The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Setting up a cold standby server

Prev Next

If you restore your backups regularly to a second Endpoint Security (HX) server, you can use the second server as a cold standby server. A cold standby server is an inactive server you can quickly activate if your primary server fails. The standby serer must be set up, installed, and configured so that agents can start polling immediately after it comes online.

Caution

Be sure that you restore the backup of a DMZ server only to another DMZ server. If you restore the backup of a DMZ server to an Endpoint Security (HX) server, you will lose critical data, including agent data, task information, alert information, and Web UI data.

Likewise, be sure you restore the backup of an Endpoint Security (HX) server only to another Endpoint Security (HX) server and not to a DMZ server.

Backups restored to cold standby servers should be full backups (<type> is full). This ensures that all data, certificates, configuration data, and artifacts can be restored. However, there will still be some data loss if the primary Endpoint Security (HX) server fails.

  • All data collected and any changes made since the last backup was created will be lost.

  • All appliance services are shut down during a restore process, so any alerts occurring during the restore process will be lost.

This sections describes:

Prerequisites
  • Admin access

Setting up the cold standby server

To set up your cold standby server:
  1. Set up and install the standby Endpoint Security (HX) server the same way you set up your primary Endpoint Security (HX) server. See Initial configuration .

    Note

    Do not add the standby server to the server address list while the primary server is running. You run the risk of losing data if agents poll and report data to the standby server. The primary server will be unaware of anything reported to the standby server because Endpoint Security (HX) servers cannot be attached to each other.

  2. Regularly back up your primary server.

    • Backups should be full backups to ensure that all data, certificates, configuration data, and artifacts are backed up.

    • Backups should specify a URL name or usb for the destination. Local backups will not be available if the primary server fails.

    Backups can be performed manually (see Backing up the database ) or be automated (see Scheduling automatic backups ).

  3. Regularly restore the backup file on the standby server. See Restoring the database from a backup file .

Switching to the cold standby server

When your primary server fails, you need to switch to the cold standby server as quickly and seamlessly as possible.

To switch to your cold standby server:
  1. Restore the latest backup file to the standby server. See Restoring the database from a backup file .

  2. Verify that the primary server is shut down.

  3. Detach any DMZ server you have attached to the primary server. See "Attaching and Detaching DMZ Servers" in the Endpoint Security (HX) Server Deployment Guide.

  4. Change the IP address of the standby server to the IP address of the primary server.

    If you use a DNS address for your Endpoint Security (HX) server, this is a simple process. See Server Appliance addressing .

  5. Reattach any DMZ server to the standby server. See "Attaching and Detaching DMZ Servers" in the Endpoint Security (HX) Server Deployment Guide.