The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Designing your infrastructure

Prev Next

For deploying Trellix DXL brokers, enable service zones so the closest TIE server handles the requests. Enable Trellix DXL Client affinity so TIE Reputation Cache servers work efficiently. See KB89775 for details.

For deploying TIE servers, follow these guidelines to determine the number of servers you need.

  • For fault tolerance, always deploy at least two TIE server instances, one Primary, and one Secondary. This minimum server topology supports up to 1000 requests per second in a dedicated infrastructure.

  • Deploy collocated TIE Secondary servers to increase capacity as required. Deploying additional Secondary servers (7 secondary instances, maximum) ensures that the network infrastructure meets multiplied replication bandwidth requirements.

    Note

    You can experience throughput reduction when adding remote Secondary servers to your topology.

  • Change the operation mode of a Primary server to a Write-Only Primary to maximize replication potential for deploying multiple Secondaries.

  • Add a Reporting Secondary server to concentrate load from Trellix ePO - On-prem reporting and only enable search services on it.

  • Rely on Reputation Cache servers when remote bandwidth isn't enough to replicate the full reputations database, or to increase reputation throughput of reused files and certificates.

For more details, see Sizing and performance topic from Trellix Threat Intelligence Exchange (TIE) Installation Guide.