If your organization has used an on-premises Endpoint Security (HX) appliance and you are moving to a cloud Endpoint Security (HX) server, you need to migrate the agents that have provisioned with the on-premises appliance to the cloud server. This migration is critical to ensuring that your agents continue to communicate with the server.
You may also need to migrate some appliance settings from the on-premises appliance to the cloud server.
Note
Trellix does not recommend that you simply change the domain name server (DNS) record of the on-premises appliance to point to the cloud server. While this can be done, the migration cut-over time may be uncertain due to long delays between DNS cache updates. This will make it difficult to diagnose migration problems.
A cloud Endpoint Security (HX) server is an instance of the Endpoint Security (HX) system image deployed in the Amazon Web Services (AWS) cloud. All agent communication is with the cloud Endpoint Security (HX) server. The cloud Endpoint Security (HX) administrator uses the cloud Endpoint Security (HX) server to configure the cloud Endpoint Security (HX) environment.
Admin access.
The on-premises and cloud Endpoint Security (HX) appliances must both be master appliances. When you run the
show hx ecosystemcommand on each appliance, the output must include this line:Appliance Role: master.
Migration steps
Follow these steps to migrate your agents from an on-premises Endpoint Security (HX) appliance to a cloud Endpoint Security (HX) appliance.
Task | Instructions |
|---|---|
1. Remediate all contained hosts in your environment and stop containing them. | Resolve all containment issues and uncontain all host endpoints before performing any further migration steps. Contained host endpoints are blocked from communicating with other host endpoints and can only communicate with the Endpoint Security (HX) and HXD appliances that manage them. Consequently, any contained hosts managed by your on-premises Endpoint Security (HX) appliance will not be able to communicate with the cloud Endpoint Security (HX) appliance if you migrate your agents without resolving the issues that required the hosts to be contained. See "Containing Host Endpoints" in the Endpoint Security (HX) Server User Guide for more information about containment. |
2. Confirm connectivity between the on-premises and cloud Endpoint Security (HX) appliances. | The on-premises and cloud Endpoint Security (HX) series appliances must be able to connect to each other. Do not attempt the migration if connectivity between the on-premises and cloud appliances cannot be established. See Testing Connectivity Between the On-Premises and Cloud HX Appliances . |
3. Verify that the on-premises and cloud appliances are running the same versions of Endpoint Security (HX) software. | Verify that the versions of the Endpoint Security (HX) software installed on your on-premises and cloud Endpoint Security (HX) appliances are the same. For each appliance, use the procedure described in Identifying the HX series software version on an appliance to identify the installed Endpoint Security (HX) software versions. If the on-premises and cloud appliances are not running the same versions of Endpoint Security (HX) software, upgrade the appliance running the older version of the Endpoint Security (HX) software. See Upgrading the Trellix software |
4. Enable quiesce mode for the on-premises Endpoint Security (HX) appliance. | The on-premises appliance must be put into quiesce mode. See Enabling and disabling HX appliance quiesce mode . |
5. Wait at least two hours. | After putting the on-premises Endpoint Security (HX) appliance into quiesce mode, wait at least two hours to ensure that all of the agents have completed or aborted any ongoing jobs to the appliance. |
6. Collect information and CA certificates for the cloud Endpoint Security (HX) ecosystem. | Collect information about the cloud Endpoint Security (HX) server IP address, the server address list (SAL), and the CA certificates in your cloud Endpoint Security (HX) ecosystem. See Collecting cloud HX information and CA certificates . You will need to restore these later in this procedure. |
7. Detach any on-premises HXD (DMZ) appliances or convert the HXD appliances to TCP relays. | If all of your host endpoints can communicate directly with the on-premises Endpoint Security (HX) appliance, detach your on-premises HXD appliances. See Detaching on-premises HXD appliances . If this is not possible, convert your on-premises HXD appliances into TCP relays to the on-premises Endpoint Security (HX) appliance. See Converting an HXD appliance Into a TCP relay . Trellix recommends that you detach your on-premises HXD appliances, rather than use them as TCP relays. |
8. Create the appliance database backup of the on-premises Endpoint Security (HX) appliance. | Create the appliance database backup of the on-premises Endpoint Security (HX) appliance. If you use the CLI, use the See Backing up the database . |
9. Create the full backup of the cloud Endpoint Security (HX) appliance in the cloud Endpoint Security (HX) ecosystem. | Create a full backup of the cloud Endpoint Security (HX) appliance in your cloud Endpoint Security (HX) ecosystem. This will ensure your system can be restored to its original state if a problem in the migration should occur. See Backing up the database . |
10. Download the appliance database backup of the on-premises Endpoint Security (HX) appliance. | Download the appliance database backup of the on-premises Endpoint Security (HX) appliance you created in Step 8. See Downloading backup files . |
11. Upload the appliance database backup of the on-premises Endpoint Security (HX) appliance into the cloud Endpoint Security (HX) appliance. | Upload the appliance database backup of the on-premises Endpoint Security (HX) appliance onto the cloud Endpoint Security (HX) appliance using either the Web UI or the CLI. Trellix recommends using the CLI |
12. Export the PKI certificates from the on-premises appliance and import them into the cloud Endpoint Security (HX) appliance. | For instructions on how to export and import the PKI certificates, see the CLI Command Reference. |
13. Configure users and user role (AAA) settings on the cloud Endpoint Security (HX) appliance. | Referring to the users and user role (AAA) settings on the on-premises appliance, configure the AAA settings on the cloud Endpoint Security (HX) appliance. For instructions on how to create user accounts and assign user roles, see "Authorization" in the System Security Guide. |
14. If required, import the configuration settings into the cloud Endpoint Security (HX) appliance. | Do a side-by-side comparison of the configuration settings of the on-premises Endpoint Security (HX) appliance and the cloud Endpoint Security (HX) appliance, and then port the configuration settings that you wish into the cloud Endpoint Security (HX) appliance. |
15. Set up the server address list in the cloud Endpoint Security (HX) ecosystem | Using the cloud Endpoint Security (HX) Web UI, set up the server address list for the cloud Endpoint Security (HX) ecosystem. See Setting up the server address list for the cloud HX ecosystem . |
16. Verify that quiesce mode is disabled on the cloud Endpoint Security (HX) appliance. | Check the status of the quiesce mode on the cloud Endpoint Security (HX) appliance, see Reviewing quiesce mode status . To disable the quiesce mode, see Disabling quiesce mode . |
17. Convert the on-premises Endpoint Security (HX) appliance to a TCP relay for the cloud Endpoint Security (HX) appliance | Convert the on-premises Endpoint Security (HX) appliance into a TCP relay for the cloud Endpoint Security (HX) appliance. See Converting the on-premises HX appliance into a TCP relay . |
When you complete these steps, the agents will initially connect to the on-premises Endpoint Security (HX) appliance, but will be relayed to the cloud Endpoint Security (HX) appliance.
When all agents are connected directly to the cloud Endpoint Security (HX) appliance, the on-premises Endpoint Security (HX) appliance will no longer be needed and can be shut down.