Use the commands in the following sections to upgrade the Endpoint Security (HX) appliance.
Task list for upgrades
Perform the following steps (detailed in the sections that follow) to upgrade the appliance.
Important
Be sure to download the software image files from the configured DTI source server before beginning any installations.
Export your agent certificates
Before upgrading the HX or HXD Series appliance, Trellix recommends that you export (back up) any existing HX certificates (the PKI keys needed to communicate with the agent population).
This is a precautionary step. Ordinarily, software upgrades do not affect the PKI keys, but if a problem occurs during the upgrade that forces you to reinstall the software or reimage the appliance, the backup of the PKI keys is critical. Without these certificates, if you need to reimage the appliance or reinstall the appliance software, you will also need to reinstall all of your agents. However, if you can import the saved agent certificates, you will not need to reinstall the agents.
Go to CLI configuration mode:
hostname > enable hostname # configure terminal
Export the certificates to the file identified by
<fileURL>:hostname (config) # hx pki export file <fileURL> passphrase <passphrase>For example:
hostname (config) # hx pki export file scp://user@host/path/to/file passphrase abc123
Download and install the appliance software image
Go to CLI configuration mode:
hostname > enable hostname # configure terminal
Check for downloads:
hostname (config) # fenet image check hostname (config) # show fenet image status
Download the software image:
hostname (config) # fenet image fetchView the download progress:
hostname (config) # show fenet image statusProgress of latest action taken: action fetch initiated Fri May 26 22:18:28 2017 applying fetch for image hx fetching image-hx_3.5.1 100 % completed fetching requested image 3.5.1 done action fetch completed Fri May 26 22:19:51 2017 fetch-done: OS image downloaded successfully: image-hx_3.5.1.img status
Note
If you have already downloaded the latest software, you may see an error: "Latest image already downloaded and ready to install (error)." To check which images are downloaded, use the following command:
hostname (config) # show fenet image listInstall the downloaded software image:
hostname (config) # fenet image install hostname (config) # show fenet image status
Progress of latest action taken: action install initiated Tue Nov 05 13:04:44 2019 applying install for image hx installing image-hx_4.9.0.img done action install completed Tue Nov 05 13:06:03 2019 install-info: New image installed (Reload required) status
Note
If an upgrade process is interrupted or fails, the appliance software automatically falls back to the currently installed image.
Save your changes:
hostname (config) # write memory
Restart the appliance and accept the EULA
Go to CLI configuration mode:
hostname > enable hostname # configure terminal
Restart the appliance:
hostname (config) # reloadAfter restarting the appliance, the system could display the Trellix End User License Agreement (EULA). Read the EULA. Click Yes if you agree to its terms, and then click Submit. If you do not accept the EULA, the appliance will not function.
After accepting the EULA, the login page is displayed. Wait a few minutes before logging in because database records are undergoing an update in preparation for the upgrade.
Note
You must access the appliance through the serial port if you want to monitor appliance boot activities. You can enter CLI commands through direct keyboard and monitor connection only before the boot loader begins loading the kernel, for example, to post output, and after the boot is completed.
Verify the upgrade
Go to CLI configuration mode:
hostname > enable hostname # configure terminal
Display the version information for the current system image:
hostname (config) # show version
Import your agent certificates
If the Endpoint Security (HX) server upgrade went smoothly, you can skip this step.
If there were any problems upgrading your server that required you to reimage it or to fully reinstall the Endpoint Security (HX) software, import the Endpoint Security (HX) certificates you exported earlier so you do not have to reinstall all of your agents.
Caution
Importing certificates automatically detaches any DMZ server from the Endpoint Security (HX) server. You need to reattach them after the certificates are imported. See the Endpoint Security (HX) Server Deployment Guide.
Go to CLI configuration mode:
hostname > enable hostname # configure terminal
Import the certificates from the file containing your exported certificates, identified by
<fileURL>:hostname (config) # hx pki import file <fileURL> passphrase <passphrase>For example:
hostname (config) # hx pki import file scp://user@host/path/to/file passphrase abc123
(Optional) Reenable HX appliance relay mode
If the Endpoint Security (HX) appliance is in relay mode when it is upgraded, relay mode must be reenabled after the upgrade completes.
Log in to the Endpoint Security (HX) appliance as an administrator.
Enable CLI configuration mode on the Endpoint Security (HX) appliance.
hostname > enable hostname # configure terminal
Review your relay mode settings before proceeding.
hostname (config) # show hx proxyReenable relay mode.
hostname (config) hx rproxy relay <hostname-or-IPaddress>where
<hostname-or-IPaddress>is the host name or IP address of the Endpoint Security (HX) appliance.Save your settings.
hostname (config) # write memory