Before installation, ensure that you complete the following tasks:
- The Windows server, on which the Manager software will be installed, should be configured and ready to be placed online (Not required for Linux based Manager).
- You must have administrator privileges for the Windows based Manager server (Not required for Linux based Manager).
- This Windows server should be dedicated, hardened for security, and placed on its own subnet. This server should not be used for programs like instant messaging or other non-secure Internet functions (Not required for Linux based Manager).
- Make sure your hardware requirements meet at least the minimum requirements.
- Ensure the proper static IP address has been assigned to the Manager server. For the Manager server, Trellix strongly recommends assigning a static IP using DHCP for IP assignment.
- If applicable, configure name resolution for the Manager.
- Ensure that all parties have agreed to the solution design, including the location and mode of all Trellix IPS Sensors, the use of sub-interfaces or interface groups, and if and how the Manager will be connected to the production network.
- Obtain the required Trellix IPS Registration key, license file, and grant number.
- Accumulate the required number of wires and (supported) GBICs, SFPs, or XFPs. Ensure these are approved hardware from Trellix or a supported vendor. Ensure that the required number of Trellix IPS dongles, which ship with the Sensors, are available.
- Crossover cables will be required for 10/100 or 10/100/1000 monitoring ports if they are directly connected to a firewall, router, or end node. Otherwise, standard patch cables are required for the Fast Ethernet ports.
- If applicable, identify the ports to be mirrored, and someone who has the knowledge and rights to mirror them.
- Allocate the proper static IP addresses for the Sensor. For the Sensors, you cannot assign IPs using DHCP.
- Identify hosts that may cause false positives, for example, HTTP cache servers, DNS servers, mail relays, SNMP managers, and vulnerability scanners.