Manage how your agents connect to TrendAI Vision One™ and download updates.
Important
|
Runtime connection policies control how your agents connect to
TrendAI Vision One™ and which update source to use. Runtime connection policies are fully compatible
with Version control policies. Runtime connection policies has the following agent
requirements:
Runtime policies agent requirements
|
Deployment type
|
Minimum agent version
|
Required version to use relay groups as an update source
|
Network requirements
|
|
Standard Endpoint Protection
|
May 2024 release or later
|
TrendAI Vision One™ Endpoint Security agent version 202603 or later
|
Relays receive connections from agents on port 4126. Configure your firewall settings
to allow your relays to receive inbound traffic on port 4126.
|
|
Server & Workload Protection
|
May 2024 release
|
||
|
Endpoint Sensor only
|
Version 202406 or later
|
||
|
Connected TrendAI™ Apex One SaaS agents
|
May 2024 release or later
|
-
|
-
|
Procedure
- In the TrendAI Vision One™ console, go to and click the Runtime connection policies tab.
- Create or edit a policy.
-
To create a new policy, click Create policy.
-
To edit a policy, find the policy you want to edit and click the name.
The policy configuration screen appears. -
- Specify a unique Policy name.

Note
You cannot edit the policy name for the Default policy. - Select the target Endpoint groups to apply the policy.
- Click the edit icon (
) to select target endpoint groups. - Locate and select the endpoint group you want to add.

Important
-
Endpoint groups can only be assigned to one policy at a time. Selecting a group that is already assigned to a policy moves that endpoint group to the new policy.
-
Selecting an endpoint group automatically selects any child groups including those already assigned to a policy. You can clear the selection for any child group you do not want to include in the new policy.You can assign child groups to a different policy than the parent group.
-
Endpoint groups not assigned to a user-created policy automatically adopt the Default policy.
-
- Click Select.
- Click the edit icon (
- Configure your priority rules.
- To add a new priority rule, click Add Priority and provide a name for the rule.New rules are automatically added to the top of the priority list as Priority 1.
- To change the order of your priority rules, click and drag the priority rule you want
to change.The priority rule number changes automatically.For example, moving Priority 1 under Priority 3 automatically changes the original Priority 1 to Priority 3, and the old Priority 2 and Priority 3 become Priority 1 and Priority 2, respectively.
- To change the name of a priority rule, click the options icon next to the name (
) and select Rename. - To delete a priority rule, click the options icon next to the name (
) and select Delete.
Important
You cannot delete the Base priority rule.
- To add a new priority rule, click Add Priority and provide a name for the rule.
- Click the priority rule you want to configure.
- Configure the Criteria for the selected priority rule.

Important
If an endpoint matches multiple priority rule criteria, the endpoint uses the highest priority rule matched.If an endpoint does not match any priority rule criteria, the endpoint uses the Base priority rule.The Base priority rule criteria is All endpoints and cannot be changed.- Select the Criteria type.
- Specify the criteria values.The criteria is used to determine which endpoints within the assigned endpoint groups the priority rule applies to. The criteria value input method changes depending on which criteria type you select.Criteria typeDescriptionInput methodAllThe priority rule is applied to all endpoints-Endpoint nameThe priority rule is applied to any endpoint containing at least one specified value in the endpoint nameFor example, if you specify Test, the priority rule is applied to the endpoint
Test01.Specify a value and either type a comma (,) or press ENTER to separate values.Operating systemThe priority rule is applied to any endpoint with the specified operating systemClick the edit icon (
) to select the OS family or a specific OS version.IP rangeThe priority rule is applied to any endpoint with an IP address within one of the specified rangesSpecify an IP range in either IPv4 or IPv6 format. Click the add icon (
) to add up to 200 IP ranges.
- Configure the Update source.
- Select the Source.
- Specify the source as needed.The update source determines what your endpoints connect to when downloading agent updates.

Note
-
To use Service Gateways, you must have at least one Service Gateway with the Generic Caching Service enabled. For best results, enable both the Generic Caching Service and ActiveUpdate Service on your selected Service Gateways. For more information, see Manage services in Service Gateway.
-
To use a relay group, you must have at least one relay group configured. For more information, see Configure relay groups.
-
Agents must be able to connect to configured update source. If agents cannot connect, the agents follow the update fallback settings.
Criteria typeDescriptionInput methodUse selected Service GatewaysAgents connect to the specified Service GatewaysAfter selecting this option, a drop-down appears. Select one or more Service Gateway appliances. Hover over the info icon (
) to view the associated IPv4 address and enabled services.Use all available Service GatewaysAgents connect to any available Service Gateway they can reach-Use relay groupAgents connect to endpoints within the specified relay groupAfter selecting this option, a drop-down appears. Select the relay group to use.No configurationAgents follow the update source settings of the next lower priorityIf no connections are configured or available, the agent connects directly to TrendAI Vision One™ to download updates.- -
- Configure the Agent connection proxy settings.
- Specify the Service Gateway policy.

Important
You must have at least one Service Gateway with Forward Proxy Service enabled to connect using this method.-
Select Use selected Service Gateways to specify which Service Gateway appliances agents use.After selecting this option, a drop-down appears. Select one or more Service Gateway appliances. Hover over the info icon (
) to view the associated IPv4 address and enabled services. -
Click Use all available Service Gateways to allow the endpoint agent to connect to any Service Gateway based on availability.
-
Click Do not use Service Gateways if you do not want your endpoints to connect using a Service Gateway.
-
- Specify the Primary custom proxy settings.Leave the settings blank if you do not want the targeted endpoints to use a proxy server to connect to TrendAI Vision One™.
-
Proxy address: The IPv4 address or FQDN of the proxy server
-
Port: The connection port for the proxy server
-
If the proxy server requires credentials, select Require authentication credentials, and provide the Account and Password.
-
- Specify the Default System Proxy Settings.

Important
Linux agents do not support using the default system proxy.Server & Workload Protection agents do not support connecting with a default system proxy that requires authentication credentials.-
If your endpoint system proxy requires authentication credentials, select Require authentication credentials, and provide the Account and Password.
-
Otherwise, leave blank.
-
- Specify the Service Gateway policy.
- Click Save.
- If want to remove a policy, delete the policy.

Note
-
You cannot delete the Default policy.
-
Any endpoint groups assigned to a deleted policy adopt the Default policy.
- Select one or more policies you want to delete.
- Click Delete.
- Confirm the selected policies and click Delete.
-
