Migrating to Trellix IVX:
Before you begin:
You must either use Remote Monitoring and Management (RMM) console or perform the migration on site by connecting a USB keyboard and screen directly to the appliance. It is recommended to create a second user in RMM before migration because the Intelligent Platform Management Interface (IPMI) connection is disabled once the migration to IVX is complete. As a result, you will not be able to log on to RMM console as a root user due to IPMI communication failure.
Ensure that no USB storage device with a valid Intelligent Sandbox installer is connected to the Intelligent Sandbox Appliance. The migration will not proceed if a USB device of this type is detected during the pre-migration checks.
Ensure that no virtual CDROM is attached to RMM.
IVX does not support email integration with Cisco ESA or any other MTA (Mail Transfer Agent) integrated with Intelligent Sandbox, and as a result, email analysis is not functional post-migration. Alternatively, Trellix provides a virtual EX product that integrates seamlessly with Trellix IVX which has inbuilt sandbox capability.
You must enable a few URLs in your firewall such as cloud.fireeye.com, unity.fireeye.com, up-cloud.fireeye.com to allow IVX to fetch licenses automatically. If this is not done, you will not be able to retrieve the license post-migration and will have to contact Trellix support for manual licensing. For more information on ports and protocols used, see Ports and Protocol Guide.
Ensure that the migration is performed during downtime or outside of peak hours as Intelligent Sandbox is completely erased and replaced with IVX and, as a result, no threat analysis is conducted. Before migrating to IVX, ensure that no analysis is pending or currently running in the Intelligent Sandbox, as this results in migration failure.
To access Intelligent Sandbox reports after migration, you must backup your Intelligent Sandbox data to an external storage location. Post-migration, initial setup will take some time, during which the system will not be able to analyze files until all configuration settings are completed.
Migrate to Trellix IVX:
Review the software and hardware requirements:
The migration is supported only on Intelligent Sandbox version 5.2.2 or 5.2.4. If you are on a version before 5.2.2 or 5.2.4, you must upgrade to these versions.
This migration is supported only on ATD appliances 6100/3100 and 6200/3200.
Migrate to Trellix IVX:
Verify the mapping of TIS interfaces (named eth0 to eth3) to their new IVX mapping (named ether1 to ether4).
Interface mapping may vary depending on the installed NIC hardware. Determine NIC configurations to identify the Ethernet controllers installed on the appliance.
Once Trellix IVX is installed, you will see the login prompt in the RMM console. Login to the device and accept the End User License Agreement (EULA).
fireeye-xxxxxx login: admin password: adminPost-migration to IVX, you can integrate IVXwith the following products:
For more details on the features and functionalities of Trellix IVX, refer to IVX Administrator Guide and IVX API Guide.
Determine the NIC configuration
After migration, identify the Ethernet controllers installed on the appliance.
Log in to the IVX CLI.
Execute the following command:
lspci | grep -i etherReview the Ethernet controller models returned by the command.
Match the output with one of the supported NIC configurations mentioned below.
Supported NIC configurations and interface mappings
The configurations A and B use the same interface mapping:
Configuration A — Built-in NIC + Intel X550
18:00.0 Ethernet controller: Intel Corporation Ethernet Controller 10G X550T (rev 01)
18:00.1 Ethernet controller: Intel Corporation Ethernet Controller 10G X550T (rev 01)
3d:00.0 Ethernet controller: Intel Corporation Ethernet Connection X722 for 10GBASE-T (rev 09)
3d:00.1 Ethernet controller: Intel Corporation Ethernet Connection X722 for 10GBASE-T (rev 09)Configuration B — Built-in NIC + Broadcom NIC
18:00.0 Ethernet controller [0200]: Broadcom Limited BCM57416 NetXtreme-E 10GBase-T RDMA Ethernet Controller [14e4:16d8] (rev 01)
18:00.1 Ethernet controller [0200]: Broadcom Limited BCM57416 NetXtreme-E 10GBase-T RDMA Ethernet Controller [14e4:16d8] (rev 01)
3d:00.0 Ethernet controller: Intel Corporation Ethernet Connection X722 for 10GBASE-T (rev 09)
3d:00.1 Ethernet controller: Intel Corporation Ethernet Connection X722 for 10GBASE-T (rev 09)TIS (ATD) interfaces | IVX interfaces |
|---|---|
eth0 | ether3 |
eth1 | ether4 |
eth2 | ether1 |
eth3 | ether2 |
Configuration C — Built-in NIC + Intel OCP NIC
3d:00.0 Ethernet controller: Intel Corporation Device 37d2 (rev 09)
3d:00.1 Ethernet controller: Intel Corporation Device 37d2 (rev 09)
3d:00.2 Ethernet controller: Intel Corporation Device 37d2 (rev 09)
3d:00.3 Ethernet controller: Intel Corporation Device 37d2 (rev 09)
TIS (ATD) interfaces | IVX interfaces |
|---|---|
eth0 | ether1 |
eth1 | ether2 |
eth2 | ether3 |
eth3 | ether4 |