Prerequisite:
You must have a freshly installed Manager to be configured as the Secondary Manager.
The Pair Creation action enables you to configure both the Primary and Secondary Managers used for MDR.
Initial MDR Configuration
First, you must configure MDR separately on both the Primary and Secondary Managers.
Steps:
Select Manager → <Admin Domain Name> → Setup → MDR.
Note
The Manager supports a maximum of three IP addresses during MDR configuration. The Manager assumes that all the IP addresses are bound to the same host name.
Note
The Manager supports one public IPv6 address per NIC. This means that there should be only one IPv6 address for the IPv6 stack supported by your operating system.
MDR Pair Creation page.png)
Fill in the following fields:
Option definitionsOption
Definition
Role of this Manager
Select Primary to use this Manager as the active Manager, or Secondary to use this Manager as the standby.
Use Out-of-Band (OOB) Manager-to-Manager Communication?
Yes to use separate interfaces for Manager-Manager and Manager-Sensor communication.
No to use the same interface for Manager-Manager and Manager-Sensor communication.
IP Address of the Other Manager (for Manager-to-Manager Communication)
This option appears if you selected the option Yes in Use Out-of-Band (OOB) Manager-to-Manager Communication?. Enter the IP address (IPv4 address for IPv4 to IPv4 communication; IPv6 address for IPv6 to IPv6 communication) of the other Manager that you want to use for Manager-Manager communication.
Note
If you set Use Out-of-Band (OOB) Manager-to-Manager Communication? to Yes in the Primary Manager, then set this option as Yes in your Secondary Manager as well. A mismatch in this option setting between the Primary and Secondary Manager pair will result in an MDR configuration failure.
IP Address of the Other Manager (for Manager-to-Sensor Communication)
Enter the IP address (IPv4 address for IPv4 to IPv4 communication; IPv6 address for IPv6 to IPv6 communication) of the other Manager that is used for communication with the Sensor.
MDR Pair Shared Secret
The same shared secret key must be entered on both Managers for MDR creation to be successful. Enter a minimum of eight characters and use no special characters.
Confirm MDR Pair Shared Secret
Re-enter the same shared secret key.
Downtime Before Switchover
Enter the downtime in minutes before the switch to the Secondary Manager occurs. Downtime before switchover should be between 1-10 minutes. This field is disabled if the Role of this Manager of Manager is set to Secondary.
Copy certificate
Select this option to Copy the SSL certificate for web server authentication from Primary Manager to Secondary Manager in the MDR pair.
Note
The Copy certificate option is available only in the Primary Manager.
Note
The Copy certificate option does not impact working of the Manager MDR.
Click Finish to confirm your changes.
Note
When you click Finish and your peer Manager's MDR settings are not yet configured, then Trellix IPS displays a warning to remind you to configure the peer Manager MDR settings.
You can configure either IPv4 address or IPv6 address or both for Manager-Sensor communication as given in the following scenarios:
If a Sensor is connected to Manager over an IPv4 network, or you want to add a Sensor from the IPv4 network to the Manager, you need to enter the IPv4 address of the peer Manager.
If a Sensor is connected to Manager over an IPv6 network, or you want to add a Sensor in the IPv6 network to the Manager, you need to enter the IPv6 address of the peer Manager.
If there are Sensors configured in Manager over both IPv4 and IPv6 networks, you need to configure both IPv4 address and IPv6 address of the peer Manager.
Note
While configuring the IP Address of the Other Manager (for Manager-to-Sensor Communication), make sure that the operating system support both IPv4 and IPv6 stacks.
When Use Out-of-Band (OOB) Manager-to-Manager Communication is set to No, IP Address of the Other Manager (for Manager-to-Sensor Communication) is used for both Manager-Manager and Manager-Sensor communication. This is applicable to both IPv4 and IPv6 addresses.
When Use Out-of-Band (OOB) Manager-to-Manager Communication is set to Yes, IP Address of the Other Manager (for Manager-to-Sensor Communication) is used only for Manager-Sensor communication. This is applicable to both IPv4 and IPv6 addresses.
Important
You need to use the IP Address of the Other Manager (for Manager-to-Sensor Communication) while establishing trust between the Sensor and Manager. Ensure that your peer Manager is configured to use the same IP address as selected from the Dedicated Interface list during the Peer Manager installation. If misconfigured, Trellix IPSgenerates an error message to prompt you to enter the correct IP address. For more information on Sensor communication Interface, see Trellix Intrusion Prevention System Installation Guide.