The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

AWS prerequisites

Prev Next

Before you deploy your NDR Console instance in AWS, make sure the following requirements are met.

Security group requirements

  • Network interfaces:

    • Management interface

  • Security groups:

    • Inbound

      • TCP port 22—SSH management

      • TCP port 443—HTTPS Web UI and API access

    • Outbound

      • TCP port 443—HTTPS connection to cloud.fireeye.com to fetch license based on activation key

Network requirements

  • Network information—Gather the following information from your network administrator:

    • One of the following:

      • DHCP allocated IP address for the virtual machine

      • Static IP address, subnet mask, and default gateway address for the virtual machine

    • IP address for each Domain Name System (DNS) server

    • IP address for each Network Time Protocol (NTP) server

  • Network access—See the Trellix Ports and Protocols Reference Guide for a list of the required ports for network access.

License requirements

  • FIREEYE_APPLIANCE is the base product license that is tied to your activation code. It enables NDR Console features and functionality.

  • NDR License is either the ESSENTIALS/CORE or ENTERPRISE license keys for NDR functionality.

  • CONTENT_UPDATES for downloading security content packages from the DTI server.

Limitations

  • Only single-node data clusters are currently supported for AWS deployments. A node can be either a data node or a director node.