Before you begin
You must have a freshly installed Manager to be configured as the Secondary Manager.
Initial MDR Configuration
First, you must configure MDR separately on both the Primary and Secondary Managers.
Task
-
Select
Manager → <Admin Domain Name> → Setup → MDR.
Note
The Manager supports a maximum of three IP addresses during MDR configuration. The Manager assumes that all the IP addresses are bound to the same host name.
Note
The Manager supports one public IPv6 address per NIC. This means that there should be only one IPv6 address for the IPv6 stack supported by your operating system.
MDR Pair Creation page .png)
-
Fill in the following fields:
Option definitions Option Definition Role of this Manager Select Primary to use this Manager as the active Manager, or Secondary to use this Manager as the standby. Use Out-of-Band (OOB) Manager-to-Manager Communication? - Yes to use separate interfaces for Manager-Manager and Manager-Sensor communication.
- No to use the same interface for Manager-Manager and Manager-Sensor communication.
IP Address of the Other Manager (for Manager-to-Manager Communication) This option appears if you selected the option Yes in Use Out-of-Band (OOB) Manager-to-Manager Communication?. Enter the IP address of the other Manager that you want to use for Manager-Manager communication. Note
If you set Use Out-of-Band (OOB) Manager-to-Manager Communication? to Yes in the Primary Manager, then set this option as Yes in your Secondary Manager as well. A mismatch in this option setting between the Primary and Secondary Manager pair will result in an MDR configuration failure.
IP Address of the Other Manager (for Manager-to-Sensor Communication) Enter the IP address of the other Manager that is used for communication with the Sensor. MDR Pair Shared Secret The same shared secret key must be entered on both Managers for MDR creation to be successful. Enter a minimum of eight characters and use no special characters. Confirm MDR Pair Shared Secret Re-enter the same shared secret key. Downtime Before Switchover Enter the downtime in minutes before the switch to the Secondary Manager occurs. Downtime before switchover should be between 1-10 minutes. This field is disabled if the Role of this Manager of Manager is set to Secondary. Copy certificate Select this option to Copy the SSL certificate for web server authentication from Primary Manager to Secondary Manager in the MDR pair. Note
The Copy certificate option is available only in the Primary Manager.
Note
The Copy certificate option does not impact working of the Manager MDR.
-
Click
Finish to confirm your changes.
Note
When you click Finish and your peer Manager's MDR settings are not yet configured, then Trellix IPS displays a warning to remind you to configure the peer Manager MDR settings.
You can configure either IPv4 address or IPv6 address or both for Manager-Sensor communication as given in the following scenarios:- If a Sensor is connected to Manager over an IPv4 network, or you want to add a Sensor from the IPv4 network to the Manager, you need to enter the IPv4 address of the peer Manager.
- If a Sensor is connected to Manager over an IPv6 network, or you want to add a Sensor in the IPv6 network to the Manager, you need to enter the IPv6 address of the peer Manager.
- If there are Sensors configured in Manager over both IPv4 and IPv6 networks, you need to configure both
IPv4 address and
IPv6 address of the peer Manager.
Note
While configuring the IP Address of the Other Manager (for Manager-to-Sensor Communication), make sure that the operating system support both IPv4 and IPv6 stacks.
- When Use Out-of-Band (OOB) Manager-to-Manager Communication is set to No, IP Address of the Other Manager (for Manager-to-Sensor Communication) is used for both Manager-Manager and Manager-Sensor communication.
- When
Use Out-of-Band (OOB) Manager-to-Manager Communication is set to Yes,
IP Address of the Other Manager (for Manager-to-Sensor Communication) is used only for Manager-Sensor communication.
Important
You need to use the IP Address of the Other Manager (for Manager-to-Sensor Communication) while establishing trust between the Sensor and Manager. Ensure that your peer Manager is configured to use the same IP address as selected from the Dedicated Interface list during the Peer Manager installation. If misconfigured, Trellix IPS generates an error message to prompt you to enter the correct IP address. For more information on Sensor communication Interface, see Trellix Intrusion Prevention System Installation Guide.