The process of migrating your Manager from an MLOS appliance to a Trellix OS appliance involves several key steps to ensure data integrity and a smooth transition.
Warning
This is not a regular upgrade. The entire DISK will be FORMATTED, and a fresh Trellix OS will be imaged onto the disk. All data will be lost, including Network configurations, backups, and any local appliance customization or hardening.
This procedure applies only to physical appliances. It does not support virtual machine instances (ESX, KVM, Nutanix, or Cloud).
Central Manager on a physical appliance is not supported.
Prerequisites:
Important
Mandatory pre-migration and post-migration actions apply to all Manager configurations (standalone, primary, or secondary).
Verify the Manager version: Ensure the Manager Server is running on Trellix IPS Manager version 11.1.7.136 or 11.1.7.136.2. This is crucial for compatibility with the migration process.
Ensure you have downloaded the latest signature set in the Manager.
Ensure the remote client machine has SSH version 9.0 or later.
To verify the current SSH version, execute the command
ssh -V.Note: You must reset the default password via VGA or serial port to use SSH services. SSH access remains restricted until the default password is changed.
You must keep the SSH keepalive configuration enabled in your SSH client (Example: Bitvise, MobaXterm) to avoid session termination in the Linux-based Manager and maintain a stable connection during the Manager upgrade process.
.png)
Record the MLOS Manager's IP address and hostname; use this same information for the Trellix OS Manager.
Execute the commands:
show network ip: Collect the IP address.show network hostname: Collect the hostname.
Carefully document all customization done in the MLOS setup, as it must be repeated post-migration.
Mandatory actions before migration:
Take the "All Table Backup" from MLOS, along with the necessary file backups, and move to an external disk. When the backup is generated, two files are created with the .jar and .dmp extensions. Back up the .jar and .dmp files to a safe location in the remote machine.
To verify a successful backup:
Execute the following commands in sequence to check if the latest backup file is available:
moveManualBackupsshow files
Go to → → → page and select Background Tasks tab to confirm the backup is complete.
Execute the command
show log file dbadmin.logand verify the success statement in the log file. If any issue persists, contact Trellix support.
When you are taking a backup from a secondary standby Manager, perform the following steps:
Execute the command, run dbBackup.sh.
When prompted for backup type, select
ALL TABLESbackup.When prompted for a list of actions, bypass the comment option.
The following folders must be copied from the MLOS system to the remote client machine in a safe location using
SFTP.Tip
Trellix recommends using Bitvise to transfer the files/folders.
/opt/IPSManager/App/temp
/opt/IPSManager/App/Backups
/opt/IPSManager/App/alertarchival
/opt/IPSManager/App/CCMigration
/opt/IPSManager/App/config
Migration steps
Log in to the Manager shell with the admin credentials.
Execute the command
upgrade.upgradeSpecify the required details at the prompt:
Manager> upgrade Choose one of the below options 1: scp setup from remote machine and install 2: install the setup present on local machine Input [1] or [2] : 1 Enter the IP of the remote machine: 10.1.1.1 Enter the user of the remote machine: admin Enter the setup file's path as on remote machine: /tftpboot/NSM/11.1.7.x/setup.bin FIPS mode initialized The authenticity of host '10.1.1.1 (10.1.1.1)' can't be established. ECDSA key fingerprint is SHA256:7***************************. ECDSA key fingerprint is SHA1:5**************. Are you sure you want to continue connecting (yes/no)? yes Warning: Permanently added '10.1.1.1' (ECDSA) to the list of known hosts. admin@10.1.1.1's password: setup.bin Preparing for the upgrade process. Kindly wait a moment.... (sudo] password for admin: Installing bundle:setup.bin Decrypting and verifying /tmp/setup.bin, this may take couple of minutes to complete Preparing to install Extracting the JRE from the installer archive... Unpacking the JRE... Extracting the installation resources from the installer archive... Configuring the installer for this system's environment... Launching installer... ======================================================================================= Manager (created with InstallAnywhere) --------------------------------------------------------------------------------------- Preparing CONSOLE Mode Installation... ======================================================================================= Introduction --------------------------------------------------------------------------------------- Welcome to the Trellix Installation Wizard. This Wizard can be used to install either of the following applications: - Trellix IPS Manager vll.1.7.x - Trellix IPS Central Manager vll.1.7.x It is strongly recommended that you quit all programs before continuing with this installation. Respond to each prompt to proceed to the next step in the installation. You may cancel this installation at any time by typing 'quit'. PRESS <ENTER> TO CONTINUE: <Enter>=================================================================================== IPS Manager OS Migration: Critical Warnings and Mandatory Actions ----------------------------------------------------------------- This upgrade migrates MLOS to Trellix OS. It is intended for IPS Manager physical appliances only. WARNING: This is not a regular upgrade. The entire DISK will be FORMATTED, and a fresh Trellix OS will be imaged onto the disk. All data will be lost, including Network configurations, backups, and any local appliance customization or hardening. MANDATORY ACTIONS BEFORE MIGRATION: * Documentation Review: You must carefully read the mandatory steps under the "Migration Procedures" section in the MLOS to Trellix OS migration document. * The latest available Signature Set must be applied to the MLOS appliance. * Backup: Ensure the "All Table Backup" from MLOS is taken, along with necessary file backups, and moved to an external disk. * Customization: All customization done on this setup must be carefully documented, as those need to be repeated post-migration. MANDATORY ACTIONS POST-MIGRATION: * The "All Table Backup" must be manually restored on the setup. * The list of files specified in the "Migration Procedures" section, must be replaced. * Ensure the latest available Signature Set is present in the appliance. Please reach out to the support team if you need assistance. Are you sure you would like to continue? ->1- NO 2- Yes ENTER THE NUMBER OF THE DESIRED CHOICE, OR PRESS <ENTER> TO ACCEPT THE DEFAULT: 2================================================================================== Manager Upgrade --------------- Your current Trellix IPS Manager Version 11.1.7.x will be upgraded to 11.1.7.x. PRESS <ENTER> TO CONTINUE: ================================================================================== Enter Database Root password ---------------------------- Please enter Database Root password : ================================================================================== Choose Link Location -------------------- Where would you like to create links? ->1- Default: /root 2- In your home folder 3- Choose another location... 4- Don't create links ENTER THE NUMBER OF AN OPTION ABOVE, OR PRESS <ENTER> TO ACCEPT THE DEFAULT : ================================================================================== Pre-Installation Summary ------------------------ Please Review the Following Before Continuing: Product Name: Manager Manager Type: IPS Manager Install folder: /opt/IPSManager/App Database folder: /opt/IPSManager/MariaDB Solr folder: /opt/1PSManager/Solr Link folder: /root Disk Space Information (for Installation Target): Required: 4,565,583,606 Bytes Available: 1,350,637,322,240 Bytes PRESS <ENTER> TO CONTINUE: <Enter>================================================================================== Ready To Install ---------------- Ready to install IPS Manager onto your system at the following location: /opt/IPSManager/App PRESS <ENTER> TO INSTALL: ================================================================================== Installing... ------------- [==================][==================][==================][==================] ================================================================================== Please Wait ----------- ================================================================================== Please Wait ----------- ================================================================================== Migration process requires automatic reboots -------------------------------------------- Your appliance automatically reboots in 15 seconds. The system is reimaged from MLOS to Trellix OS. This process takes approximately 30-40 minutes and might include several automatic reboots. Warning: Do not power off your device until the upgrade is complete. Otherwise, the upgrade might fail. PRESS <ENTER> TO ACCEPT THE FOLLOWING (OK): <Enter>
Data Migration
After migrating to Trellix OS Manager, perform a data restore to load all your original data onto the new operating system.
Prerequisite:
Enable the SFTP and SCP features on the Trellix OS machine to copy files from the remote machine.
Execute the following commands in sequence:
enableconfigure terminalssh server services file-transfer scp enablessh server services file-transfer sftp enablewrite memory
Mandatory actions post migration:
After exiting the installer, connect to the Manager appliance's serial port or video graphics array (VGA) cable to configure the network parameters. When setting the IP address and hostname, ensure they match the previous MLOS Manager settings. For more information, see the section Configure the Manager Appliance.
Tip
The network configurations must remain unchanged from their original state before the 11.1 Update 9 MLOS migration.
Stop the Manager service by using
no ipsmanager enable.Copy the "All Table Backup" files from the remote client machine to Trellix OS Manager.
Assuming the
AllTablesBackup.jarandAllTablesBackup.dmpfiles are located at/home/adminpath on your client system, execute the commands:scp -r /home/admin/AllTablesBackup.jar admin@10.1.1.1:/opt/IPSManager/App/Backups/scp -r /home/admin/AllTablesBackup.dmp admin@10.1.1.1:/opt/IPSManager/App/Backups/
Restore the "All Table Backup" files in Trellix OS Manager.
Execute the following commands in sequence:
enableconfigure terminalTo list the latest backup files, execute the command:
show ipsmanager backupsipsmanager database restore path /opt/IPSManager/App/Backups/AllTablesBackup.jarshow ipsmanager database restore status
The following folders must be replaced in the Trellix OS system using
scprecursively.If the backup folders taken from 11.1 Update 9 are located at the path
/home/admin/folderbackupson your client machine, replace thetempfolder by executing the following command:scp -r /home/admin/folderbackups/temp/* admin@10.1.1.1:/opt/IPSManager/App/temp/You must repeat the same command for the following folders:
/home/admin/folderbackups/temp
/home/admin/folderbackups/Backups
/home/admin/folderbackups/alertarchival
/home/admin/folderbackups/CCMigration
Replace the
mlcCertsfolder by executing the command:scp -r /home/admin/folderbackups/config/mlcCerts/* admin@10.1.1.1:/opt/IPSManager/App/config/mlcCerts/If the backup folder taken from 11.1 Update 9 is located at the path
/home/admin/folderbackups/configon your client machine:Replace the
jssecacertsfile by executing the following command:scp /home/admin/folderbackups/config/jssecacerts admin@10.1.1.1:/opt/IPSManager/App/config/jssecacertsReplace the
CustomJSSEcaCertsfile by executing the following command:scp /home/admin/folderbackups/config/CustomSecurity/CustomJSSEcaCerts admin@10.1.1.1:/opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts
Replacing the
ems.propertiesfile:Identify custom entries added for
ems.propertiesin the 11.1 Update 9 Manager.Create a new file
myEms.propertiesin the client machine.Add the custom entries in
myEms.propertiesfile.Update
myEms.propertiesfile in Trellix OS. If the file is created in/home/admin/folderbackups/config/myEms.properties, execute the command:scp /home/admin/folderbackups/config/myEms.properties admin@10.1.1.1:/opt/IPSManager/App/config/myEms.properties
Tip
An automated tool is available to read
ems.propertiesfile, identify differences, and update the necessary changes in the new configuration file. For any assistance, contact Trellix support.Restart MariaDB by using the commands:
enableconfigure terminalno mariadb enablemariadb enable
Enable the Manager service by using
ipsmanager enable.You must allow time for the Manager to establish trust with the attached Sensors.
Ensure you have downloaded the latest signature set in the Manager.
For the Manager in an MDR pair, restore the database and file backups for the primary and secondary Manager to avoid post-migration issues such as the CA-signed Sensor channel flap issue.
The following table lists the impact of alert data migration in Manager.
Component
Impact
Alert data storage
Note
Manager
Disk is wiped
Alerts are stored in MariaDB and Solr.
The Attack Log will have no alerts immediately after migration.
Alert data gets restored on the Manager startup.
Expect a delay before the alerts appear in the Attack Log.
To ensure all alerts are available in the Attack Log, wait for the automated Solr import process to complete. Check Background Tasks for the status.