Trellix recommends that you regularly monitor for maintenance releases and new versions of the Manager software. To know whether the new version of the Manager is applicable to Linux appliances, see the specific version of Trellix Intrusion Prevention System release notes. The Linux based Manager upgrade file contains Manager software upgrade file bundled with MLOS upgrade patch. On executing the Linux based Manager upgrade file, the MLOS and the Linux based Manager application are upgraded simultaneously.
Pre-requisites:
Make sure you have a Linux machine installed in your network.
You must download the Manager upgrade file (setup.bin) from the Download Server and save it in the Linux machine, If you are upgrading from 10.1.7.4 Linux based Manager versions.
Note
Make a note of the location where the upgrade file is saved in the Linux machine.
You must download the Manager upgrade file (setup.bin) from the Download Server and save it in the Linux based Manager server when using
install the setup present on local machineupgrade in 10.1.7.7 or higher Linux based Manager versions.Note
Make a note of the location where the upgrade file is saved in the Manager server.
You must download the Manager upgrade file (setup.bin) from the Download Server and save it in the Linux machine, when using
scp setup from remote machine and installupgrade in 10.1.7.7or higher Linux based Manager versions.Note
Make a note of the location where the upgrade file is saved in the Linux machine.
Scenario 1: If you are upgrading from Manager versions 11.1.7.84 to 11.1.7.136.2
Log on to the restricted shell of Manager Appliance using the default username and password.
Execute the following command to upgrade the Manager.
upgradeAfter executing the above command, the Manager instance prompts the following options:
Choose one of the below options 1: scp setup from remote machine and install 2: install the setup present on local machine Input [1] or [2] : <Select the upgrade method>Note
If you select
1: scp setup from remote machine and install, you must have the Linux based Manager upgrade file saved in a remote Linux machine.If you select
2: install the setup present on local machine, you must have the Linux based Manager upgrade file saved in the Linux based Manager itself.
If you select 1, continue with the following steps, else skip to step 7.
You are prompted to provide your SCP server IP address:
Enter the IP of the remote machine: <remote_machine_ip>Type the SCP server IP address and press
Enter.You are prompted to provide your username for the SCP server.
Enter the user of the remote machine: <remote_machine_user>Type your username for the SCP server and press
Enter.You are prompted to provide the filepath of Manager upgrade file in the SCP server.
Enter the setup file's path as on remote machine: <Filepath of the upgrade file in the remote machine>Type filepath for the upgrade file in the SCP server and press
Enter.When the Manager upgrade begins, respond to each prompt to proceed to the next step.
When you are prompted to provide the MariaDB root password, type your database root password and press
Enter. By default, the MariaDB root password isroot123.You are prompted to provide the location to create links.
Where would you like to create links? ->1- Default: /root 2- In your home folder 3- Choose another location... 4- Don't create links ENTER THE NUMBER OF AN OPTION ABOVE, OR PRESS <ENTER> TO ACCEPT THE DEFAULT :Type the required location and press
Enter.The pre-installation summary is displayed. Press
Enterto continue the upgrade.Pre-Installation Summary ------------------------ Please Review the Following Before Continuing: Product Name: Manager Manager Type: IPS Manager Install folder: /opt/IPSManager/App Database folder: /opt/IPSManager/MariaDB Solr folder: /opt/IPSManager/Solr Link folder: /root Disk Space Information (for Installation Target): Required: 2,469,326,987 Bytes Available: 342,469,943,296 Bytes PRESS <ENTER> TO CONTINUE:Next, the Manager location details are displayed. Press
Enterto continue the upgrade.Ready To Install ---------------- Ready to install IPS Manager onto your system at the following location: /opt/IPSManager/App PRESS <ENTER> TO INSTALL:Once the installation is complete, an auto reboot of the server will be initiated. Press
Enterto exit the installer and complete the upgrade.Installation Complete --------------------- Congratulations. Manager has been successfully installed to: /opt/IPSManager/App Auto Reboot of the server will be initiated to complete the upgrade process after exiting the installer. PRESS <ENTER> TO EXIT THE INSTALLER:When the auto reboot is initiated, the following details are displayed:
Please Wait ----------- Connection closing...Socket close. Connection closed by foreign host. Disconnected from remote host(NSM_xx_xx) at 20:18:46.After completing the upgrade procedure, check the Manager version using
show managerVersioncommand to ensure a successful upgrade.
If you select 2, do the following.
You are prompted to provide filepath of the upgrade file in the Linux based Manager server:
Enter the path to the setup.bin file: <upgrade_file_filepath>Type the filepath of the upgrade file in the Linux based Manager server and press
Enter.When you are prompted to provide the MariaDB root password, type your database root password and press
Enter. By default, the MariaDB root password isroot123.Once the installation is complete, an auto reboot of the server will be initiated to complete the upgrade process. Press
Enterto exit the installer and complete the upgrade process.The following details will be displayed after the auto reboot is initiated:
Please Wait ----------- Connection closing...Socket close. Connection closed by foreign host. Disconnected from remote host(NSM_xx_xx) at 20:18:46.After completing the upgrade procedure, check the Manager version using
show managerVersioncommand to ensure a successful upgrade.
Note
The default Manager root directory for App, MariaDB, and Solr will be moved from /opt/NetworkSecurityManager to /opt/IPS Manager. In such scenarios, you will be prompted with this directory change in the console.
Scenario 2: If you are upgrading from Manager versions 10.1.7.7 to 11.1.7.71
Log on to the restricted shell of Manager Appliance using default username and password.
Stop the Watchdog service by executing
watchdog stopcommand.Stop the Manager service by executing
manager stopcommand.Execute the following command to upgrade the Manager.
upgradeAfter executing the above command, the Manager instance prompts the following options:
Choose one of the below options 1: scp setup from remote machine and install 2: install the setup present on local machine Input [1] or [2] : <Select the upgrade method>Note
If you select
1: scp setup from remote machine and install, you must have the Linux based Manager upgrade file saved in a remote Linux machine.Note
If you select
2: install the setup present on local machine, you must have the Linux based Manager upgrade file saved in the Linux based Manager itself.If you select 1, continue with the following steps, else skip to step 7.
You are prompted to provide your SCP server IP address:
Enter the IP of the remote machine: <remote_machine_ip>Type the SCP server IP address and press
Enter.You are prompted to provide your username for the SCP server.
Enter the user of the remote machine: <remote_machine_user>Type your username for the SCP server and press
Enter.You are prompted to provide the filepath of Manager upgrade file in the SCP server.
Enter the setup file's path as on remote machine: <Filepath of the upgrade file in the remote machine>Type filepath for the upgrade file in SCP server and press
Enter.When you are prompted to provide the MariaDB root password, type your database root password and press
Enter. By default, the MariaDB root password isroot123.Important
After providing the MariaDB password, you will not be able to proceed with the upgrade process if you have configured any M-series Sensor in the Manager. The following error message is displayed:
=============================================================================== Enter Database Root password ---------------------------- Please enter Database Root password : =============================================================================== Upgrade Failure --------------- Manager version 11.1.7.x will not support M-series devices. The upgrade cannot continue. Please ensure all M-series devices have been removed and restart the upgrade. Please see the "SensorModel.log" file that has been placed on your /opt/apps for the list of M-series devices attached to your Manager. PRESS <ENTER> TO ACCEPT THE FOLLOWING (OK): Manager@MLOS-NSM1> dbShellTo continue with the upgrade process, disconnect any M-series Sensors configured in the 10.1 Manager.
Important
You can generate configuration reports for a selected M-series Sensor for future reference from → → → → . For more information, see Generate IPS Sensor reportsin Trellix Intrusion Prevention System 11.1.x Product Guide.
A list of all M-series Sensors are provided in SensorModel.log file on
/opt/apps. To view the complete domain path for the required M-series Sensors, go to → → → . Select the required M-series Sensor from Sensors tab and view the domain details from Owner Domain column. By default, the Owner Domain column is not enabled. To enable it, go to Device Details drop-down and select → → .
After completing the upgrade procedure, check the Manager version using
show managerVersioncommand to ensure successful upgrade.Reboot the Linux based Manager by executing
rebootcommand.
If you select 2, do the following.
You are prompted to provide filepath of the upgrade file in the Linux based Manager server:
Enter the path to the setup.bin file: <upgrade_file_filepath>Type the filepath of the upgrade file in the Linux based Manager server and press
Enter.When you are prompted to provide the MariaDB root password, type your database root password and press
Enter. By default, the MariaDB root password isroot123.Caution
After providing the MariaDB password, you will not be able to proceed with the upgrade process if you have configured any M-series Sensor in the Manager. The following error message is displayed:
=============================================================================== Enter Database Root password ---------------------------- Please enter Database Root password : =============================================================================== Upgrade Failure --------------- Manager version 11.1.7.x will not support M-series devices. The upgrade cannot continue. Please ensure all M-series devices have been removed and restart the upgrade. Please see the "SensorModel.log" file that has been placed on your /opt/apps for the list of M-series devices attached to your Manager. PRESS <ENTER> TO ACCEPT THE FOLLOWING (OK): Manager@MLOS-NSM1> dbShellTo continue with the upgrade process, disconnect any M-series Sensors configured in the 10.1 Manager.
Important
You can generate configuration reports for a selected M-series Sensor for future reference from → → → → . For more information, see Generate IPS Sensor reportsin Trellix Intrusion Prevention System 11.1.x Product Guide.
A list of all M-series Sensors are provided in SensorModel.log file on
/opt/apps. To view the complete domain path for the required M-series Sensors, go to → → → . Select the required M-series Sensor from Sensors tab and view the domain details from Owner Domain column. By default, the Owner Domain column is not enabled. To enable it, go to Device Details drop-down and select → → .
After completing the upgrade procedure, check the Manager version using
show managerVersioncommand to ensure successful upgrade.Reboot the Linux based Manager by executing
rebootcommand.
Note
The default Manager root directory for App, MariaDB, and Solr will be moved from /opt/NetworkSecurityManager to /opt/IPS Manager. In such scenarios, you will be prompted with this directory change in the console.
Scenario 3: If you are upgrading from Manager versions 10.1.7.4 to 10.1.7.7
Log on to the restricted shell of Manager Appliance using default username and password.
Stop the Watchdog service by executing
watchdog stopcommand.Stop the Manager service by executing
manager stopcommand.Execute the following code block to upgrade the Manager.
upgrade <Username> <Linux_machine_ip> <File_path_of_the_upgrade_file>Following are the input parameters required for the restricted shell command:
Parameter
Description
UsernameLogin username for the Linux machine where the Manager upgrade file is saved.
Linux_machine_ipIP address of Linux machine where you have saved the upgrade file.
File_path_of_the_upgrade_fileFile path for the upgrade file in the Linux machine.
After executing the above command block, the Manager instance prompts a question:
Are you sure you want to continue connecting (yes/no)?Type
yesand pressEnter.You are prompted to provide the Linux machine password.
admin@w.x.y.z's password:Type password for the user account and press
Enter.You are prompted to provide your Linux based Manager shell password.
[sudo] password for admin:Type password for the Manager. By default, the password for Manager shell is
MLOSnsmAppfor Manager andMLOSnscmAppfor Central Manager.When you are prompted to provide the MariaDB root password, type your database root password and press
Enter. By default, the MariaDB root password isroot123.Important
After providing the MariaDB password, you will not be able to proceed with the upgrade process if you have configured any M-series Sensor in the Manager. The following error message is displayed:
=============================================================================== Enter Database Root password ---------------------------- Please enter Database Root password : =============================================================================== Upgrade Failure --------------- Manager version 11.1.7.x will not support M-series devices. The upgrade cannot continue. Please ensure all M-series devices have been removed and restart the upgrade. Please see the "SensorModel.log" file that has been placed on your /opt/apps for the list of M-series devices attached to your Manager. PRESS <ENTER> TO ACCEPT THE FOLLOWING (OK): Manager@MLOS-NSM1> dbShellTo continue with the upgrade process, disconnect any M-series Sensors configured in the 10.1 Manager.
Important
You can generate configuration reports for a selected M-series Sensor for future reference from → → → → . For more information, see Generate IPS Sensor reportsin Trellix Intrusion Prevention System 11.1.x Product Guide.
A list of all M-series Sensors are provided in SensorModel.log file on
/opt/apps. To view the complete domain path for the required M-series Sensors, go to → → → . Select the required M-series Sensor from Sensors tab and view the domain details from Owner Domain column. By default, the Owner Domain column is not enabled. To enable it, go to Device Details drop-down and select → → .
After completing the upgrade procedure, check the Manager version using
show managerVersioncommand to ensure successful upgrade.Reboot the Linux based Manager by executing
rebootcommand.
Note
The default Manager root directory for App, MariaDB, and Solr will be moved from /opt/NetworkSecurityManager to /opt/IPS Manager. In such scenarios, you will be prompted with this directory change in the console.