The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Synchronizing configuration settings

Prev Next

The configuration settings that affect detection must be identical for the two Network Security appliances in a Network Security HA pair, because each appliance must assume the detection functions of its peer if the peer fails.

The Central Management System appliance warns you when the following settings do not match, and provides a way to synchronize the settings of one appliance with the other appliance:

  • Date and Time

    Important

    You can use the procedures in this section to synchronize NTP servers and the time zone. However, if the system time on the two appliances differs by more than 30 seconds, a status message will be displayed, and you must synchronize the time manually. You can change the system time on one appliance to match its peer, set the time in the Central Management System Web UI in the context of the pair, or enable NTP on the pair.

  • Email

  • DTI Network

  • Inline Operational Modes

  • Inline Policy Exceptions

  • Whitelists

  • IPS Policy and Policy Exceptions

    Note

    To successfully synchronize IPS settings, both appliances must have a valid IPS license.

  • Network IP Address Whitelists

  • Login Banner

  • Static Analysis tool settings, such as AV-Suite integration, AV-Check, YARA configuration, and dropper detection

    Note

    To successfully synchronize AV-Check settings, both appliances must have a valid AV_ENGINE_SOPHOS license.

The Central Management System Web UI prevents you from making configuration changes in the wrong context. If the setting must be made on the pair, you cannot select the individual appliances from the appliance drop-down list. If the setting must be made on the individual appliance, you cannot select the pair.

In the following examples, the pair name is Acme_NXHA, and the appliance names are nx-1 and nx-2. The individual appliance names are not available in the list for the DTI Network Settings page, and the pair name is not available on the User accounts page.

NXHA_PairContext_scap.png

NXHA_IndividContext_scap.png

Important

The following settings must match, but the Central Management System appliance does not warn you if they are out-of-sync. You must check the settings on each appliance, and manually synchronize them if necessary.

  • YARA Rules

  • Custom Rules ( Network Security and IPS)

  • Custom MD5 Whitelists

  • Custom MD5 Blacklists

  • Custom Greylists

Configuration mismatches

As described in Configuration replication, these settings might be different. When this happens, a message is displayed in the Central Management System Web UI and on each page with settings that must be configured in the context of a pair. The Appliances > Sensors page provides sync controls and tooltips that display the mismatched settings when you hover your cursor over them. Examples of these messages follow.

Web UI Example

NXHA_HealthDashCM1_scap.png

Appliances page examples

NXHA_MismatchTooltip3_scap.png

NXHA_MismatchTooltip_scap.PNG

The following sections describe how to use the Central Management System appliance to synchronize the configuration of one Network Security appliance to the peer appliance.

Note

Other items, such as the appliance model, software image, guest images, security content, detection-related feature licenses, and Network Security edition must also be identical. See System requirements and Viewing the Network Security HA status for more information.

Prerequisites

  • Operator or Admin access