Review this section and its sub-sections before deploying the vIPS solution.
Trellix IPS Manager server instance requirements
| Cloud environment | Resource | Recommended |
|---|---|---|
| AWS | Instance type | m4.xlarge or c4.xlarge |
| Disk space | 150 GB | |
| Azure | Instance type | D2s_v4 |
| Disk space | 150 GB |
External Controller instance requirements
| Cloud environment | Resource | Recommended |
|---|---|---|
| AWS | Instance type | c4.large |
| Disk space | 20 GB | |
| Azure | Instance type | F4s_v2 |
| Disk space | 20 GB |
Note
In the event of a large deployment with more than 200 vIPS Probes, Trellix recommends you to deploy an External Controller.
Trellix IPS Sensor instance requirements
| Cloud environment | Resource | Recommended |
|---|---|---|
| AWS | Instance type | c4.xlarge or c5.xlarge |
| Disk space | 40 GB | |
| Azure | Instance type | F4s_v2 |
| Disk space | 40 GB |
Trellix vIPS Probe Operating System compatibility
| Operating System | Minimum OS version required (AWS) | Minimum OS version required (Azure) |
|---|---|---|
| Linux | Any of the following:
|
Any of the following:
|
| Windows |
|
|
Trellix vIPS Probe Operating System for inbound SSL decryption support
The following are the operating systems that are supported for inbound SSL decryption known-key method:
- 64-bit Red Hat Enterprise Linux 7
- 64-bit CentOS 7
- 64-bit SUSE Linux Enterprise Server 12 and 15
- 64-bit Ubuntu Server 16.04 LTS
- Amazon Linux 2
- Oracle Linux 7.4, 7.5, 7.6, 7.7, and 7.8
- Debian 9
- Windows Server 2019 R2 (Server with a GUI) English operating system
- Windows Server 2016 Datacenter Edition (Server with a GUI) English operating system
- Windows Server 2012 R2 (Server with a GUI) English operating system
- Windows 10 English operating system
For Windows operating system with OpenSSL version 1.1.1, complete the steps below to enable inbound SSL decryption:
- Go to the folder where Apache is installed and execute the openssl version -v command to verify the OpenSSL version.
- If the OpenSSL version is 1.1.1 and above, perform the steps as given below:
- On your Windows machine, click Start → Run.
- Type regedit in the Open textbox. Click OK.
- Locate and then click the following subkey in the registry:
HKLM\System\CurrentControlSet\Control\SecurityProviders\Schannel
- Go to Edit → New → DWORD.
- Enter DisableServerExtendedMasterSecret: REG_DWORD as the name of the DWORD for the machine receiving the request. Click Enter.
- Enter DisableClientExtendedMasterSecret as the name of the DWORD for the machine initiating the request. Click Enter.
- Right-click the DWORD entry, and then click Modify.
- Type any non-zero value like 1 in the Value data box to disable the TLS extension.
Note
You do not have to restart the system after you make changes to the DisableClientExtendedMasterSecret registry settings.
Trellix IPS Manager client requirements
The following table lists the 10.1 Manager/Central Manager client requirements when using Windows 10:
| Minimum | Recommended | |
|---|---|---|
| Operating system | Windows 10, English or Japanese
|
Windows 10, version 1903 English or Japanese |
| Memory | 8 GB | 16 GB |
| CPU | 1.5 GHz processor | 2.4 GHz or faster |
| Monitor | 32-bit color, 1440 x 900 display setting | 1920 x 1080 (or above) |
| Browser |
|
|
Note
If you wish to install packet capture tool in your Client machines, Trellix recommends you to stop the vIPS Probe and then install the tool.