The steps presented are for installation of the Manager/ Central Manager software on Windows server. The installation procedure prompts you to submit program and icon locations, including the location and access information of your database. Read each step carefully before proceeding to the next step.
Notes:
Ensure that the prerequisites have been met and your target server has been prepared before commencing installation.
You can exit the setup program by clicking Cancel in the setup wizard. Upon cancellation, all temporary setup files are removed, restoring your server to its same state prior to installation.
After you complete a step, click Next; click Previous to go one step back in the installation process.
Unless specified during installation, Trellix Intrusion Prevention System Manager is installed by default.
The Installation Wizard creates the default folders based on the Manager Type you are installing. For example, for a first-time installation of Trellix Intrusion Prevention System Manager, the default location is
<System_Drive>\Program Files\Trellix\IPS Manager\App. For Trellix Intrusion Prevention System Central Manager, it is<System_Drive>\Program Files\Trellix\IPS Central Manager\App. Similarly, the Wizard creates default folders for the database as well. For the sake of explanation, this section mentions only the folder paths for Trellix IPS Manager unless it is necessary to mention the path for Trellix IPS Central Manager.Before you begin to install, make sure the Windows Regional and Language Options are configured accordingly. For example, if you are installing it on Windows Server 2019 Standard or Datacenter Edition, Japanese Operating System (64 bit) (Full Installation), ensure that the Windows Regional and Language Options are configured for Japanese.
When you install the Manager for the first time, it is automatically integrated with Trellix Global Threat Intelligence to send your alert, general setup, and feature usage data to Trellix for optimized protection. If you do not wish to send these data, you should disable the integration with Trellix Global Threat Intelligence. However, note that to be able to query Trellix GTI IP Reputation for information on the source or target host of an attack, you need to send at least your alert data summary to Trellix. For details, see Trellix Intrusion Prevention System Integration Guide.
If you plan to create a new installation of the Manager in a system that currently has the Manager installed, follow these steps:
Uninstall the Manager.
Go to the installation directory.
Delete all the previous Manager default folders.
Once the folders are removed, restart the system and then continue with the Manager installation.
Steps:
Log on to your Windows server as Administrator and close all open programs.
Run the Manager executable file that you downloaded from the Trellix Download Server.
The Installation Wizard starts with an introduction screen. See also the Download the Manager/Central Manager executable.
.jpg)
Confirm your acknowledgment of the License Agreement by selecting I accept the terms of the License Agreement.
.png)
From the Manager Type drop-down list, select IPS Manager or IPS Central Manager.
For an upgrade, IPS Manager or IPS Central Manager is displayed accordingly, which you cannot change.
.jpg)
Note
Once installed, the Central Manager cannot be converted to Manager or vice versa.
Choose a folder where you want to install the Manager software.
For a first-time installation, the default location is
<System_Drive>\Program Files\Trellix\IPS Manager\App. For an upgrade, it is the same location as that of the earlier version.Restore Default Folder: Resets the installation folder to the default location.
Choose: Browse to a different location.
Caution
Installing the Manager software on a network-mapped drive may result in improper installation.
Note
The Manager software cannot be installed to a directory path containing special characters such as a comma (,), equal sign (=), or pound sign (#).
.jpg)
Choose a location for the Manager shortcut icon:
On the Start Menu
On the Desktop
On the Quick Launch Bar
Create Icons for All Users
You can include or remove multiple options by selecting the relevant check boxes.
.jpg)
Type the password for your default user.
Use a combination of alphabets [both uppercase (A-Z) and lowercase (a-z)], numbers [0-9] and/or, special characters like "~ ` ! @ # $ % - * _ + [ ] : ; , ( ) ? { }".
Do not use null or empty characters.
Note
Trellixstrongly recommendsthat the password must be at least 8 characters in length and must contain a combination of numbers, characters, and special characters. For more information on the password control, see section Configure password complexity settings in Trellix Intrusion Prevention System Product Guide.
.jpg)
Set the following:
Database Type is displayed as MariaDB.
You must use only the MariaDB bundled with the Manager installation file. Provide the database connection information as follows:
Database Name: Type a name for your database. It is recommended you keep the default entry of lf intact.
The database name can be a combination of alphabets [both uppercase (A-Z) and lowercase (a-z)], numbers [0-9] and/or, special characters like dollar and underscore [$ _].
Database User: Type a user name for database-Manager communication; this account name is used by the Manager. This account enables communication between the database and the Manager. When typing a user name, observe the following rules:
- The database user name can be a combination of alphabets [both uppercase (A-Z) and lowercase (a-z)], numbers [0-9] and/or, special characters like "~ ` ! @ # $ % - * _ + [ ] : ; , ( ) ? { }".
- The first character must be a letter.
- Do not use null or empty characters.
- Do not use more than 16 characters.
Database Password: Type a password for the database-Manager communication account. This password relates to the Database User account.
- The database password can be a combination of alphabets [both uppercase (A-Z) and lowercase (a-z)], numbers [0-9] and/or, special characters like "~ ` ! @ # $ % - * _ + [ ] : ; , ( ) ? { }".
- Do not use null or empty characters.
Important
This password is not the root password for database management; you will set the root password in a subsequent step.
MariaDB Installation Directory: Type or browse to the absolute location of your selected Manager database. For a first-time installation, the default location is:
<System_Drive>\Program Files\Trellix\IPS Manager\MariaDB. You can type or browse to a location different from the default. However, the database must be on the same server as the Manager.For upgrades, the default location is the previous database installation directory. The user names and user permissions will be same as before.
.jpg)
Click Next.
Note
If you are creating a new database, New MariaDB Installation message appears asking to confirm that you really want to create a new database. Click Continue to continue with the installation.
.jpg)
Type the root password for your database. If this is the initial installation, type a root password and then type it again to confirm.
The MariaDB root password is required for root access configuration privileges for your database. Use a combination of alphabets [both uppercase (A-Z) and lowercase (a-z)], numbers [0-9] and/or, special characters like "~ ` ! @ # $ % - * _ + [ ] : ; , ( ) ? { }".
Do not use null or empty characters.
Tip
For security reasons, you can set a MariaDB root password that is different from the Database Password that you set in a previous step.
.jpg)
Choose the folder in want you wish to install the Solr database.
The Manager uses Apache Solr for quick retrieval of data. Solr is an open-source search platform from the Apache Lucene project. The Manager makes use of Solr to retrieve data to be displayed in the Manager Dashboard and Analysis tabs.
For a first‑time installation, the default location is
<System_Drive>\Program Files\Trellix\IPS Manager\Solr.The following options are available in the wizard:
Restore Default Folder: Resets the installation folder to the default location.
Choose: Click to browse to a different location.
.jpg)
Solr is used by the Manager to enhance database access. This helps in faster data refresh in the Manager dashboard and monitors.
Verify that you have at least 20 GB of free space before you install Solr.
Note
The Solr installation directory screen will not be displayed during the Central Manager installation.
Click Next.
Note
11.1 Manager installation is supported only on 64-bit OS. If you try installing it in a 32-bit OS, a warning message will be displayed. Click Ok on the warning message to exit the Manager installation wizard.
.jpg)
Enter a value to set Actual Maximum RAM Usage.
The RAM size indicated here determines the recommended amount of program memory (virtual memory) to allocate for server processes required by Trellix IPS. Since Jboss memory uses hard-disk-based memory (program memory), the total amount of both can exceed the Manager server's RAM memory size.
Note
The Recommended Maximum RAM Usage is Physical Server Memory divided by 2 or 1170 MB - whichever is greater. The Actual Maximum RAM Usage can be between 768 MB and three-fourth of the Physical Server Memory size.
Set the following (applicable only in Trellix IPS Manager):
Number of Sensors: Select the numbers of IPS Sensors to be managed by this installation of the Manager.
Actual Maximum DB connections: Enter the maximum number of concurrent database connections allowed from the Manager. The default is 40. The recommended number indicated above is based on the Number of Sensors.
.jpg)
If the Manager server has multiple IPv4 or IPv6 addresses, you can specify a dedicated address that it should use to communicate with the Trellix IPS devices.
To specify an IP address, select Use IPv4 Interface? or Use IPv6 Interface? and then select the address from the corresponding drop-down list.
Note
In the wizard, the option to specify a dedicated interface is displayed only if the Manager has more than one IPv4 or IPv6.
When configuring the Sensors, you need to configure the same IP that you selected here as the IP address used to communicate with the Trellix IPS devices.
.jpg)
If the Manager has an IPv6 address, then you can add Sensors with IPv6 addresses to it.
If an IP address is not displayed in the drop-down list or if a deleted IP address is displayed, then cancel the installation, restart the server, and re-install the Manager.
Post-installation, if you want to change the dedicated IP address that you already specified, you need to re-install the Manager.
In the Manager Installation Wizard, review the Pre-Installation Summary section for accurate folder locations and disk space requirements. This page lists the following information:
Product Name: Shows product as Manager (for both Manager and Central Manager).
Install Folder: The folder you specified in Step 5.
Shortcut Folder: The folder you specified in Step 6.
Manager type: Type of Manager being installed.
Database Installation location: The location on your hard drive where the database is to be located, which you specified in Step 8.
Solr Installation location: The location on your hard drive where the Solr is to be located, which you specified in Step 11.
Dedicated Interface: The IPv4 and IPv6 addresses that you specified for Manager-to-Sensor communication are displayed.
Click Install.
.jpg)
The Manager software and the database are installed to your target server. In case of an upgrade, database information is synchronized during this process.
.jpg)
Important
Post-installation, you can check the initdb.log (from <Manager_Install_Dir>\App\logs) for any installation errors. In case of errors, contact Trellix Support with initdb.log.
A congratulatory message appears upon successful installation.
The Manager Installation Wizard displays the following fields.
URL to access web-based user interface. For example, if the Manager server's computer name is Callisto, the URL is
https://CallistoDefault username
Launch the Web-based user interface on exit? checkbox
(by default, the check box is selected).
.jpg)
Click Done.
If the installation wizard prompts for a restart, it is recommended to restart the system before logging onto the Manager.
Note
The restart option might be displayed if there are any pending OS flags reset required by the installer for proper removal/updates of temporary files used during installation.
Use the shortcut icon that you created to begin using the Manager.
The Manager program opens by default in HTTPS mode for secure communication.
Note
All the Manager services will be initiated after clicking the Done button at the end of installation.
Type a valid login ID (default: admin) and password (default: admin123) for Trellix IPS Manager, and login ID (default: nscmadmin) and password (default: admin123) for Trellix IPS Central Manager.
You can use the Manager Initialization Wizard to complete the basic configuration steps.
Modify the Database Connection Pool Post-Installation
Follow these steps to change the maximum database connection pool size after completing the installation:
Stop the Trellix IPS Manager network services.
Open the ems.properties configuration file using a standard text editor and locate the line starting with
c3po.connection.maxPoolSize=.Increase the numeric pool value to standard threshold values (e.g., modifying from 40 to 60 or higher, depending on the number of configured sensor profiles).
Note
The allowed maximum threshold value for the pool is 100.
Save and close the file.
Restart the Trellix IPS Manager service engine.