The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Downloading content updates from peer agents

Prev Next

Downloading updates and installation files from peers (agents in the same broadcast domain) reduces the load on ePO - On-prem.

A Trellix Agent can be configured as a peer-to-peer server or client as needed. Configuring a Trellix Agent as a peer-to-peer server enables it to provide updates to others in the broadcast domain when requested. A peer-to-peer server has local disk space allocated to cache updates. By default, the peer-to-peer server caches 512 MB of updates at <agent data folder>\data\mcafeeP2P, but the cache size and location can be customized. You can also configure the policy to purge updates cached in the local disk.

When an agent requires a content update, it tries to discover peer-to-peer servers with the content update in its broadcast domain. On receiving the request, the agents configured as peer-to-peer servers check if they have the requested content and respond back to the agent. The agent requesting the content downloads it from the peer-to-peer server that responds first.

Note

Enable the policy option Enable Peer-to-Peer Communication to allow the client system to discover peer-to-peer servers in the broadcast domain.

The peer-to-peer server uses HTTP to serve content to clients.

If a Trellix Agent can't discover a peer-to-peer server or the content update among its peers in the broadcast domain, it falls back to the repository, as configured in the policy.

Peer-to-peer communication uses port 8082 to discover peer servers and port 8081 to serve peer agents with updates.

Peer-to-peer server purges the content based on the disk quota and purge interval configuration.