The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

ePO - Connection failure

Prev Next

If there is a connection failure between the Manager and the ePO - On-prem server, perform the following steps for troubleshooting.

In the Manager:

Steps:

  1. Ensure that the provided configurations such as IP address, port numbers, user name, and the password to the ePO server are correct.

  2. Ping or try to access ePO server directly from the Manager server. If it is not accessible, check the firewall configuration and follow other regular network troubleshooting steps.

  3. Ensure that the required permissions are given to the configured user name. To isolate the permission issue, use global administrator user name or password for testing the connection. If the connection is successful with global administrator credentials, then it could be a problem with configured user name.

  4. Check the ems.log files for any errors:

  5. Manager uses the following URLs. Try accessing them from the Manager server through a browser:https://EPO_SERVER_IP:8443/remote/ISExtension.HostForensicsCommand.do?command=getHostDetails&ip=[specify_IP]

    Check the logs files.

    Following denotes is a successful "TestConnection":

    011-11-22 15:09:51,500 INFO [ajp-127.0.0.1-8009-3] iv.common.HttpClient.ApacheGetImpl - doGET(), succesfully made the request to http client, url is https://172.16.101.37/remote/ISExtension.HostForensicsCommand.do?command=getHostDetails&ip=127.0.0.1&orion.user.security.token=tpc5pvsNVHxo3fiS

    The following denotes an error in connection:

    ems.log.3:2011-11-17 12:15:10,914 ERROR [ajp-127.0.0.1-8009-5] iv.common.HttpClient.ApacheGetImpl - doGET:Error while doing the http get function for the url https://172.17.94.80/remote/ISExtension.HostForensicsCommand.do?command=getHostDetails&ip=127.0.0.1&orion.user.security.token=kSffjTChbZRcE0IJ the error isjava.net.SocketTimeoutException: Read timed out

    ems.log.3:2011-11-17 12:48:21,435 ERROR [ajp-127.0.0.1-8009-4] iv.common.HttpClient.ApacheGetImpl - doGET:Error while doing the http get function for the url

In the ePO

Steps:

  1. Ensure that the ePO server has the latest Trellix IPS Extension installed.

    Note

    The Trellix IPS Extension file needs to be installed on the ePO server to help establish communication between Trellix Intrusion Prevention System and ePO.

  2. Ensure that the required permissions are given to the configured username. Check if user has sufficient permission to access Trellix IPS Extension.

    • In Menu → User Management → Users → desired User, note down "Permissions Sets".

    • In Menu → User Management → Permission sets, select the permission that is assigned to this user. Check if Trellix Intrusion Prevention System has view and change settings.

  3. To test the connection to the Manager server, manually run the NSP:Dashboard Data Pull Task. If connection fails, ping or try to access the Manager server directly from the ePO server. If connection fails, check the firewall and follow regular network troubleshooting steps.

  4. Check orion.log file for any error messages at <ePO_Install_Dir>\Server\Logs. .

Note

If test connection is carried out from child admin domain, create test connection for parent admin domain by following above troubleshooting steps.