Warning
You cannot perform a direct upgrade from 11.1 Update 9 (MLOS) to Trellix OS Manager using the
upgradecommand. To install the Trellix OS Manager on a VM, you must perform a fresh deployment and restore theAll Table Backup.This procedure applies only to virtual machine instances (ESX, KVM, Nutanix, or Cloud).
Pre-deployment process:
To ensure data integrity and a smooth transition, follow these requirements to upgrade your Manager from 11.1 Update 9 (MLOS) to Trellix OS.
Prerequisites:
Important
Mandatory actions apply to Manager/Central Manager configurations (standalone, primary, and secondary).
Verify that the Manager server uses Trellix IPS Manager version 11.1.7.136 or 11.1.7.136.2.
Ensure that the remote client machine used to copy files and folders from the MLOS Manager has SSH version 9.0 or later.
To verify the current SSH version, execute the command
ssh -V.You must keep the SSH keepalive configuration enabled in your SSH client (Example: Bitvise, MobaXterm) to avoid session termination in the Linux-based Manager and maintain a stable connection during the Manager upgrade process.
.png)
Record the MLOS Manager's IP address and hostname; use this same information for the Trellix OS Manager.
Execute the commands:
show network ip: Collect the IP address.show network hostname: Collect the hostname.
Carefully document all customization done in the MLOS setup, as it must be repeated post-migration.
Mandatory actions before deploying the Trellix OS Manager:
Take the "All Table Backup" from MLOS and move it to an external disk. When the backup is generated, two files are created with the .jar and .dmp extensions. Back up the .jar and .dmp files to a safe location in the remote machine.
To verify a successful backup:
Execute the following commands in sequence to check if the latest backup file is available:
moveManualBackupsshow files
Go to → → → page and select Background Tasks tab to confirm the backup is complete.
Execute the command
show log file dbadmin.logand verify the success statement in the log file. If any issue persists, contact Trellix support.
When you are taking a backup from a secondary standby Manager, perform the following steps:
Execute the command, run dbBackup.sh.
When prompted for backup type, select
ALL TABLESbackup.When prompted for a list of actions, bypass the comment option.
The following folders must be copied from the MLOS system to the remote client machine in a safe location using
SFTP.Tip
Trellix recommends using Bitvise to transfer the files/folders.
/opt/IPSManager/App/temp
/opt/IPSManager/App/Backups
/opt/IPSManager/App/alertarchival
/opt/IPSManager/App/CCMigration
/opt/IPSManager/App/config
For steps on installing the Manager, refer to sections Create a Manager instance using the OVA file and Create a Manager instance using a qcow2 file.
Post-deployment process:
After deploying Trellix OS Manager, perform a data restore to load all your original data onto the new operating system.
Prerequisite:
Enable the SFTP and SCP features on the Trellix OS machine to copy files from the remote machine.
Execute the following commands in sequence:
enableconfigure terminalssh server services file-transfer scp enablessh server services file-transfer sftp enablewrite memory
Mandatory actions post deployment:
Stop the Manager service by using
no ipsmanager enable.Restore the "All Table Backup" files in Trellix OS Manager.
Execute the following commands in sequence:
enableconfigure terminalTo list the latest backup files, execute the command:
show ipsmanager backupsipsmanager database restore path /opt/IPSManager/App/Backups/AllTablesBackup.jarshow ipsmanager database restore status
The following folders must be replaced in the Trellix OS system using
scprecursively.If the backup folders taken from 11.1 Update 9 are located at the path
/home/admin/folderbackupson your client machine, replace thetempfolder by executing the following command:scp -r /home/admin/folderbackups/temp/* admin@10.1.1.1:/opt/IPSManager/App/temp/You must repeat the same command for the following folders:
/home/admin/folderbackups/temp
/home/admin/folderbackups/Backups
/home/admin/folderbackups/alertarchival
/home/admin/folderbackups/CCMigration
Replace the
mlcCertsfolder by executing the command:scp -r /home/admin/folderbackups/config/mlcCerts/* admin@10.1.1.1:/opt/IPSManager/App/config/mlcCerts/If the backup folder taken from 11.1 Update 9 is located at the path
/home/admin/folderbackups/configon your client machine:Replace the
jssecacertsfile by executing the following command:scp /home/admin/folderbackups/config/jssecacerts admin@10.1.1.1:/opt/IPSManager/App/config/jssecacertsReplace the
CustomJSSEcaCertsfile by executing the following command:scp /home/admin/folderbackups/config/CustomSecurity/CustomJSSEcaCerts admin@10.1.1.1:/opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts
Replacing the
ems.propertiesfile:Identify custom entries added for
ems.propertiesin the 11.1 Update 9 Manager.Create a new file
myEms.propertiesin the client machine.Add the custom entries in
myEms.propertiesfile.Update
myEms.propertiesfile in Trellix OS. If the file is created in/home/admin/folderbackups/config/myEms.properties, execute the command:scp /home/admin/folderbackups/config/myEms.properties admin@10.1.1.1:/opt/IPSManager/App/config/myEms.properties
Tip
An automated tool is available to read
ems.propertiesfile, identify differences, and update the necessary changes in the new configuration file. For any assistance, contact Trellix support.Restart MariaDB by using the commands:
enableconfigure terminalno mariadb enablemariadb enable
Enable the Manager service by using
ipsmanager enable.You must allow time for the Manager to establish trust with the attached Sensors.
Ensure you have downloaded the latest signature set in the Manager.
For the Manager in an MDR pair, restore the database and file backups for the primary and secondary Manager to avoid post-migration issues such as the CA-signed Sensor channel flap issue.
The following table lists the impact of alert data migration in Manager:
Component
Impact
Alert data storage
Note
Manager
Disk is wiped
Alerts are stored in MariaDB and Solr.
The Attack Log will have no alerts immediately after All Table Backup restore.
Alert data gets restored on the Manager startup.
Expect a delay before the alerts appear in the Attack Log.
To ensure all alerts are available in the Attack Log, wait for the automated Solr import process to complete. Check Background Tasks for the status.