Review these important requirements carefully before you proceed with the upgrade.
This document provides information on how to upgrade from Network Security Platform versions 9.1 and 9.2 to Trellix Intrusion Prevention System version 10.1. See the corresponding upgrade guide and release notes to first upgrade to the minimum required version for 10.1, if you are on a version other than the ones mentioned here. Consider that your current version is in the 8.1 release train but your current version is not supported for upgrade to 10.1. See the latest Network Security Platform 8.1 Upgrade Guide and upgrade to 8.1.5.175 version, upgrade to 9.1.5.63 before you upgrade to 10.1. For 8.1 version software images contact Trellix Technical Support.
The minimum required software versions to upgrade to 10.1 are provided in the following sections:
After you upgrade the Linux based Central Manager or the Manager to 10.1, you will be prompted to restart the server.
Following are the ports that are used for Sensor-to-Manager communication in release 10.1. Before you begin the 10.1 upgrade process, make sure that your firewall rules are updated accordingly to open up the required ports. This applies to a firewall that resides between the Sensor and the Manager (including a local firewall on the Manager server).
Port #
Protocol
Description
Direction of communication
4167 (high ports) (source port on the Manager for IPv4 communication)
4166 (source port on the Manager for IPv6 communication)
UDP
Default SNMPv3 (command channel)
Manager<-->Sensor
8500 (destination port on the Sensor)
UDP
Default SNMPv3 (command channel)
Sensor<-->Manager
8501
TCP
Proprietary (install channel using SHA256 2048-bit self-signed certificate)
Sensor<-->Manager
8502
TCP
Proprietary (alert channel/control channel using SHA256 2048-bit self-signed certificate)
Sensor<-->Manager
8503
TCP
Proprietary (packet log channel using SHA256 2048-bit self-signed certificate)
Sensor<-->Manager
8504
TCP
Proprietary (file transfer channel)
Sensor<-->Manager
8506
TCP
Proprietary (install channel for SHA256 2048-bit CA-signed certificates)
Sensor<-->Manager
8507
TCP
Proprietary (alert channel/control channel using SHA256 2048-bit CA-signed certificates)
Sensor<-->Manager
8508
TCP
Proprietary (packet log channel using SHA256 2048-bit CA-signed certificates)
Sensor<-->Manager
8509
TCP
Proprietary (Bulk file transfer channel using SHA256 2048-bit CA-signed certificates)
Sensor<-->Manager
8510
TCP
Proprietary (Bulk file transfer channel using SHA256 2048-bit self-signed certificates)
Sensor<-->Manager
443
TCP
HTTPS
client-->Manager
80
TCP
Web-based user interface
client-->Manager
22
TCP
SSH
Remote console access