The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deploy the Network Security Integration In-band from the GCP console

Prev Next

To deploy the NSI In-band from the GCP console, perform the following steps:

  1. Log in to the Google Cloud and click on Activate Cloud Shell to launch the Cloud Shell terminal. Now, execute the following commands:

  2. Go to Search in the Google Cloud console and type Health checks. Now, click on create health check.

    The Create a health check page is displayed.

  3. In the Create a health check page, provide the following details:

    1. Source: Select Regional.

    2. Name: Define the name for a health check.

    3. Protocol: Select TCP from the drop-down.

    4. Port: Enter 9001 in the field.

      You can use the default value for all other parameters and click Create.

  4. Execute the below commands to deploy the backend service (NSI In-band) in Trellix vIPS VPC:

    gcloud compute backend-services create <name_backend_service> \
    --load-balancing-scheme=INTERNAL \
    --protocol=UDP \
    --region=<region> \
    --health-checks=<name_healthcheck>
  5. Create a forwarding rule in Trellix vIPS VPC:

    gcloud compute forwarding-rules create <name_forwarding rule> \
    --load-balancing-scheme=INTERNAL \
    --backend-service=<name_backend_service> \
    --ip-protocol=UDP \
    --ports=6081 \
    --region=<region> \
    --subnet=<Trellix_vIPS_subnet> \
    --network=<name>
    
  6. Create an intercept deployment group in Trellix vIPS VPC:

    gcloud network-security intercept-deployment-groups create <name_intercept_deployment_group> \
    --location=global \
    --no-async \
    --network=<name> 
  7. List and describe the intercept deployment

    gcloud network-security intercept-deployments create <name_intercept_deployment> \
    --location=global 
    
  8. Create intercept deployment in Trellix vIPS VPC:

    gcloud network-security intercept-deployments create <name_intercept_deployment> \
    --location <location> \
    --forwarding-rule <name_forwarding_rule> \
    --forwarding-rule-location <location> \
    --no-async \
    --intercept-deployment-group \
     projects/$PRODUCER_PROJECT/locations/global/interceptDeploymentGroups/<name_intercept_deployment_group> 
    
  9. View details of the intercept deployment

    gcloud network-security intercept-deployments describe <name_intercept_deployment> \
    --location <location> 
    
  10. Create an intercept endpoint group in consumer VPC:

    gcloud network-security intercept-endpoint-groups create <name_intercept_endpoint_group> \
    --location global \
    --no-async
    --intercept-deployment-group \
     projects/$PRODUCER_PROJECT/locations/global/interceptDeploymentGroups/<name_intercept_deployment_group> 
    
  11. View details of the endpoint group

    gcloud network-security intercept-endpoint-groups describe <name_intercept_endpoint_group> \
    --location global
    
  12. Create an intercept endpoint group association in the consumer VPC:

    gcloud network-security intercept-endpoint-group-associations create <name_intercept_endpoint_group_association> \
    --location global \
    --network <name_consumer_VPC> \
    --no-async \
    --intercept-endpoint-group \
     projects/$PRODUCER_PROJECT/locations/global/interceptDeploymentGroups/<name_intercept_endpoint_group_association> 
    
    
  13. View details of the endpoint group association

    gcloud network-security intercept-endpoint-group-association describe <name_intercept_endpoint_group_association> \
    --location global
    
  14. Create a Security Profile. You must require organization level access to create a security profile.

    gcloud network-security security-profiles custom-intercept create <name_network_security_profile> \
    --organization <Org_Number> \
    --location global \
    --billing-project $PRODUCER_PROJECT \
    --intercept-endpoint-group \
     projects/$PRODUCER_PROJECT/locations/global/interceptEndpointGroups/<name_intercept_endpoint_group> 
    
    
  15. Create a security profile group:

    gcloud network-security security-profile-groups create <name_network_security_profile_group> \
    --custom-intercept-prole <name_network_security_profile> \
    --billing-project $PRODUCER_PROJECT \
    --organization <org_number> \
    --location global
  16. Create network firewall policy:

    gcloud compute network-firewall-policies create <name_network_firewall_policy> 
  17. Configure the required firewall rules for Sensors to intercept and inspect traffic. An example is shown below

    gcloud compute network-firewall-policies rules create 1 \
    --action=APPLY_SECURITY_PROFILE_GROUP \
    --firewall-policy <name_network_firewall_policy> \
    --security-profile-group organizations/<org_number>/locations/global/securityProfileGroups/<name_network_security_profile_group> \
    --direction INGRESS \

    Tip

    You can determine the required CIDR based on the protected VM's CIDR range.

  18. Create a network firewall policy association:

    gcloud compute network-firewall-policies associations create \
    --name <name_network_firewall_policy_association> \
    --global-firewall-policy \
    --firewall-policy <name_network_firewall_policy> \
    --network <name_consumer_VPC> \
    --project $PRODUCER_PROJECT