The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Replacing a Network Security HA member using an RMA

Prev Next

This section outlines the process for replacing a member of a Network Security HA pair using a Return of Materials Authorization (RMA).

Important

The Central Management System appliance aggregates alerts and events, but it does not store artifacts such as pcaps, binaries, and malware objects. If you return an appliance using an RMA, its artifacts will be lost. However, you can recover some events as described in Recovering malware-object events after a failure.

Task list

Perform the following steps to replace a defective Network Security appliance that is a member of an HA pair.

Task

Instructions

1. Contact Trellix Technical Support, and complete the "Return Process" procedure.

See the Hardware Administration Guide for your appliance model.

2. Remove the defective appliance from the HA pair.

See Removing an appliance from a Network Security HA pair.

3. Remove the defective appliance from the Central Management System appliance.

See the Central Management System Administration Guide.

4. Replace the defective appliance.

The basic steps for replacing an appliance with disk drives follow. For comprehensive information, and for steps for replacing an appliance without disk drives, see your Hardware Administration Guide.

  1. Perform an orderly shutdown of the defective appliance.

  2. Unplug the appliance.

  3. Remove the cables connecting the two pether11 ports and the two pether12 ports.

  4. Unrack the appliance.

  5. Rack-mount and re-cable the replacement appliance, including the cables between the pether11 and pether12 ports.

  6. Power on the replacement appliance.

5. Configure the replacement appliance.

Note

The replacement appliance can have the same IP address and appliance name as the defective appliance, or a different IP address and appliance name.

  1. Configure basic network settings. (See the "Initial Configuration" section of the Network Security System Administration Guide.)

  2. If available, restore the appliance's configuration and database. (See the "Database Backup and Restore" section of the Network Security System Administration Guide.)

  3. Install replacement licenses. (See Licensing requirements and the "License Management" section of the Network Security System Administration Guide.)

6. Add the replacement appliance to the Central Management System appliance.

See the Central Management System Administration Guide.

7. Add the replacement appliance to the HA pair.

See Replacing a member of a Network Security HA pair.

8. Synchronize the configuration so the detection settings are the same on both appliances.

See Synchronizing configuration settings.

Alerts displayed after a member is replaced

This section uses an example to describe the alerts that are displayed in the Central Management System Web UI after you replace a member of an HA pair. The following alerts are displayed when nx-3 replaces nx-2 in an HA pair with nx-1:

  • The alerts that were attributed to the nx-1/nx-2 pair. These alerts cannot be expanded to view their details, and cannot be submitted to a managed Malware Analysis appliance for deeper forensic analysis.

  • The alerts that were attributed to nx-1 and nx-3 before they were connected to the Central Management System appliance.

  • The alerts that were attributed to nx-1 and nx-3 after they were connected to the Central Management System appliance, but before they were added to the pair.

  • New alerts generated by nx-1 and nx-3 and attributed to the nx-1/nx-3 pair.

Important

If a full database backup of nx-2 is restored to nx-3, all alerts generated by nx-2 are displayed, but are attributed to nx-3. This includes the alerts attributed to nx-2 as a standalone or unpaired appliance, and the alerts attributed to the nx-1/nx-2 pair. If you filter on the nx-3 appliance instead of the nx-1/nx-2 pair, you can expand the alerts generated by nx-2 and submit them to a managed Malware Analysis appliance.