The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Migrating from MLOS Manager Appliance to Trellix OS Manager Appliance

Prev Next

The process of migrating your Manager from an MLOS appliance to a Trellix OS appliance involves several key steps to ensure data integrity and a smooth transition.

Warning

  • This is not a regular upgrade. The entire DISK will be FORMATTED, and a fresh Trellix OS will be imaged onto the disk. All data will be lost, including Network configurations, backups, and any local appliance customization or hardening.

  • This procedure applies only to physical appliances. It does not support virtual machine instances (ESX, KVM, Nutanix, or Cloud).

  • Central Manager on a physical appliance is not supported.

Prerequisites:

Important

Mandatory pre-migration and post-migration actions apply to all Manager configurations (standalone, primary, or secondary).

  1. Verify the Manager version: Ensure the Manager Server is running on Trellix IPS Manager version 11.1.7.136 or 11.1.7.136.2. This is crucial for compatibility with the migration process.

  2. Ensure you have downloaded the latest signature set in the Manager.

  3. Ensure the remote client machine has SSH version 9.0 or later.

    To verify the current SSH version, execute the command ssh -V.

    Note: You must reset the default password via VGA or serial port to use SSH services. SSH access remains restricted until the default password is changed.

  4. You must keep the SSH keepalive configuration enabled in your SSH client (Example: Bitvise, MobaXterm) to avoid session termination in the Linux-based Manager and maintain a stable connection during the Manager upgrade process.

    Mobaxterm.png

  5. Record the MLOS Manager's IP address and hostname; use this same information for the Trellix OS Manager.

    Execute the commands:

    • show network ip: Collect the IP address.

    • show network hostname: Collect the hostname.

  6. Carefully document all customization done in the MLOS setup, as it must be repeated post-migration.

Mandatory actions before migration:

  1. Take the "All Table Backup" from MLOS, along with the necessary file backups, and move to an external disk. When the backup is generated, two files are created with the .jar and .dmp extensions. Back up the .jar and .dmp files to a safe location in the remote machine.

    To verify a successful backup:

    • Execute the following commands in sequence to check if the latest backup file is available:

      1. moveManualBackups

      2. show files

    • Go to Manager → <Admin Domain Name> → Troubleshooting → Logs page and select Background Tasks tab to confirm the backup is complete.

    • Execute the command show log file dbadmin.log and verify the success statement in the log file. If any issue persists, contact Trellix support.

  2. When you are taking a backup from a secondary standby Manager, perform the following steps:

    1. Execute the command, run dbBackup.sh.

    2. When prompted for backup type, select ALL TABLES backup.

    3. When prompted for a list of actions, bypass the comment option.

  3. The following folders must be copied from the MLOS system to the remote client machine in a safe location using SFTP.

    Tip

    Trellix recommends using Bitvise to transfer the files/folders.

    • /opt/IPSManager/App/temp

    • /opt/IPSManager/App/Backups

    • /opt/IPSManager/App/alertarchival

    • /opt/IPSManager/App/CCMigration

    • /opt/IPSManager/App/config

Migration steps

  1. Log in to the Manager shell with the admin credentials.

  2. Execute the command upgrade.

    upgrade
  3. Specify the required details at the prompt:

    Manager> upgrade 
    Choose one of the below options
    
    1: scp setup from remote machine and install 
    2: install the setup present on local machine 
    Input [1] or [2] : 1
    
    Enter the IP of the remote machine: 10.1.1.1 
    Enter the user of the remote machine: admin
    Enter the setup file's path as on remote machine: /tftpboot/NSM/11.1.7.x/setup.bin
    FIPS mode initialized
    The authenticity of host '10.1.1.1 (10.1.1.1)' can't be established.
    ECDSA key fingerprint is SHA256:7***************************.
    ECDSA key fingerprint is SHA1:5**************.
    Are you sure you want to continue connecting (yes/no)? yes
    Warning: Permanently added '10.1.1.1' (ECDSA) to the list of known hosts.
    admin@10.1.1.1's password:
    setup.bin
    
    Preparing for the upgrade process. Kindly wait a moment....
    
    (sudo] password for admin:
    Installing bundle:setup.bin
    Decrypting and verifying /tmp/setup.bin, this may take couple of minutes to complete 
    Preparing to install
    Extracting the JRE from the installer archive...
    Unpacking the JRE...
    Extracting the installation resources from the installer archive...
    Configuring the installer for this system's environment...
    
    Launching installer...
    =======================================================================================
    Manager	                                                 (created with InstallAnywhere)
    ---------------------------------------------------------------------------------------
    Preparing CONSOLE Mode Installation...	
    
    
    
    
    =======================================================================================
    Introduction
    ---------------------------------------------------------------------------------------
    
    Welcome to the Trellix Installation Wizard.
    
    This Wizard can be used to install either of the following applications: 
    
    - Trellix IPS Manager vll.1.7.x
    
    - Trellix IPS Central Manager vll.1.7.x
    
    It is strongly recommended that you quit all programs before continuing with this installation.
    
    Respond to each prompt to proceed to the next step in the installation. 
    
    You may cancel this installation at any time by typing 'quit'.
    
    PRESS <ENTER> TO CONTINUE: <Enter>
    ===================================================================================
    IPS Manager OS Migration: Critical Warnings and Mandatory Actions
    -----------------------------------------------------------------
    
    This upgrade migrates MLOS to Trellix OS. It is intended for IPS Manager 
    physical appliances only.
    
    WARNING: This is not a regular upgrade. The entire DISK will be FORMATTED, and 
    a fresh Trellix OS will be imaged onto the disk. All data will be lost, 
    including Network configurations, backups, and any local appliance 
    customization or hardening.
    
    MANDATORY ACTIONS BEFORE MIGRATION:
    
    * Documentation Review: You must carefully read the mandatory steps under the 
    "Migration Procedures" section in the MLOS to Trellix OS migration document. 
    * The latest available Signature Set must be applied to the MLOS appliance. 
    * Backup: Ensure the "All Table Backup" from MLOS is taken, along with
    necessary file backups, and moved to an external disk.
    * Customization: All customization done on this setup must be carefully 
    documented, as those need to be repeated post-migration.
    
    
    MANDATORY ACTIONS POST-MIGRATION:
    *  The "All Table Backup" must be manually restored on the setup.
    *  The list of files specified in the "Migration Procedures" section, must be 
    replaced.
    *  Ensure the latest available Signature Set is present in the appliance.
    
    
    Please reach out to the support team if you need assistance.
    
    Are you sure you would like to continue?
    
        ->1- NO 
          2- Yes
    
    ENTER THE NUMBER OF THE DESIRED CHOICE, OR PRESS <ENTER> TO ACCEPT THE
    DEFAULT: 2
    ==================================================================================
    Manager Upgrade
    ---------------
    
    Your current Trellix IPS Manager Version 11.1.7.x will be upgraded to 
    11.1.7.x.
    
    PRESS <ENTER> TO CONTINUE:
    
    
    ==================================================================================
    Enter Database Root password
    ----------------------------
    
    
    Please enter Database Root password :
    
    ==================================================================================
    Choose Link Location
    --------------------
    
    Where would you like to create links?
      ->1- Default: /root
        2- In your home folder
        3- Choose another location...
        4- Don't create links
    
    ENTER THE NUMBER OF AN OPTION ABOVE, OR PRESS <ENTER> TO ACCEPT THE DEFAULT
          : 
    
    
    ==================================================================================
    Pre-Installation Summary
    ------------------------
    
    Please Review the Following Before Continuing:
    
    Product Name:
        Manager
    
    Manager Type:
        IPS Manager
    
    Install folder:
        /opt/IPSManager/App
    
    Database folder:
        /opt/IPSManager/MariaDB
    
    Solr folder:
        /opt/1PSManager/Solr
    
    Link folder:
        /root
    
    Disk Space Information (for Installation Target): 
        Required:	4,565,583,606 Bytes
        Available: 1,350,637,322,240 Bytes
    
    PRESS <ENTER> TO CONTINUE: <Enter>
    ==================================================================================
    Ready To Install
    ----------------
    
    Ready to install IPS Manager onto your system at the following location:
    
        /opt/IPSManager/App
    
    PRESS <ENTER> TO INSTALL:
    
    ==================================================================================
    Installing...
    -------------
    
    
    [==================][==================][==================][==================]
    
    ==================================================================================
    
    Please Wait
    -----------
    
    
    ==================================================================================
    
    Please Wait
    -----------
    
    ==================================================================================
    Migration process requires automatic reboots
    --------------------------------------------
    
    Your appliance automatically reboots in 15 seconds.
    
    The system is reimaged from MLOS to Trellix OS. This process takes
    approximately 30-40 minutes and might include several automatic reboots.
    
    Warning: Do not power off your device until the upgrade is complete.
    Otherwise, the upgrade might fail.
    
    PRESS <ENTER> TO ACCEPT THE FOLLOWING (OK): <Enter>
    

Data Migration

After migrating to Trellix OS Manager, perform a data restore to load all your original data onto the new operating system.

Prerequisite:

  1. Enable the SFTP and SCP features on the Trellix OS machine to copy files from the remote machine.

    Execute the following commands in sequence:

    1. enable

    2. configure terminal

    3. ssh server services file-transfer scp enable

    4. ssh server services file-transfer sftp enable

    5. write memory

Mandatory actions post migration:

  1. After exiting the installer, connect to the Manager appliance's serial port or video graphics array (VGA) cable to configure the network parameters. When setting the IP address and hostname, ensure they match the previous MLOS Manager settings. For more information, see the section Configure the Manager Appliance.

    Tip

    The network configurations must remain unchanged from their original state before the 11.1 Update 9 MLOS migration.

  2. Stop the Manager service by using no ipsmanager enable.

  3. Copy the "All Table Backup" files from the remote client machine to Trellix OS Manager.

    Assuming the AllTablesBackup.jar and AllTablesBackup.dmp files are located at /home/admin path on your client system, execute the commands:

    1. scp -r /home/admin/AllTablesBackup.jar admin@10.1.1.1:/opt/IPSManager/App/Backups/

    2. scp -r /home/admin/AllTablesBackup.dmp admin@10.1.1.1:/opt/IPSManager/App/Backups/

  4. Restore the "All Table Backup" files in Trellix OS Manager.

    Execute the following commands in sequence:

    1. enable

    2. configure terminal

    3. To list the latest backup files, execute the command:

      show ipsmanager backups

    4. ipsmanager database restore path /opt/IPSManager/App/Backups/AllTablesBackup.jar

    5. show ipsmanager database restore status

  5. The following folders must be replaced in the Trellix OS system using scp recursively.

    If the backup folders taken from 11.1 Update 9 are located at the path /home/admin/folderbackups on your client machine, replace the temp folder by executing the following command:

    scp -r /home/admin/folderbackups/temp/* admin@10.1.1.1:/opt/IPSManager/App/temp/

    You must repeat the same command for the following folders:

    • /home/admin/folderbackups/temp

    • /home/admin/folderbackups/Backups

    • /home/admin/folderbackups/alertarchival

    • /home/admin/folderbackups/CCMigration

  6. Replace the mlcCerts folder by executing the command:

    scp -r /home/admin/folderbackups/config/mlcCerts/* admin@10.1.1.1:/opt/IPSManager/App/config/mlcCerts/

  7. If the backup folder taken from 11.1 Update 9 is located at the path /home/admin/folderbackups/config on your client machine:

    • Replace the jssecacerts file by executing the following command:

      scp /home/admin/folderbackups/config/jssecacerts admin@10.1.1.1:/opt/IPSManager/App/config/jssecacerts

    • Replace the CustomJSSEcaCerts file by executing the following command:

      scp /home/admin/folderbackups/config/CustomSecurity/CustomJSSEcaCerts admin@10.1.1.1:/opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts

  8. Replacing the ems.properties file:

    1. Identify custom entries added for ems.properties in the 11.1 Update 9 Manager.

    2. Create a new file myEms.properties in the client machine.

    3. Add the custom entries in myEms.properties file.

    4. Update myEms.properties file in Trellix OS. If the file is created in /home/admin/folderbackups/config/myEms.properties, execute the command:

      scp /home/admin/folderbackups/config/myEms.properties admin@10.1.1.1:/opt/IPSManager/App/config/myEms.properties

    Tip

    An automated tool is available to read ems.properties file, identify differences, and update the necessary changes in the new configuration file. For any assistance, contact Trellix support.

  9. Restart MariaDB by using the commands:

    1. enable

    2. configure terminal

    3. no mariadb enable

    4. mariadb enable

  10. Enable the Manager service by using ipsmanager enable.

  11. You must allow time for the Manager to establish trust with the attached Sensors.

  12. Ensure you have downloaded the latest signature set in the Manager.

  13. For the Manager in an MDR pair, restore the database and file backups for the primary and secondary Manager to avoid post-migration issues such as the CA-signed Sensor channel flap issue.

  14. The following table lists the impact of alert data migration in Manager.

    Component

    Impact

    Alert data storage

    Note

    Manager

    Disk is wiped

    Alerts are stored in MariaDB and Solr.

    The Attack Log will have no alerts immediately after migration.

    Alert data gets restored on the Manager startup.

    Expect a delay before the alerts appear in the Attack Log.

    To ensure all alerts are available in the Attack Log, wait for the automated Solr import process to complete. Check Background Tasks for the status.