The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Considerations

Prev Next

Review this section and its sub-sections before deploying the vIPS solution.

Trellix IPS Manager server instance requirements

Cloud environment Resource Recommended
AWS Instance type m4.xlarge or c4.xlarge
Disk space 150 GB
Azure Instance type D2s_v4
Disk space 150 GB

External Controller instance requirements

Cloud environment Resource Recommended
AWS Instance type c4.large
Disk space 20 GB
Azure Instance type F4s_v2
Disk space 20 GB

Note

In the event of a large deployment with more than 200 vIPS Probes, Trellix recommends you to deploy an External Controller.

Trellix IPS Sensor instance requirements

Cloud environment Resource Recommended
AWS Instance type c4.xlarge or c5.xlarge
Disk space 40 GB
Azure Instance type F4s_v2
Disk space 40 GB

Trellix vIPS Probe Operating System compatibility

Operating System Minimum OS version required (AWS) Minimum OS version required (Azure)
Linux Any of the following:
  • 64-bit Red Hat Linux 7 and 8
  • 64-bit CentOS Linux 7 and 8
  • 64-bit SUSE Linux Enterprise Server (SLES) 12 and 15
  • 64-bit OpenSUSE Tumbleweed
  • 64-bit Ubuntu Linux 16.04, 18.04, and 20.04
  • 64-bit Amazon Linux 2
  • 64-bit Debian 9 and 10
  • 64-bit Oracle Linux 7.9

Note

Only x86 architectures are supported.

Any of the following:
  • 64-bit Red Hat Linux 8
  • 64-bit CentOS Linux 8
  • 64-bit SUSE Linux Enterprise Server (SLES) 12 and 15
  • 64-bit Ubuntu Linux 16.04, 18.04, and 20.04
  • 64-bit Debian 9 and 10
  • 64-bit Oracle Linux 7.9

Note

Only x86 architectures are supported.

Windows
  • Windows Server 2019 R2 Standard Edition (Server with a GUI) English operating system
  • Windows Server 2019 Datacenter Edition (Server with a GUI) English operating system
  • Windows Server 2016 Standard Edition (Server with a GUI) English operating system
  • Windows Server 2016 Datacenter Edition (Server with a GUI) English operating system
  • Windows Server 2012 R2 Standard Edition (Server with a GUI) English operating system
  • Windows Server 2019 Datacenter Edition (Server with a GUI) English operating system
  • Windows Server 2016 Datacenter Edition (Server with a GUI) English operating system
  • Windows Server 2012 R2 Datacenter Edition (Server with a GUI) English operating system

Trellix vIPS Probe Operating System for inbound SSL decryption support

The following are the operating systems that are supported for inbound SSL decryption known-key method:

  • 64-bit Red Hat Enterprise Linux 7
  • 64-bit CentOS 7
  • 64-bit SUSE Linux Enterprise Server 12 and 15
  • 64-bit Ubuntu Server 16.04 LTS
  • Amazon Linux 2
  • Oracle Linux 7.4, 7.5, 7.6, 7.7, and 7.8
  • Debian 9
  • Windows Server 2019 R2 (Server with a GUI) English operating system
  • Windows Server 2016 Datacenter Edition (Server with a GUI) English operating system
  • Windows Server 2012 R2 (Server with a GUI) English operating system
  • Windows 10 English operating system

For Windows operating system with OpenSSL version 1.1.1, complete the steps below to enable inbound SSL decryption:

  1. Go to the folder where Apache is installed and execute the openssl version -v command to verify the OpenSSL version.
  2. If the OpenSSL version is 1.1.1 and above, perform the steps as given below:
    1. On your Windows machine, click Start → Run.
    2. Type regedit in the Open textbox. Click OK.
    3. Locate and then click the following subkey in the registry:

      HKLM\System\CurrentControlSet\Control\SecurityProviders\Schannel

    4. Go to Edit → New → DWORD.
    5. Enter DisableServerExtendedMasterSecret: REG_DWORD as the name of the DWORD for the machine receiving the request. Click Enter.
    6. Enter DisableClientExtendedMasterSecret as the name of the DWORD for the machine initiating the request. Click Enter.
    7. Right-click the DWORD entry, and then click Modify.
    8. Type any non-zero value like 1 in the Value data box to disable the TLS extension.

    Note

    You do not have to restart the system after you make changes to the DisableClientExtendedMasterSecret registry settings.

Trellix IPS Manager client requirements

The following table lists the 10.1 Manager/Central Manager client requirements when using Windows 10:

Minimum Recommended
Operating system Windows 10, English or Japanese

Note

The display language of the Manager client must be same as that of the Manager server operating system.

Windows 10, version 1903 English or Japanese
Memory 8 GB 16 GB
CPU 1.5 GHz processor 2.4 GHz or faster
Monitor 32-bit color, 1440 x 900 display setting 1920 x 1080 (or above)
Browser
  • Microsoft Edge
  • Mozilla Firefox
  • Google Chrome

Note

To avoid the certificate mismatch error and security warning, add the Manager web certificate to the trusted certificate list.

Note

Internet Explorer 11 is not supported.

  • Microsoft Edge 42.0 or later
  • Mozilla Firefox 70.0 or later
  • Google Chrome 76.0 or later

Note

If you wish to install packet capture tool in your Client machines, Trellix recommends you to stop the vIPS Probe and then install the tool.