The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Upgrading the appliance using the CLI

Prev Next

Use the commands in the following sections to upgrade the Endpoint Security (HX) appliance.

Task list for upgrades

Perform the following steps (detailed in the sections that follow) to upgrade the appliance.

Important

Be sure to download the software image files from the configured DTI source server before beginning any installations.

Export your agent certificates

Before upgrading the HX or HXD Series appliance, Trellix recommends that you export (back up) any existing HX certificates (the PKI keys needed to communicate with the agent population).

This is a precautionary step. Ordinarily, software upgrades do not affect the PKI keys, but if a problem occurs during the upgrade that forces you to reinstall the software or reimage the appliance, the backup of the PKI keys is critical. Without these certificates, if you need to reimage the appliance or reinstall the appliance software, you will also need to reinstall all of your agents. However, if you can import the saved agent certificates, you will not need to reinstall the agents.

To export your certificates:
  1. Go to CLI configuration mode:

    hostname > enable
    hostname # configure terminal
  2. Export the certificates to the file identified by <fileURL>:

    hostname (config) # hx pki export file <fileURL> passphrase <passphrase>

    For example:

    hostname (config) # hx pki export file scp://user@host/path/to/file passphrase abc123

Download and install the appliance software image

To download and install the software image:
  1. Go to CLI configuration mode:

    hostname > enable
    hostname # configure terminal
  2. Check for downloads:

    hostname (config) # fenet image check
    hostname (config) # show fenet image status
  3. Download the software image:

    hostname (config) # fenet image fetch
  4. View the download progress:

    hostname (config) # show fenet image status
    Progress of latest action taken:
    action fetch initiated Fri May 26 22:18:28 2017
    applying fetch for image hx
    fetching image-hx_3.5.1 100 % completed
    fetching requested image 3.5.1 done
    action fetch completed Fri May 26 22:19:51 2017
    fetch-done: OS image downloaded successfully: image-hx_3.5.1.img status

    Note

    If you have already downloaded the latest software, you may see an error: "Latest image already downloaded and ready to install (error)." To check which images are downloaded, use the following command:

    hostname (config) # show fenet image list

  5. Install the downloaded software image:

    hostname (config) # fenet image install
    hostname (config) # show fenet image status
    Progress of latest action taken:
       action install initiated                  Tue Nov 05 13:04:44 2019
       applying install for image                hx
       installing image-hx_4.9.0.img             done
       action install completed                  Tue Nov 05 13:06:03 2019 
       install-info: New image installed         (Reload required) status

    Note

    If an upgrade process is interrupted or fails, the appliance software automatically falls back to the currently installed image.

  6. Save your changes:

    hostname (config) # write memory

Restart the appliance and accept the EULA

To restart the appliance and accept the EULA:
  1. Go to CLI configuration mode:

    hostname > enable
    hostname # configure terminal
  2. Restart the appliance:

    hostname (config) # reload
  3. After restarting the appliance, the system could display the Trellix End User License Agreement (EULA). Read the EULA. Click Yes if you agree to its terms, and then click Submit. If you do not accept the EULA, the appliance will not function.

    After accepting the EULA, the login page is displayed. Wait a few minutes before logging in because database records are undergoing an update in preparation for the upgrade.

    Note

    You must access the appliance through the serial port if you want to monitor appliance boot activities. You can enter CLI commands through direct keyboard and monitor connection only before the boot loader begins loading the kernel, for example, to post output, and after the boot is completed.

Verify the upgrade

To verify the upgrade:
  1. Go to CLI configuration mode:

    hostname > enable
    hostname # configure terminal
  2. Display the version information for the current system image:

    hostname (config) # show version

Import your agent certificates

If the Endpoint Security (HX) server upgrade went smoothly, you can skip this step.

If there were any problems upgrading your server that required you to reimage it or to fully reinstall the Endpoint Security (HX) software, import the Endpoint Security (HX) certificates you exported earlier so you do not have to reinstall all of your agents.

Caution

Importing certificates automatically detaches any DMZ server from the Endpoint Security (HX) server. You need to reattach them after the certificates are imported. See the Endpoint Security (HX) Server Deployment Guide.

To import your certificates:
  1. Go to CLI configuration mode:

    hostname > enable
    hostname # configure terminal
  2. Import the certificates from the file containing your exported certificates, identified by <fileURL>:

    hostname (config) # hx pki import file <fileURL> passphrase <passphrase>

    For example:

    hostname (config) # hx pki import file scp://user@host/path/to/file passphrase abc123

(Optional) Reenable HX appliance relay mode

If the Endpoint Security (HX) appliance is in relay mode when it is upgraded, relay mode must be reenabled after the upgrade completes.

  1. Log in to the Endpoint Security (HX) appliance as an administrator.

  2. Enable CLI configuration mode on the Endpoint Security (HX) appliance.

    hostname > enable
    hostname # configure terminal
  3. Review your relay mode settings before proceeding.

    hostname (config) # show hx proxy
  4. Reenable relay mode.

    hostname (config) hx rproxy relay <hostname-or-IPaddress>

    where <hostname-or-IPaddress> is the host name or IP address of the Endpoint Security (HX) appliance.

  5. Save your settings.

    hostname (config) # write memory