Review this section and its sub-sections before deploying the vIPS solution.
Trellix IPS Manager server instance requirements
Cloud environment | Resource | Recommended |
|---|---|---|
AWS | Instance type | c7i.2xlarge |
Disk space | 150 GB | |
Azure | Instance type | D2s_v3 |
Disk space | 150 GB | |
GCP | Instance type | n1-standard-4 |
Disk space | 150GB |
External Controller instance requirements
Cloud environment | Resource | Recommended |
|---|---|---|
AWS | Instance type | c5.xlarge or m5.xlarge |
Disk space | 20 GB | |
Azure | Instance type | F4s_v2 |
Disk space | 20 GB |
Note
In the event of a large deployment with more than 200 vIPS Probes, Trellix recommends you to deploy an External Controller.
Trellix IPS Sensor instance requirements
Cloud environment | Resource | Recommended |
|---|---|---|
AWS | Instance type | For IPS-VM600-VSS-SSL Sensor, use c7i.2xlarge For other Sensor models, use c5.xlarge or c6i.xlarge |
Disk space | 40 GB | |
Azure | Instance type | For IPS-VM600-VSS-SSL Sensor, use F8s_v2 For other Sensor models, use F4s_v2 |
Disk space | 40 GB | |
GCP | Instance type | For IPS-VM600-VSS-SSL Sensor, use n2-standard-8 For IPS-VM600-VSS Sensor, use n1-standard-4 |
Disk space | 40 GB |
Trellix vIPS Probe Operating System compatibility
Operating System | Minimum OS version required (AWS) | Minimum OS version required (Azure) |
|---|---|---|
Linux | Any of the following:
| Any of the following:
|
Windows |
|
|
Trellix vIPS Probe Operating System for inbound SSL decryption support
The following are the operating systems that are supported for inbound SSL decryption known-key method:
64-bit Red Hat Enterprise Linux 7
64-bit CentOS 7
64-bit SUSE Linux Enterprise Server 12 and 15
64-bit Ubuntu Server 16.04 LTS
Amazon Linux 2
Oracle Linux 7.4, 7.5, 7.6, 7.7, and 7.8
Debian 9
Windows Server 2019 R2 (Server with a GUI) English operating system
Windows Server 2016 Datacenter Edition (Server with a GUI) English operating system
Windows 10 English operating system
For Windows operating system with OpenSSL version 1.1.1, complete the steps below to enable inbound SSL decryption:
Go to the folder where Apache is installed and execute the
openssl version -vcommand to verify the OpenSSL version.If the OpenSSL version is 1.1.1 and above, perform the steps as given below:
On your Windows machine, click Start → Run.
Type
regeditin the Open textbox. Click OK.Locate and then click the following subkey in the registry:
HKLM\System\CurrentControlSet\Control\SecurityProviders\SchannelGo to Edit → New → DWORD.
Enter
DisableServerExtendedMasterSecret: REG_DWORDas the name of the DWORD for the machine receiving the request. Click Enter.Enter
DisableClientExtendedMasterSecretas the name of the DWORD for the machine initiating the request. Click Enter.Right-click the DWORD entry, and then click Modify.
Type any non-zero value like 1 in the Value data box to disable the TLS extension.
Note
You do not have to restart the system after you make changes to the
DisableClientExtendedMasterSecretregistry settings.
Trellix IPS Manager client requirements
The following table lists the 11.1 Manager/Central Manager client requirements when using Windows 11:
Minimum | Recommended | |
|---|---|---|
Operating system | Windows 11, English or Japanese
| Windows 11, version 24H2 English or Japanese |
Memory | 8 GB | 16 GB |
CPU | 1.5 GHz processor | 2.4 GHz or faster |
Monitor | 32-bit color, 1440 x 900 display setting | 1920 x 1080 (or above) |
Browser |
|
|
Note
If you wish to install packet capture tool in your Client machines, Trellix recommends you to stop the vIPS Probe and then install the tool.