To launch the Manager as a virtual machine, perform the following steps:
Task
-
-
To launch the Virtual IPS Sensor from Azure Marketplace, do the following:
- Go to Azure Marketplace at https://azuremarketplace.microsoft.com/en-us/marketplace/.
- Type
Trellix Intrusion Prevention System Manager 10.1 in the search field for Marketplace and select
Trellix Intrusion Prevention System Manager 10.1.
The Trellix Intrusion Prevention System Manager 10.1 page opens.
- Click
GET IT NOW.
If you have an Azure subscription account, it logs into your account and directs you to Create this app in Azure window.
Tip
Read the plans and pricing for the vIPS component before launching the security component.
- Click
Continue.
The Trellix Intrusion Prevention System Manager 10.1 page opens in Azure.
- Click
Create.
The Create virtual machine window along with the Basics tab opens.
-
To launch the Manager from your Azure Subscription, do the following:
- Procure Trellix IPS Manager Virtual Hard Disk (VHD) file from Trellix. For more information, see How to procure vIPS components Virtual Hard Disk (VHD) files from Trellix.
- Create a Manager Azure image in your subscription from the Virtual Hard Disk (VHD) file. For more information, see Create an Azure image from Virtual Hard Disk (VHD) file.
- Go to
Dashboard and type the
Trellix Intrusion Prevention System Manager name in the search field.
The Trellix Intrusion Prevention System Manager image page opens.
- Click Create VM.
The Create virtual machine window along with the Basics tab opens.
-
To launch the Virtual IPS Sensor from Azure Marketplace, do the following:
-
On the
Basics tab, enter the following details:
Option Definition Project details Subscription - The subscription linked with your Azure account is selected by default. If you have multiple subscription accounts, select the subscription account in which you would like to launch the Manager virtual machine.
Resource group
- Create new - You can create a new resource group to be protected.
- Use existing - Select the resource group to be protected.
Instance details Virtual machine name - Type a name for the Manager virtual machine.
Note
The Manager name should not exceed 25 characters.
Region - Select the region where the Manager virtual machine must be created.
Availability options - [Optional] Select the availability sets for providing high availability to the Managers.
Image - By default, the image created for the Manager is selected as the image for the virtual machine.
Size - Select D2s_v4 based on the requirement.
Administrator account Authentication type - Select SSH authentication type.
Note
Only SSH Public Key authentication type is supported for Manager.
Username - Enter the user name that must be used for the Manager virtual machine.
Note
The Username created in Azure UI gets mapped to the admin username internally. So, Trellix recommends you to use the admin username to access the Manager shell through SSH.
SSH public key store
- Generate new key pair - You can create a new key pair in Azure for SSH login to the Manager.
- Use existing key stored in Azure - You can use a previously stored key pair in Azure for SSH login to the Manager.
- Use existing public key – You can a key pair generated using an external tool.
Note
The private key file for the SSH public key must be in .pem format.
Inbound port rules Public inbound ports - Select the ports in the Manager virtual machine to be accessible from public internet. Trellix recommends you to select None.
Note
Azure validates the information you enter and a green tick appears against the fields where you enter details.
-
Click
Next: Disks >.
The Disks tab opens. Enter the following details:
Option Definition Disk options OS disk type - The SSD type is selected by default. Trellix recommends you use premium SSD disk type for Manager for improved performance.
Data disks You can attach a new disk or an existing disk for your virtual machine. Advanced Use Managed disks - Select Yes for Azure to manage the disk availability automatically.
-
Click
Next: Networking >.
The Networking tab opens. Enter the following details:
Option Definition Network interface Virtual network - Select the virtual network in which the Manager must be deployed.
Subnet - Select the subnet in which the Manager must be deployed.
Public IP - [Optional] By default, a static Public IP is assigned to the Manager instance.
NIC Network security group (firewall) - Select Advanced and assign pre-configured network security group rules.
Configure network security group— Select the security group created for the Manager virtual machine.
Accelerated networking - By default, Off is selected as the selected image does not support accelerated networking.
-
Click
Next: Management >.
The Management tab opens. Enter the following details:
Option Definition Monitoring Boot diagnostics - Trellix recommends you to select Disbale.
OS guest diagnostice - Trellix recommends you to select Off.
Identity By default, the system assigned managed identity is Off. Auto-shutdown Trellix recommends you to select Off as the Manager should not be shutdown on a daily basis. -
Click
Next: Advanced >.
The Advanced tab opens. Enter the following details:
Option Definition Extensions Installing external extensions is not supported on vIPS components. Custom Data By default, Custom Data is not applicable for the selected image. -
Click
Next: Tags >.
The Tags tab opens. On this tab, you can categorize resources by applying a tag name and value to multiple resources and resource groups.
-
Click
Next: Review + create >.
The Review + create tab opens. Validate the summary details which contains all the parameters selected. Make sure the validation is successful.
-
Click
Create.
The IPS Manager virtual machine is deployed.
Note
The installation procedure takes few minutes for configurational settings to complete. You can access the Manager only after the downtime.