Before you begin
- Ensure that the account/region where you want to deploy has not reached the maximum limits for VPC.
- Create a key pair for logging in to instances in the region you want to deploy.
- Obtain the Trellix IPS Registration Key from Trellix.
- Ensure that you have the required rights for the following:
- Creating IAM roles for the Manager. For more information see the Requirements to deploy Trellix vIPS in AWS environment.
- CloudFormation
- Managing EC2
Using the vIPS CFT, you can deploy instances of Manager, Sensor, and External Controller. The steps for deploying vIPS using CFT is given below:
Task
- Go to AWS Marketplace.
- In the search bar, enter Trellix vIPS.
-
From the search result, click
Trellix Virtual Intrusion Prevention System.
-
In the
Trellix Virtual Intrusion Prevention System page, click
Continue to Subscribe.
-
Verify the terms and the pricing, and then click
Continue to Configuration.
- Select CFT to deploy Trellix vIPS AWS Solution from the Delivery Method drop down.
- Select <latest software version available> (<latest date available>) from the Software Version drop-down.
- Select the region where you want to deploy the CFT from the Region drop-down.
-
Click
Continue to Launch.
-
Verify the configuration details and select
Launch CloudFormation. Click
Launch.
-
In the
Create stack page, under
Specify template section, ensure
Specify an Amazon S3 template URL is selected and a URL is provided in the text box. Click
Next.
-
In the
Specify stack details
page, specify the following parameter values:
Parameter Values Stack name Name of the Stack Network Configurations Service VPC IPv4 CIDR for VPC Public Subnet IPv4 CIDR for Public Subnet Private Subnet IPv4 CIDR for Private Subnet Availability Zone for Service VPC Subnets Availability Zone for creating Service VPC Subnets Instance SSH Settings Key Name Name of an existing EC2 KeyPair to enable SSH access to the EC2 Instances Trellix Intrusion Prevention System Manager settings Source CIDR for RDP and HTTPS Access Allowed Inbound Source Address Range for RDP and HTTPS access to the Manager vIPS Controller settings Launch External controller? Select Yes do deploy a vIPS External Controller. ControllerName Name of the External Controller in the Manager Note
You must use the same controller name while creating the External Controller in the Manager.
vIPS Controller - Trellix IPS Manager Shared Secret Key Shared secret key used to establish trust between the Controller and the Manager Note
You must use the same shared secret key while creating the External Controller in the Manager.
Virtual IPS Sensor settings ClusterName Name of the Sensor cluster in the Manager Note
You must use the same cluster name while creating the cluster in the Manager.
ClusterSecret Shared secret key for Manager to establish trust with the Sensor Note
You must use the same shared secret key while creating the cluster in the Manager.
AutoScaling configuration for virtual IPS Sensor Max Size Maximum number of Sensor instances to be launched from the AutoScaling Group AutoScaling - Alarm configuration settings [Alarm Metric : CPU] CPU Average for Upper Threshold Alarm Average CPU utilization for upper threshold alarm in percentage Note
The value must be a number less than 100.
CPU Average for Lower Threshold Alarm Average CPU utilization for lower threshold alarm in Percentage Note
The value must be a number less than 100.
Alarm Monitoring Time Interval Monitoring time interval for the alarm configurations defined for the Sensor Note
The time intervals must be specified in seconds. The default value in 300 seconds.
-
[Optional] In the
Specify Details page, specify the following parameter values:
Parameter Values Tags Tags are arbitrary key-value pairs that can be used to identify your stack for purposes such as cost allocation. Permissions An existing AWS Identity and Access Management (IAM) service role that AWS CloudFormation can assume Stack policy Defines the resources that you want to protect from unintentional updates during a stack update Rollback configuration Specifies alarm for the CFT when creating and using the stack Notification options A new or existing Amazon Simple Notification Service topic where notifications about stack events are sent. Syack creation options Specifies whether the stack should be rolled back if stack creation fails and prevents a stack from being accidently deleted - Verify the configuration details, select I acknowledge that AWS CloudFormation might create IAM resources with custom names.
-
Click
Create stack.
-
Once the instances are running, you can access the Manager using the public IP address for the same.
The default credentials for the Manager application are the following:
Username: admin
Password: <Last 6 digit of the Manager instance ID>.
Note
The CFT output includes the Manager public IP address and the Manager instance ID required to access the Manager application.
- Register the Manager with Trellix. For more information, see Product Registration.
- Make sure to configure the Controller and the Cluster in the Manager as described in the Configure a Controller in the Manager and Create a vIPS Cluster for AWS.
-
Download the Virtual Probe from the Manager and install it in the instances that are to be protected.
For steps to download Virtual Probe, see Download the Virtual Probe.For steps to install Virtual Probe, see Install the Virtual Probe.