The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling compliance with managed appliances

Prev Next

If your Central Management System is FIPS 140-3 or CC-NDcPP compliant and runs in compliance mode, it can manage appliances that are also compliant. For CC-NDcPP certification, the managed Endpoint Security (HX) appliances must run release 10.0.0. For FIPS 140-3 certification, the managed Endpoint Security (HX) appliance must run release 5.0.3 or later.

  • For server-initiated connections, you must add the managed applianceʼs RSA host key.

  • For client-initiated connections, an RSA host key is not needed.

If your Central Management System is not compliant, it can manage appliances that are FIPS 140-3 or CC-NDcPP compliant.

  • For server-initiated connections, an RSA host key is not needed.

  • For client-initiated connections, you must add the RSA host key of the Central Management System.

For more information about server-initiated connections, see the “Configuring Secure Shell (SSH) authentication” section of the Central Management System Administration Guide.

For more information about client-initiated connections, see the “Configuring Secure Shell (SSH) authentication” section of the System Administration Guide for your appliance.