Review the items in this section before you begin your upgrade.
User Role—You must have admin access to upgrade the Endpoint Security (HX) appliance.
Back Up the Appliance—Before performing the upgrade, back up your appliance. See Database backup and restore for more information.
Licenses—Before performing upgrades, confirm that the following licenses are installed and valid:
CONTENT_UPDATES license (needed for security content updates)
FIREEYE_SUPPORT license (needed for software updates)
Note
See License management for more information. If you need to obtain the licenses, send an email to key_request@fireeye.com.
End-User License Agreement (EULA)—The upgrade could require acceptance of the End User License Agreement (EULA). If it is required, the appliance will not function until the EULA is accepted. To review the EULA before the upgrade, download a copy from the Trellix Customer Support Portal at
http://csportal.fireeye.com.Minimum Version to Upgrade—Refer to the Release Notes to determine whether you can upgrade directly from the current release to the new release.
IPMI and BIOS Versions—The latest IPMI and BIOS firmware should be running. See IPMI and BIOS firmware updates .
Note
The HX 4502 model requires IPMI 3.11 and BIOS 1.9.
Download Time—Downloading the operating system software requires about 45 minutes when upgrading from the CLI.
Certificates—Any existing Endpoint Security (HX) certificates (the PKI keys used to communicate with the agent population) must be backed up before you begin the upgrade. Otherwise, if you reset or reinstall the Endpoint Security (HX) appliance, you will need to reinstall all of the agents. See Export your agent certificates.
Quiesce Mode — Enable quiesce mode before upgrading your Endpoint Security server. See Enabling and disabling Endpoint Security server quiesce mode . Disable quiesce mode when the upgrade is complete.
Enterprise Search Requests — Be sure to stop all Enterprise Search queries before you upgrade an Endpoint Security (HX) server. Running Enterprise Search queries at the same time as a server upgrade can impact the performance of the upgrade.
Network Proxy Configuration—If you have an intelligent proxy appliance that is required for access to the Internet, ensure that it does not perform secure sockets layer (SSL) terminations with certificate replacement. An example of such a proxy is the Blue Coat ProxySG appliance. If the proxy does perform SSL terminations, then you must whitelist the Central Management System appliance, the Trellix Dynamic Threat Intelligence (DTI) network server (
staticcloud.fireeye.com), or the Content Distribution Network (CDN) server (cloud.fireeye.comordownload.fireeye.com) in the proxy configuration.For integration with third-party products, such as ArcSight, Juniper STRM, Blue Coat ProxySG, or Q1 Lab QRadar, contact Trellix Technical Support. Refer to the vendor documentation for proxy configuration information.