The GAM Automatic Deployment tab enables you to configure and deploy Gateway antimalware updates to the attached devices across all domains automatically when you upload the required GAM update file to the Manager. You can schedule the automatic deployment of new GAM updates to the Sensors at any time of your preference using this tab. If you are in an air-gap network, the downloaded GAM update file (.upd) can be copied to the Manager server using a remote machine with internet connection.
When GAM update is scheduled for auto-deployment, any new GAM file imported to the Manager using the Manual Import tab will be pushed to multiple Sensors at once, which includes Sensors in a fail-open pair, Sensors in a stack, and stacked HA Sensors, as per the configuration made. The automatic deployment of GAM files works even when the Manager is not registered with Trellix, or in a proxy-disabled state. If the Managers are in an MDR pair, the deployment of the GAM file will occur as configured on the Primary Manager.
Note
The automatic deployment of GAM updates is not applicable to NTBA or virtual NTBA devices.
Perform the following steps to configure and schedule the automatic deployment of GAM updates:
Navigate to Manager → <Admin Domain Name> → Trellix IPS Protection Status → GAM Automatic Deployment.
The GAM Automatic Deployment tab is displayed.
GAM Automatic Deployment tab.jpg)
In the GAM Automatic Deployment (Manager to Devices) section, configure auto-deployment of the GAM updates by entering the relevant details as given in the table below.
Option
Definition
Automatically Deploy New GAM Updates?
Enabling it activates the automatic deployment option.
By default, it is disabled.
Deployment
The following options are displayed in the drop-down:
Immediate (after download): To deploy the GAM file immediately after it is uploaded on the Manager.
Note
When this option is configured, new GAM updates will be auto-deployed to all Sensors that are attached to the Manager at that point of time. If any Sensor is attached to the Manager after the GAM file has already been imported to the Manager, users need to re-import the file for the new GAM updates to be auto-deployed to those Sensors.
Scheduled: To schedule the deployment of new GAM file. Choosing this provides the When option.
From the When option, customize the interval at which the deployment must occur. The following options are displayed in the drop-down list:
Daily: To deploy new GAM update file daily. Set the time at which the deployment must occur.
Weekly: To deploy new GAM update file weekly. Set the day of the week and time at which the deployment must occur.
Custom: To customize the interval at which the deployment must occur. The following options are displayed:
Every: Set the recurrence of time for the devices to poll the Manager for the deployment. The options available are 1 Hour, 2 Hours, 4 Hours, 8 Hours, and 12 Hours.
Between: Set the time range at which the deployment must occur.
When it is configured, click Save.
When GAM updates have been scheduled for automatic deployment, you can check the deployment status on the User Activities tab under Manager → <Admin Domain Name> → Troubleshooting → Logs after importing the GAM update file (.upd) to the Manager.
.jpg)
If you wish the deploy the GAM updates on a specific device or selected devices, you can do so from Devices → <Admin Domain Name> → Devices → <Device Name> → Deploy Pending Changes page, or from Devices → <Admin Domain Name> → Global → Device Manager page. For more information, refer to the section Update Gateway Anti-Malware Engine manually.