The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

NTBA-EIA deployment scenarios

Prev Next

Scenario

Solution

NTBA-EIA integration with IPS Sensor

The NTBA Appliance, the IPS Sensor, and EIA should be configured in such a way that traffic from endpoints passing through IPS, same endpoints must be configured to send executable information to the NTBA Appliance.

NTBA-EIA integration without netflows coming to NTBA

The solution will work. Applications associated with the executables will not be shown. Events will not have executable information. The Network Forensics page will be blank.

NTBA-EIA integration in a setup with IPS Sensor and multiple NTBA Appliances

The Endpoint Executables page displays information per NTBA appliance. The block lists and allow lists maintained by the Manager are pushed to all NTBA Appliances with EIA integration enabled. Trellix recommends that you distribute EIA agents across various NTBAs depending on the maximum limit of endpoints supported by connected NTBA models.

Note

When more than one NTBA is configured to get executable information from endpoints and if an NTBA is not connected to IPS Sensor, the Endpoint Executables → Applications displays no applications. Sensor generated alerts do not display executable information.

NTBA-EIA integration in a setup with endpoints distributed across geo-locations

The NTBA Appliance must be deployed closer to the specific geo to be monitored in order to reduce data exchange across WAN links. The number of endpoints at a particular geo-location should be used as a factor to decide the location at which the NTBA Appliance is to be deployed. For more information, refer to the NTBA-EIA sizing recommendations.

NTBA-EIA integration in a setup with multiple ePO servers

If there are multiple ePOs managing different parts of the network and all endpoints need to communicate to a NTBA appliance on the network, this can be achieved by using third-party CA in ePO to provide the CA certificates. This way, all endpoints will receive certificates from the same CA.