This section mentions the various upgrade paths available to the latest DoDIN Trellix Intrusion Prevention System. It takes into consideration several scenarios to migrate to a DoDIN supported version of Trellix Intrusion Prevention System 10.1. For a list of upgrade paths not related to DoDIN, refer to the Trellix Intrusion Prevention System 10.1.10 Installation Guide.
Upgrade paths for Manager software versions
This section shows you different scenarios of deployment from which you can upgrade/migrate to the latest version of the Manager.
Note
You can log in to the Trellix Download Server using your Grant ID to verify the file hash for the software build.
Caution
If you are currently using a Sensor which is on software version 9.1.17.2, 9.1.17.4, 9.1.17.18, 9.1.17.100, or 9.1.17.104 and the Manager is on software version 10.1.19.17 or later, the communication between the Manager and Sensor will fail. Therefore, you must first upgrade the Sensor to software version 9.1.17.120 and later upgrade your Manager to 10.1.19.17 or later versions. Post this, you can upgrade the Sensor to 10.1.17.75.
For example, if you have a NS9300 Sensor running on software version 9.1.17.100 and Manager software version 9.1.21.40, and you plan to upgrade the Sensor to 10.1.17.75 and Manager to 10.1.19.53, you must follow the upgrade path as listed below:
- Upgrade your NS9300 Sensor from 9.1.17.100 to 9.1.17.120.
- Upgrade the Manager from 9.1.21.40 to 10.1.19.53.
- Upgrade the Sensor from 9.1.17.120 to 10.1.17.75.
Migration from Windows based Manager to Linux based Manager:
| Manager version | Recommended Manager version |
|---|---|
| 9.1.19.32, 9.1.19.38 | 10.1.19.56 |
Linux based Manager:
| Manager version | Recommended Manager version |
|---|---|
| 9.1.21.20, 9.1.21.33, 9.1.21.40 | 10.1.19.56 |
| 9.1.21.38 | 9.1.21.40 | 10.1.19.56 |
| 10.1.19.17, 10.1.19.30, 10.1.19.33, 10.1.19.38, 10.1.19.47, 10.1.19.53 | 10.1.19.56 |
Upgrade paths for Sensor software versions
This section shows you different scenarios of deployment from which you can upgrade to the latest version of the Sensors.
| Sensor model | Current Sensor software
(FIPS, CC, and DoDIN APL compliant) |
Upgrade path to latest FIPS, CC, and DoDIN APL compliant Sensor software |
|---|---|---|
| NS3100, NS3200, NS5100, NS5200, NS7100, NS7200, NS7300, NS7150, NS7250, NS7350, NS9100, NS9200, NS9300 | 9.1.17.2, 9.1.17.4, 9.1.17.18, 9.1.17.100, 9.1.17.104 | 9.1.17.120 | 10.1.17.91 |
| NS3100, NS3200, NS5100, NS5200, NS7100, NS7200, NS7300, NS7150, NS7250, NS7350, NS9100, NS9200, NS9300 | 9.1.17.105, 9.1.17.120 | 10.1.17.91 |
| NS3100, NS3200, NS3500, NS5100, NS5200, NS7100, NS7200, NS7300, NS9100, NS9200, NS9300 | 10.1.17.15, 10.1.17.26, 10.1.17.36, 10.1.17.47, 10.1.17.63, 10.1.17.75 | 10.1.17.91 |
| NS7150, NS7250, NS7350, N9500 | 10.1.17.15, 10.1.17.26, 10.1.17.36, 10.1.17.50, 10.1.17.63, 10.1.17.75 | 10.1.17.91 |
| NS7500 | 10.1.17.15, 10.1.17.36, 10.1.17.47, 10.1.17.63, 10.1.17.75 | 10.1.17.91 |
Note
A DoDIN compliant Manager can manage both DoDIN and non-DoDIN compliant Sensors.
The following applies for FIPS software running on NS-series Sensors:
- The user must synchronize a symmetric key, specified from the CLI using the set fips sharedkey command, on both the Primary and Secondary Sensors of an NS9300.
- The Sensor bootloaders are automatically upgraded to allow verification of subsequent image downloads signed with SHA256.
- The FIPS Sensor boot-up executes all the FIPS compliant algorithms, as part of the power-on self-tests (POST) and known answer tests (KAT).