The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Considerations

Prev Next

Review this section and its sub-sections before deploying the vIPS solution.

Trellix IPS Manager server instance requirements

Cloud environment

Resource

Recommended

AWS

Instance type

c7i.2xlarge

Disk space

150 GB

Azure

Instance type

D2s_v3

Disk space

150 GB

GCP

Instance type

n1-standard-4

Disk space

150GB

Note: For virtual deployments in Amazon Web Services (AWS), use instances such as m4.xlarge or c4.xlarge with at least 16 GB of memory and 300 GB of storage.

External Controller instance requirements

Cloud environment

Resource

Recommended

AWS

Instance type

c5.xlarge or m5.xlarge

Disk space

20 GB

Azure

Instance type

F4s_v2

Disk space

20 GB

Note

In the event of a large deployment with more than 200 vIPS Probes, Trellix recommends you to deploy an External Controller.

Trellix IPS Sensor instance requirements

Cloud environment

Resource

Recommended

AWS

Instance type

For IPS-VM600-VSS-SSL Sensor, use c7i.2xlarge

For other Sensor models, use c5.xlarge or c6i.xlarge

Disk space

40 GB

Azure

Instance type

For IPS-VM600-VSS-SSL Sensor, use F8s_v2

For other Sensor models, use F4s_v2

Disk space

40 GB

GCP

Instance type

For IPS-VM600-VSS-SSL Sensor, use n2-standard-8

For IPS-VM600-VSS Sensor, use n1-standard-4

Disk space

40 GB

Trellix vIPS Probe Operating System compatibility

Operating System

Minimum OS version required (AWS)

Minimum OS version required (Azure)

Linux

Any of the following:

  • 64-bit Red Hat Linux 7 and 8

  • 64-bit CentOS Linux 8

  • 64-bit SUSE Linux Enterprise Server (SLES) 12

  • 64-bit Ubuntu Linux 16.04, 18.04 and 20.04

  • 64-bit Amazon Linux 2

  • 64-bit Debian 9 and 10

Note

Only x86 architectures are supported.

Any of the following:

  • 64-bit Red Hat Linux 7

  • 64-bit CentOS Linux 8

  • 64-bit SUSE Linux Enterprise Server (SLES) 12

  • 64-bit Ubuntu Linux 16.04, 18.04 and 20.04

  • 64-bit Debian 9 and 10

Note

Only x86 architectures are supported.

Windows

  • Windows Server 2022 Standard Edition English operating system

  • Windows Server 2022 Datacenter Edition English operating system

  • Windows Server 2019 R2 Standard Edition (Server with a GUI) English operating system

  • Windows Server 2019 Datacenter Edition (Server with a GUI) English operating system

  • Windows Server 2016 Standard Edition English operating system

  • Windows Server 2022 Datacenter Edition English operating system

  • Windows Server 2019 Datacenter Edition (Server with a GUI) English operating system

  • Windows Server 2016 Datacenter Edition (Server with a GUI) English operating system

Trellix vIPS Probe Operating System for inbound SSL decryption support

The following are the operating systems that are supported for inbound SSL decryption known-key method:

  • 64-bit Red Hat Enterprise Linux 7

  • 64-bit CentOS 7

  • 64-bit SUSE Linux Enterprise Server 12 and 15

  • 64-bit Ubuntu Server 16.04 LTS

  • Amazon Linux 2

  • Oracle Linux 7.4, 7.5, 7.6, 7.7, and 7.8

  • Debian 9

  • Windows Server 2019 R2 (Server with a GUI) English operating system

  • Windows Server 2016 Datacenter Edition (Server with a GUI) English operating system

  • Windows 10 English operating system

For Windows operating system with OpenSSL version 1.1.1, complete the steps below to enable inbound SSL decryption:

  1. Go to the folder where Apache is installed and execute the openssl version -v command to verify the OpenSSL version.

  2. If the OpenSSL version is 1.1.1 and above, perform the steps as given below:

    1. On your Windows machine, click Start → Run.

    2. Type regedit in the Open textbox. Click OK.

    3. Locate and then click the following subkey in the registry:

      HKLM\System\CurrentControlSet\Control\SecurityProviders\Schannel

    4. Go to Edit → New → DWORD.

    5. Enter DisableServerExtendedMasterSecret: REG_DWORD as the name of the DWORD for the machine receiving the request. Click Enter.

    6. Enter DisableClientExtendedMasterSecret as the name of the DWORD for the machine initiating the request. Click Enter.

    7. Right-click the DWORD entry, and then click Modify.

    8. Type any non-zero value like 1 in the Value data box to disable the TLS extension.

    Note

    You do not have to restart the system after you make changes to the DisableClientExtendedMasterSecret registry settings.

Trellix IPS Manager client requirements

The following table lists the 11.1 Manager/Central Manager client requirements when using Windows 11:

Minimum

Recommended

Operating system

Windows 11, English or Japanese

Note

The display language of the Manager client must be same as that of the Manager server operating system.

Windows 11, version 24H2 English or Japanese

Memory

8 GB

16 GB

CPU

1.5 GHz processor

2.4 GHz or faster

Monitor

32-bit color, 1440 x 900 display setting

1920 x 1080 (or above)

Browser

  • Microsoft Edge

  • Mozilla Firefox

  • Google Chrome

Note

To avoid the certificate mismatch error and security warning, add the Manager web certificate to the trusted certificate list.

  • Microsoft Edge 111.0 or later

  • Mozilla Firefox 111.0 or later

  • Google Chrome 111.0 or later

Note

If you wish to install packet capture tool in your Client machines, Trellix recommends you to stop the vIPS Probe and then install the tool.