This section outlines the process for replacing a member of a Network Security HA pair using a Return of Materials Authorization (RMA).
Important
The Central Management System appliance aggregates alerts and events, but it does not store artifacts such as pcaps, binaries, and malware objects. If you return an appliance using an RMA, its artifacts will be lost. However, you can recover some events as described in Recovering malware-object events after a failure.
Task list
Perform the following steps to replace a defective Network Security appliance that is a member of an HA pair.
Task | Instructions |
|---|---|
1. Contact Trellix Technical Support, and complete the "Return Process" procedure. | See the Hardware Administration Guide for your appliance model. |
2. Remove the defective appliance from the HA pair. | |
3. Remove the defective appliance from the Central Management System appliance. | See the Central Management System Administration Guide. |
4. Replace the defective appliance. | The basic steps for replacing an appliance with disk drives follow. For comprehensive information, and for steps for replacing an appliance without disk drives, see your Hardware Administration Guide.
|
5. Configure the replacement appliance. NoteThe replacement appliance can have the same IP address and appliance name as the defective appliance, or a different IP address and appliance name. |
|
6. Add the replacement appliance to the Central Management System appliance. | See the Central Management System Administration Guide. |
7. Add the replacement appliance to the HA pair. | |
8. Synchronize the configuration so the detection settings are the same on both appliances. |
Alerts displayed after a member is replaced
This section uses an example to describe the alerts that are displayed in the Central Management System Web UI after you replace a member of an HA pair. The following alerts are displayed when nx-3 replaces nx-2 in an HA pair with nx-1:
The alerts that were attributed to the nx-1/nx-2 pair. These alerts cannot be expanded to view their details, and cannot be submitted to a managed Malware Analysis appliance for deeper forensic analysis.
The alerts that were attributed to nx-1 and nx-3 before they were connected to the Central Management System appliance.
The alerts that were attributed to nx-1 and nx-3 after they were connected to the Central Management System appliance, but before they were added to the pair.
New alerts generated by nx-1 and nx-3 and attributed to the nx-1/nx-3 pair.
Important
If a full database backup of nx-2 is restored to nx-3, all alerts generated by nx-2 are displayed, but are attributed to nx-3. This includes the alerts attributed to nx-2 as a standalone or unpaired appliance, and the alerts attributed to the nx-1/nx-2 pair. If you filter on the nx-3 appliance instead of the nx-1/nx-2 pair, you can expand the alerts generated by nx-2 and submit them to a managed Malware Analysis appliance.