rack may tip over causing serious personal injury. To prevent injury:

  • Before extending the rack to the installation position, read the installation instructions.

  • Do not put any load on the slide-rail mounted equipment when the rails are extended in the installation position.

  • Do not leave the slide-rail mounted equipment with the rails extended in the installation position.

Server Precautions

Trellix recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.

Review the following before installing the appliance in the rack:

  • Determine the placement of each component in the rack.

  • Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.

  • Install the heaviest component at the bottom of the rack first, then move up.

3 | The EX 3600


  • Allow hot-swappable power supply units, disk drives, and transceivers to cool before handling them.

  • Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.

  • Keep all of the rack's doors and panels closed when you are not servicing the components.

Rack-Mounting Precautions

Consider the following safety precautions when you install the appliance in the rack:

  • Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.

  • Use an electrostatic wrist guard when handling the appliance.

  • At least two technicians should be involved to install the appliance safely.

  • Trellix recommends only individuals with rack-mounting experience should install the appliance.

  • Install the appliance in an environment compatible with the manufacturer's maximum recommended ambient temperature (TMRA) for each component in your rack.

Power Requirements

The EX 3600 uses a 400 W power supply unit with an input rating of 100-240VAC / 6.0 - 3.0A | 200-240VDC / 3.4- 3.2A at 50-60 Hz.

Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.

Ventilation Requirements

Ventilation and optimal location are essential to the proper operation of the EX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.

The EX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.

Cabling Requirements

The EX Series appliance ships with the following cables:

  • (2) 6 ft AC power cord, SVT, 60oC, 3x18AWG (0.824mm2)

  • (1) 6 ft null modem DB9 female serial cable

3 | The EX 3600


You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.

Rack Installation

This section explains how to install your appliance in a standard 19‑inch wide rack with the equipment provided. Because various rack units are available, the assembly procedure may differ slightly from the following instructions. Refer to the installation instructions that came with your rack.

Installing the Inner Rails on the Appliance

  1. Starting with either rail (each works for both sides of the appliance), pull the inner rail from the outer rail until it is fully extended.

  2. Push the arrow-shaped rail-release lever on the inner rail in the direction of the arrow and slide the inner rail out until it is detached from the outer rail.

  3. Align the notches of the inner rail with the tabs on the side of the appliance.

  4. While firmly pressing the inner rail against the appliance, slide it in the direction of the tabs until you hear a click.

  5. Repeat steps 1—4 with the other inner rail on the other side of the appliance.

Installing the Outer Rails on the Rack

  1. Insert the front end of an outer rail (“Front Bracket” is engraved on the front end) into the front rack column at the desired height. A metal tab will slide and lock onto the column automatically.

  2. Extend the rail until it reaches the rear rack column.

  3. Insert the back end into the rack column at the same height chosen in step 1.

  4. Repeat steps 1—3 with the other outer rail on the other side of the rack.

Mounting the Appliance on the Rack

  1. Align the rear of the inner rails installed on the appliance with the front channels of the outer rails installed on the rack.

  2. Fully slide the appliance into the rack. The inner and outer rails will lock together automatically.

  3. (Optional) Further secure the appliance to the rack by using the captive screws installed on the ears of the appliance.

3 | The EX 3600


Attaching Cables to the Appliance

  1. Connect the EX Series appliance to one or more network devices using the cables appropriate to the deployment of your choice.

  2. Connect the power cable or cables to the power port or ports on the back of the appliance.


EX 3600 Hardware Administration Guide EX 3600 19

Replacements

This chapter provides information about returning or replacing defective parts of your EX appliance.

Return Process

If you believe you have a defective part or system, you must first contact Trellix Technical Support, who will validate the claim. If the part or system is defective, Technical Support will initiate a Return Materials Authorization (RMA) and guide you through the process. For more information, visit https://www.trellix.com/en-us/support.html.

Removing and Replacing a Disk Drive

Perform the following steps to remove and replace a disk drive:

  1. Remove the bezel at the front of the appliance by sliding the release tab to the right and pulling the bezel away from the chassis.

  2. Locate the disk drive carrier that contains the failed disk drive. The carrier should have a blinking amber LED.

  3. Unlock the disk drive handle by sliding the blue tab to the left.

  4. Push the maroon button on the right to release the latch handle.

  5. Pull the handle to slide the disk drive from its slot.

  6. Insert the new disk drive carrier into the available slot and push in until it clicks.

Removing and Replacing a Power Supply Unit

Perform the following steps to remove and replace a power supply unit (PSU):

  1. At the rear of the appliance, remove the power cable from the failed PSU.

  2. While gripping the handle to the left of the power port and pressing the release lever to the right of it, pull out the failed PSU.

  3. Insert the replacement PSU in the open slot and slide it in until it clicks into place.

  4. Attach the power cable to the new power supply.

Removing and Replacing a Cooling Fan

Perform the following steps to remove and replace a failed fan:

4 | The EX 3600


  1. Turn off the appliance.

  2. Using a Phillips screwdriver, remove the four screws securing the middle section of the appliance’s top cover.

  3. Remove the middle section of the top cover.

  4. Remove the fan from the appliance by squeezing the plastic release tab and pulling.

  5. Insert the new fan into the empty fan bracket, ensuring it is oriented the same way as the others. You will hear a click when it is secured.

  6. Replace the top cover and secure it with screws.


EX 3600 Hardware Administration Guide EX 3600

21

5 | The EX 3600


Appendices

This section includes all the appliance hardware specifications.

Appendix 1: System Specifications

The table below provides the technical specifications for the Trellix EX 3600 .

Component

EX 3600 Specifications

Form Factor

1U chassis

Weight of Appliance

32.3 lbs

Weight of Packaged Appliance

39.3 lbs

Dimensions (W x D x H)

17.2" (437 mm) X 19.98" (507 mm) X 1.7" (43 mm)

Enclosure

1 RU, fits 19-inch Rack

Management Interfaces

(1) 10/100/1000BASE-T Ports

Live Mode Analysis Ports

(1) 10/100/1000BASE-T Ports

SMTP Interface Ports

(2) 10/100/1000BASE-T Ports

Memory

64 GB (2 x 32 GB)

Drive Capacity

(4) 4 TB HDD, RAID 10, 3.5 inch, FRU

AC Power Supply

Redundant (1+1), FRU, 400W with Input 1100-240VAC / 6.0 – 3.0A | 200-240VDC / 3.4- 3.2A, 50-60 Hz IEC60320- C14 inlet

Maximum Power Consumption

300 W


22

EX 3600 Hardware Administration Guide EX 3600

5

| The EX 3600


Component

EX 3600 Specifications

Operating Temperature

5° to 35° C (41°F - 95°F)

Maximum Thermal Dissipation

1024 BTU/hr

Relative Humidity

Operational standard: 90% RH
Non-operational standard: 95% RH

Note:

The appliance box can work under 90% RH, and can also be stored (powered off) at 95% RH for a short period of time. It is not recommended to store any electronics in high humidity places for an extended period of time.

Appendix 2: Product Compliance Information

The Compliance Number for EX 3600 appliance is FEI-020.

The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the EX 3600 appliance.

EMC

LVD/Safety

Environmental/RoHS

EN 55032:2015/A11:2020,

EN 55035:2017/A11:2020,

EN 61000-3-2:2014,

EN 61000-3-3:2013

BS EN 55032:2015

BS EN55035:2017

AS/NZS CISPR 32:2015

KS C 9832

KS C 9835

VCCI-CISPR 32:2016

FCC CFR 47 Part 15

CAN ICES-003

EN IEC 62368-1:2018+A11:2020

UL 62368-1

CSA 22.2 No. 62368-1

CNS 15598-1

IS 13252 (Part-1)/IEC 60950-1

Directive 2011/65/EU

CNS 15663


EX 3600 Hardware Administration Guide EX 360023

5 | The EX 3600


EMC

LVD/Safety

Environmental/RoHS

CNS 15936

*All current amendments

6 | The EX 3600


Technical Support

For technical support, contact Trellix through the Support portal:

https://www.trellix.com/en-us/support.html

Documentation

Documentation for all Trellix products is available on the Trellix Documentation Portal:

https://docs.trellix.com/


EX 3600 Hardware Administration Guide EX 3600

25

Copyright © 2026 Musarubra US LLC.

Trellix and FireEye are the trademarks or registered trademarks of Musarubra US LLC, FireEye Security Holdings US LLC, and their affiliates in the US and /or other countries. Other names and brands are the property of these companies or may be claimed as the property of others.

Trellix logo — stylized Trellix wordmark in black with a small multicolored blue/green accent mark

The EX 3600

Compliance Number: FEI-020

Trellix EX 3600 rackmount appliance front perspective photo showing Trellix branding on a black patterned front panel, rack ears visible at sides

The Trellix EX 3600 protects your network from spear phishing attacks that bypass traditional anti-spam technologies. It analyzes every attachment using a signature-less, Multi-Vector Virtual Execution engine that can identify zero-day attacks by detonating attachments in an environment that mimics operating systems, applications, and browsers in their exhaustive list of versions, configurations, and plug-ins.

The EX 3600 provides layers of dynamic malware analysis to protect your network from malicious images, PDFs, and ZIP/RAR/ TNEF archives.

The Front View

Close-up front view of Trellix EX 3600 front panel, showing drive slots, ventilation pattern, and EX 3600 label

Technical front-panel line drawing of EX 3600 showing drive bays, power/reset buttons, and labeled front connectors with a red callout box highlighting a section of the panel

Front-panel LED and button diagram: labeled schematic showing LAN2 LED, LAN1 LED, HDD LED, Power LED, Reset Button, Power Button, Information LED


4

EX 3600 Hardware Administration Guide EX 3600

1 | The EX 3600


1. Information LED

Alerts operator to several states:

Red, solid

An overheat condition has occurred

Red, blinking at 1 Hz

A fan has failed, check for an inoperative fan

Red, blinking at 0.25 Hz

A power supply has failed, check for a non-operational power supply

Red, solid, with Power LED blinking green

Fault detected

Blue and red, blinking at 10 Hz

Recovery mode

Blue, solid

UID has been activated locally to locate the server in a rack environment

Blue, blinking at 1 Hz

UID has been activated using the BMC to locate the server in a rack environment

Blue, blinking at 2 Hz

BMC is resetting

Blue, blinking at 4 Hz

BMC is setting factory defaults

Blue, blinking at 10 Hz with Power LED blinking green

BMC/BIOS firmware is updating

2. LAN 2 LED

Indicates network activity on a LAN when flashing.

3. LAN 1 LED

Indicates network activity on a LAN when flashing.

4. HDD LED

Indicates activity on the hard

1 | The EX 3600


5. Power LED

Steady on

Power on

Blinking at 4 Hz

Checking BIOS/BMC integrity

Blinking at 4Hz and "i" LED is blue

BIOS firmware updating

Two blinks at 4 Hz, one pause 2 Hz and "i" LED is blue

BMC firmware updating

Blinking at 1 Hz and "i" LED is red

Fault detected

6. Reset Button

Reboots the system.

7. Power Button

The main power switch applies or removes primary power from the power supply to the server but maintains standby power. Unplug the appliance before servicing.

8. Drive Device LED

Each drive carrier displays two status LEDs on the front of the carrier.

9. Drive Device LED

Each drive carrier displays two status LEDs on the front of the carrier.

Drive Carrier LED Indicators

The chassis includes externally accessible SAS/SATA drives.

Each drive carrier has two LED indicators: an activity indicator and a status indicator.

1 | The EX 3600


LED Type

Color

Blinking Pattern

Meaning of Blinking Pattern

Activity LED

Blue

Solid On

Idle SAS/NVMe drive installed.

Blinking

I/O activity.

Off

Idle SATA drive installed.

Status LED

Red

Solid On

Failure of drive with RSTe support.

Blinking at 1 Hz

Rebuild drive with RSTe support.

On for five seconds, then off

Power on for drive with RSTe support.

Blinking at 4 Hz

Identify drive with RSTe support.

Blinking with two blinks and one stop at 1 Hz

Hot spare for drive with RSTe support

Green

Solid Green LED

Safe to remove NVMe device.

Amber

Blinking at 1 Hz

Do not remove NVMe device.

1 | The EX 3600


Chassis

Front chassis line drawing of the EX 3600 showing multiple hot‑swappable disk drive carriers across the front

  1. Disk Drive Carrier: Each carrier can house a hot-swappable disk drive. A drive slot map displays the disk slot numbers on top of the appliance.

  2. Handle Release: Press this tab to release the handle. Use the handle to pull the disk drive carrier from the chassis.

The Rear View

Rear view of the EX 3600 back panel with numbered red callouts 1 to 11 indicating ports and components

1) Power Supply 1

7) IPMI Port

2) Power Supply 2

8) ether2/pether2 (RJ45) Live Mode Analysis 2 Port

3) Serial Console Port

9) ether1 (RJ45) Management 1 Port

4) VGA Connector

10) pether3 (RJ45) SMTP interface 3 Port

5) USB 2.0 Port

11) pether4 (RJ45) SMTP interface 4 Port

6) USB 3.2 Port

1 | The EX 3600


Power

  • Power: Connect your power source to this port to provide power to the appliance. The appliance comes with one redundant power supply unit for use if the primary unit fails.

I/O Ports

  • USB 2.0: These ports are USB 2.0 compliant.

  • Serial Console: Connect to this port to manage the appliance from your terminal.

  • Video: Connect a monitor to this port to view the appliance's command-line interface.

  • USB 3.2: These ports are USB 3.2 compliant.

Management Ports

  • ether1 (RJ45): Connect your LAN to this port to enable remote access to the CLI and Web UI. The RJ45 connector is a 10/100/1000BASE-T port.

  • IPMI: Connect for access to out-of-band management functions, including power control, console redirection, and appliance health status. The connector is a 10/100/1000BASE-T port.

Live Mode Analysis Ports

  • ether2/pether2 (RJ45): The RJ45 connector is 10/100/1000BASE-T port.

SMTP Interface Ports

  • pether3 through pether4 (RJ45): The RJ45 connectors support are 10/100/1000BASE-T ports.


EX 3600 Hardware Administration Guide EX 3600

2 | The EX 3600


Deployment

You can deploy the EX 3600 in your network in one of the following ways:

Message Transfer Agent Deployment

When the EX 3600 is in Message Transfer Agent deployment, it serves as an MTA inline with the email traffic flow and can be configured to Block Analysis Mode or Monitor Analysis Mode. In Block Analysis Mode (the default), the EX 3600 will prevent malicious emails from passing through to the mail server. In Monitor Analysis Mode, all email is passed through to the mail server and only copies of the email are analyzed.

The diagram below illustrates the MTA deployment of an EX 3600 in a typical network environment.

Note

For information about configuring the EX 3600 for MTA deployment mode, see the Email Security — Server System Administration Guide for your release.

Network diagram showing MTA deployment of an EX 3600. Diagram includes the Internet cloud connecting to an Edge Router, Firewall, Core Switch, and a LAN segment; a DMZ area contains the EX Series appliance connected via ether1/ether2/ether3 to a switch and shows SMTP traffic to a Mail Server. Components are enclosed in dashed network boundaries and labeled (Internet, Edge Router, Firewall, Core Switch, LAN, DMZ, EX Series, Mail Server).


10

EX 3600 Hardware Administration Guide EX 3600

2 | The EX 3600


Prerequisites

Before connecting the EX 3600 to your network, ensure that your network devices provide 10/100/1000BASE-T Ethernet output.

Cabling

Connect two cables to the EX 3600 appliance’s management ports as follows:

  • ether1: Connect one end of an Ethernet cable to the EX appliance’s ether1 port, and connect the other end to your LAN-facing switch. This port is the management interface.

  • pether3: Connect one end of an Ethernet cable to the EX appliance’s pether3 port, and connect the other end to your MTA or anti-spam device. This connection allows the appliance access to the upstream and downstream of traffic.

  • (For optional URL Dynamic Analysis) pether2: Connect one end of an Ethernet cable to the EX appliance’s pether2 port, and connect the other end to your Internet facing firewall device.

This connection allows the appliance to retrieve objects referred to by suspicious URLs for further analysis. Trellix recommends connecting to an isolated Internet connection to prevent the exposure of the IP address and other information about your main network.

You can monitor more network segments by connecting additional MTA or anti-spam devices to pether3-4.

Bcc: Deployment

When the EX 3600 is in Bcc: mode, it receives a copy of all emails from a Message Transfer Agent (MTA) or anti-spam device for analysis. If the results of the analysis are positive for malicious attachments or URLs, a notification is sent to a configured email alias of “admin CC:” or “Bcc:” members.

The diagram below illustrates the Bcc: deployment of an EX 3600 appliance in a typical network environment.

[IMAGE PLACEHOLDER: Diagram showing Bcc deployment of EX 3600 in a typical network environment with EX appliance, MTA/anti-spam device, firewall, and monitored network segments.]

Important

For information about configuring the EX Appliance for Bcc: mode, see the Email Security — Server System Administration Guide for your release.

2 | The EX 3600

Network diagram showing Internet cloud on the left, edge routers, firewalls, a core switch, a LAN block of workstations on the right, and a DMZ area containing an EX Series appliance connected to MTA/anti-spam and a mail server; labels include pether3, ether1, and (ether2).

Prerequisites

Before connecting the EX appliance to your network, ensure that your network devices provide 10/100/1000BASE-T Ethernet output.

Cabling

  • ether1: Connect one end of an Ethernet cable to the EX appliance’s ether1 port, and connect the other end to your LAN-facing switch. This port is the management interface.

  • pether3: Connect one end of an Ethernet cable to the EX appliance’s pether3 port, and connect the other end to your MTA or anti-spam device. This connection allows the appliance access to the upstream and downstream of traffic.

  • (For optional URL Dynamic Analysis) pether2: Connect one end of an Ethernet cable to the EX appliance’s pether2 port, and connect the other end to your Internet facing firewall device.

This connection allows the appliance to retrieve objects referred to by suspicious URLs for further analysis. Trellix recommends connecting to an isolated Internet connection to prevent the exposure of the IP address and other information about your main network.

You can monitor more network segments by connecting additional MTA or anti-spam devices to pether3-4.

SPAN/ TAP Deployment

When the EX 3600 appliance is in SPAN/TAP deployment, it is connected to a network switch capable of mirroring traffic. The EX


12

EX 3600 Hardware Administration Guide EX 3600

2 | The EX 3600


appliance extracts email from the traffic for analysis.

The diagram below illustrates the SPAN/TAP deployment of an EX appliance in a typical network environment.

ⓘ Important

For information about configuring the EX 3600 appliance for SPAN/TAP mode, see the Email Security — Server System Administration Guide for your release.

Network diagram showing SPAN/TAP deployment. Diagram includes an Internet cloud, edge routers, firewall, core switch, LAN block, a DMZ area containing a switch, mail server and an EX Series appliance with labeled ports (ether1, pether2, pether3). The diagram shows dashed network boundaries and connections between devices.

Prerequisites

Before connecting the EX appliance to your network, ensure that your network devices provide 10/100/1000BASE-T Ethernet output.

Cabling

  • ether1: Connect one end of an Ethernet cable to the EX appliance’s ether1 port, and connect the other end to your LAN-facing switch. This port is the management interface.

  • pether3: Connect one end of an Ethernet cable to the EX appliance’s pether3 port, and connect the other end to your switch. This connection allows the appliance access to the upstream and downstream of traffic.

  • (For optional URL Dynamic Analysis) pether2: Connect one end of an Ethernet cable to the EX appliance’s pether2 port, and connect the other end to your Internet-facing firewall device.


EX 3600 Hardware Administration Guide EX 3600

13

2 | The EX 3600


This connection allows the appliance to retrieve objects referred to by suspicious URLs for further analysis. Trellix recommends connecting to an isolated Internet connection to prevent the exposure of the IP address and other information about your main network.


14

EX 3600 Hardware Administration Guide EX 3600

3 | The EX 3600


Installation

This chapter provides information about the site requirements of your installation location.

Before You Begin

Follow the steps in this section before you install the appliance.

Before Opening the Box

  • Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.

  • Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.

  • If there appears to be damage to the box, file a damage claim with the carrier who delivered it.

Unpacking the Appliance

Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.

Ensure your box contains:

  • The correct appliance model

  • An accessory kit

  • Online Documents Portal Referral

  • A rail kit

Installation Site Guidelines

Follow these guidelines when you select an installation site:

  • Leave enough clearance in front of the rack for its door to open completely without obstruction.

  • Avoid environments that produce heat, electrical noise, and electromagnetic fields.

  • Only install the appliance in a restricted access location such as a service closet or dedicated equipment room.

  • Make sure the location is properly ventilated.


EX 3600 Hardware Administration Guide EX 360015

3 | The EX 3600


  • Make sure there is sufficient space for air flow.

Rack Precautions

Trellix recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements.

Consider the following before installing your appliance in the rack:

  • Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.

  • In a single-rack installation, stabilizers should be attached to the rack.

  • In a multiple-rack installation, the racks should be coupled together to increase their stability.

  • Always make sure the rack is stable before extending a component from the rack.

  • Only extend one component from the rack at a time—extending two or more simultaneously may cause the rack to become unstable.

  • Ensure your rack meets the safety requirements of UL 60950-1.

Blue exclamation warning icon Warning

STABILITY HAZARD: The rack may tip over causing serious personal injury. To prevent injury:

  • Before extending the rack to the installation position, read the installation instructions.

  • Do not put any load on the slide-rail mounted equipment when the rails are extended in the installation position.

  • Do not leave the slide-rail mounted equipment with the rails extended in the installation position.

Server Precautions

Trellix recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.

Review the following before installing the appliance in the rack:

  • Determine the placement of each component in the rack.

  • Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.

  • Install the heaviest component at the bottom of the rack first, then move up.

3 | The EX 3600


  • Allow hot-swappable power supply units, disk drives, and transceivers to cool before handling them.

  • Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.

  • Keep all of the rack's doors and panels closed when you are not servicing the components.

Rack-Mounting Precautions

Consider the following safety precautions when you install the appliance in the rack:

  • Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.

  • Use an electrostatic wrist guard when handling the appliance.

  • At least two technicians should be involved to install the appliance safely.

  • Trellix recommends only individuals with rack-mounting experience should install the appliance.

  • Install the appliance in an environment compatible with the manufacturer's maximum recommended ambient temperature (TMRA) for each component in your rack.

Power Requirements

The EX 3600 uses a 400 W power supply unit with an input rating of 100-240VAC / 6.0 - 3.0A | 200-240VDC / 3.4- 3.2A at 50-60 Hz.

Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.

Ventilation Requirements

Ventilation and optimal location are essential to the proper operation of the EX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.

The EX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.

Cabling Requirements

The EX Series appliance ships with the following cables:

  • (2) 6 ft AC power cord, SVT, 60oC, 3x18AWG (0.824mm2)

  • (1) 6 ft null modem DB9 female serial cable

3 | The EX 3600


You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.

Rack Installation

This section explains how to install your appliance in a standard 19‑inch wide rack with the equipment provided. Because various rack units are available, the assembly procedure may differ slightly from the following instructions. Refer to the installation instructions that came with your rack.

Installing the Inner Rails on the Appliance

  1. Starting with either rail (each works for both sides of the appliance), pull the inner rail from the outer rail until it is fully extended.

  2. Push the arrow-shaped rail-release lever on the inner rail in the direction of the arrow and slide the inner rail out until it is detached from the outer rail.

  3. Align the notches of the inner rail with the tabs on the side of the appliance.

  4. While firmly pressing the inner rail against the appliance, slide it in the direction of the tabs until you hear a click.

  5. Repeat steps 1—4 with the other inner rail on the other side of the appliance.

Installing the Outer Rails on the Rack

  1. Insert the front end of an outer rail (“Front Bracket” is engraved on the front end) into the front rack column at the desired height. A metal tab will slide and lock onto the column automatically.

  2. Extend the rail until it reaches the rear rack column.

  3. Insert the back end into the rack column at the same height chosen in step 1.

  4. Repeat steps 1—3 with the other outer rail on the other side of the rack.

Mounting the Appliance on the Rack

  1. Align the rear of the inner rails installed on the appliance with the front channels of the outer rails installed on the rack.

  2. Fully slide the appliance into the rack. The inner and outer rails will lock together automatically.

  3. (Optional) Further secure the appliance to the rack by using the captive screws installed on the ears of the appliance.

3 | The EX 3600


Attaching Cables to the Appliance

  1. Connect the EX Series appliance to one or more network devices using the cables appropriate to the deployment of your choice.

  2. Connect the power cable or cables to the power port or ports on the back of the appliance.


EX 3600 Hardware Administration Guide EX 3600 19

Replacements

This chapter provides information about returning or replacing defective parts of your EX appliance.

Return Process

If you believe you have a defective part or system, you must first contact Trellix Technical Support, who will validate the claim. If the part or system is defective, Technical Support will initiate a Return Materials Authorization (RMA) and guide you through the process. For more information, visit https://www.trellix.com/en-us/support.html.

Removing and Replacing a Disk Drive

Perform the following steps to remove and replace a disk drive:

  1. Remove the bezel at the front of the appliance by sliding the release tab to the right and pulling the bezel away from the chassis.

  2. Locate the disk drive carrier that contains the failed disk drive. The carrier should have a blinking amber LED.

  3. Unlock the disk drive handle by sliding the blue tab to the left.

  4. Push the maroon button on the right to release the latch handle.

  5. Pull the handle to slide the disk drive from its slot.

  6. Insert the new disk drive carrier into the available slot and push in until it clicks.

Removing and Replacing a Power Supply Unit

Perform the following steps to remove and replace a power supply unit (PSU):

  1. At the rear of the appliance, remove the power cable from the failed PSU.

  2. While gripping the handle to the left of the power port and pressing the release lever to the right of it, pull out the failed PSU.

  3. Insert the replacement PSU in the open slot and slide it in until it clicks into place.

  4. Attach the power cable to the new power supply.

Removing and Replacing a Cooling Fan

Perform the following steps to remove and replace a failed fan:

4 | The EX 3600


  1. Turn off the appliance.

  2. Using a Phillips screwdriver, remove the four screws securing the middle section of the appliance’s top cover.

  3. Remove the middle section of the top cover.

  4. Remove the fan from the appliance by squeezing the plastic release tab and pulling.

  5. Insert the new fan into the empty fan bracket, ensuring it is oriented the same way as the others. You will hear a click when it is secured.

  6. Replace the top cover and secure it with screws.


EX 3600 Hardware Administration Guide EX 3600

21

5 | The EX 3600


Appendices

This section includes all the appliance hardware specifications.

Appendix 1: System Specifications

The table below provides the technical specifications for the Trellix EX 3600 .

Component

EX 3600 Specifications

Form Factor

1U chassis

Weight of Appliance

32.3 lbs

Weight of Packaged Appliance

39.3 lbs

Dimensions (W x D x H)

17.2" (437 mm) X 19.98" (507 mm) X 1.7" (43 mm)

Enclosure

1 RU, fits 19-inch Rack

Management Interfaces

(1) 10/100/1000BASE-T Ports

Live Mode Analysis Ports

(1) 10/100/1000BASE-T Ports

SMTP Interface Ports

(2) 10/100/1000BASE-T Ports

Memory

64 GB (2 x 32 GB)

Drive Capacity

(4) 4 TB HDD, RAID 10, 3.5 inch, FRU

AC Power Supply

Redundant (1+1), FRU, 400W with Input 1100-240VAC / 6.0 – 3.0A | 200-240VDC / 3.4- 3.2A, 50-60 Hz IEC60320- C14 inlet

Maximum Power Consumption

300 W


22

EX 3600 Hardware Administration Guide EX 3600

5

| The EX 3600


Component

EX 3600 Specifications

Operating Temperature

5° to 35° C (41°F - 95°F)

Maximum Thermal Dissipation

1024 BTU/hr

Relative Humidity

Operational standard: 90% RH
Non-operational standard: 95% RH

Note:

The appliance box can work under 90% RH, and can also be stored (powered off) at 95% RH for a short period of time. It is not recommended to store any electronics in high humidity places for an extended period of time.

Appendix 2: Product Compliance Information

The Compliance Number for EX 3600 appliance is FEI-020.

The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the EX 3600 appliance.

EMC

LVD/Safety

Environmental/RoHS

EN 55032:2015/A11:2020,

EN 55035:2017/A11:2020,

EN 61000-3-2:2014,

EN 61000-3-3:2013

BS EN 55032:2015

BS EN55035:2017

AS/NZS CISPR 32:2015

KS C 9832

KS C 9835

VCCI-CISPR 32:2016

FCC CFR 47 Part 15

CAN ICES-003
CNS 15936

EN IEC 62368-1:2018+A11:2020

UL 62368-1

CSA 22.2 No. 62368-1

CNS 15598-1

IS 13252 (Part-1)/IEC 60950-1

Directive 2011/65/EU

CNS 15663