The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Azure UI deployment for External Controller

Prev Next

To launch the External Controller as a virtual machine from Azure, perform the following steps:

Task


    1. To launch the Virtual IPS Sensor from Azure Marketplace, do the following:
      1. Go to Azure Marketplace at https://azuremarketplace.microsoft.com/en-us/marketplace/.
      2. Type Trellix vIPS External Controller 10.1 in the search field for Marketplace and select Trellix vIPS External Controller 10.1.

        The Trellix vIPS External Controller 10.1 page opens.

      3. Click GET IT NOW.

        If you have an Azure subscription account, it logs into your account and directs you to Create this app in Azure window.

        Tip

        Read the plans and pricing for the vIPS component before launching the security component.

      4. Click Continue.

        The Trellix vIPS External Controller 10.1 page opens in Azure.

      5. Click Create.

        The Create virtual machine window along with the Basics tab opens.

    2. To launch the vIPS External Controller from your Azure Subscription, do the following:
      1. Procure vIPS External Controller Virtual Hard Disk (VHD) file from Trellix. For more information, see the section How to procure vIPS components Virtual Hard Disk (VHD) files from Trellix.
      2. Create a vIPS External Controller Azure image in your subscription from the Virtual Hard Disk (VHD) file. For more information, see the section Create an Azure image from Virtual Hard Disk (VHD) file.
      3. Go to Dashboard and type the vIPS External Controller image name in the search field.

        The vIPS External Controller image page opens.

      4. Click Create VM.
      The Create virtual machine window along with the Basics tab opens.
  1. On the Basics tab, enter the following details:
    Option Definition
    Project details

    Subscription - The subscription linked with your Azure account is selected by default. If you have multiple subscription accounts, select the subscription account in which you would like to launch the External Controller virtual machine.

    Resource group

    • Create new - You can create a new resource group to be protected.
    • Use existing - Select the resource group to be protected.
    Instance details

    Virtual machine name - Type a name for the External Controller virtual machine.

    Region - Select the region where the External Controller virtual machine must be created.

    Availability options - [Optional] Select the availability sets for providing high availability to the External Controllers. It is recommended to deploy one Controller in one availability set and the other Controller in another availability set. This way when there is a downtime, one of the Controller is available.

    Image - By default, Trellix External Controller is selected as the image for the virtual machine.

    Size - Select F4s_v2 for the External Controller.

    Administrator account

    Authentication type - Select SSH authentication type.

    Note

    Only SSH Public Key authentication type is supported for Controller.

    Username - Enter the user name for the Controller virtual machine.

    Username - Enter the user name that must be used for the Manager virtual machine.

    Note

    The Username created in Azure UI gets mapped to the admin username in the instance internally. So, Trellix recommends you to use the admin username to access the Controller shell through SSH.

    SSH public key store

    • Generate new key pair - You can create a new key pair in Azure for SSH login to the Controller.
    • Use existing key stored in Azure - You can use a previously stored key pair in Azure for SSH login to the Controller.
    • Use existing public key – You can a key pair generated using an external tool.

    Note

    The private key file for the SSH public key must be in .pem format.

    Inbound port rules

    Public inbound ports - Select the ports in the Controller virtual machine to be accessible from public internet. Trellix recommends you to select None.

    Note

    Azure validates the information you enter and a green tick appears against the fields where you enter details.

  2. Click Next: Disks >.
    The Disks tab opens. Enter the following details:
    Option Definition
    Disk options

    OS disk type - The Premium SSD type is selected by default. Trellix recommends you use Premium SSD disk type for External Controller for improved performance.

    Data disks You can attach a new disk or an existing disk for your virtual machine.
    Advanced

    Use managed disks -Select Yes for Azure to manage the disk availability automatically.

  3. Click Next: Networking >.
    The Networking tab opens. Enter the following details:
    Option Definition
    Network interface

    Virtual network - Select the virtual network in which the Controller must be deployed.

    Subnet - Select the subnet in which the Controller must be deployed.

    Public IP - Trellix recommends you to not assign public IP address to the Controller virtual machine.

    NIC network security group - Select Advanced and assign pre-configured network security group rules.

    Configure network security group - Select the security group created for the External Controller virtual machine.

    Accelerated networking - By default, Off is selected as the selected image does not support accelerated networking.

  4. Click Next: Management >.
    The Management tab opens. Enter the following details:
    Option Definition
    Monitoring

    Boot diagnostics - Trellix recommends you to select Disbale.

    OS guest diagnostice - Trellix recommends you to select Off.

    Identity By default, the system assigned managed identity is Off.
    Auto-shutdown Trellix recommends you to select Off as the External Controller should not be shutdown on a daily basis.
  5. Click Next: Advanced >.
    The Advanced tab opens. Enter the following details:
    Option Definition
    Extensions Installing external extensions is not supported on vIPS components.
    Custom Data Enter the Custom Data for the External Controller in the following format:
    {
       "Primary Manager IP" : "IPS_PRIMARY_MANAGER_PRIVATE_IP",
       "Secondary Manager IP" : "IPS_SECONDARY_MANAGER_PRIVATE_IP",
       "Controller Name" : "CONTROLLER_NAME",
       "Controller Shared Key" : "SHARED_KEY"
    }
    Custom data parameters
    Parameters Description
    Primary Manager IP Private IP address of the primary Manager
    Secondary Manager IP Private IP address of the secondary Manager
    Controller Name Name of the Controller defined in the Manager
    Controller Shared Key Shared secret key of the Controller provided in the Manager
  6. Click Next: Tags >.
    The Tags tab opens. On this tab, you can categorize resources by applying a tag name and value to multiple resources and resource groups.
  7. Click Next: Review + create >.
    The Review + create tab opens. Validate the summary details which contains all the parameters selected. Make sure the validation is successful.
  8. Click Create.
    The External Controller virtual machine is created.

    Tip

    To view the External Controller virtual machine, go to All services, under the Compute section and click Virtual machines. You are directed to the Virtual machines page where you can view or delete the External Controller virtual machine.

  9. [Optional] If you are using IAM role for Cloud Access, you must assign the user assigned managed identity to the External Controller virtual machine.
    To assign user assigned managed identity to the External Controller virtual machine, do the following:
    1. Go to the External Controller instance you want to assign the IAM role to, under Identity category, and select User assigned.
    2. The Add user assigned managed identity window opens.
    3. Select the required User assigned managed identities and click Add.
  10. After the External Controller is deployed, select vIPS Controllers tab in the Manager from Devices → <Admin Domain Name> → Global → Device Manager to validate successful deployment of the External Controller.
    If the External Controller is deployed successfully, a green icon appears next to the Controller name.