The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deploying vIPS CloudFormation Template (CFT) from AWS Marketplace

Prev Next

Before you begin

  1. Ensure that the account/region where you want to deploy has not reached the maximum limits for VPC.
  2. Create a key pair for logging in to instances in the region you want to deploy.
  3. Obtain the Trellix IPS Registration Key from Trellix.
  4. Ensure that you have the required rights for the following:

Using the vIPS CFT, you can deploy instances of Manager, Sensor, and External Controller. The steps for deploying vIPS using CFT is given below:

Task

  1. Go to AWS Marketplace.
  2. In the search bar, enter Trellix vIPS.
  3. From the search result, click Trellix Virtual Intrusion Prevention System.
  4. In the Trellix Virtual Intrusion Prevention System page, click Continue to Subscribe.
  5. Verify the terms and the pricing, and then click Continue to Configuration.
  6. Select CFT to deploy Trellix vIPS AWS Solution from the Delivery Method drop down.
  7. Select <latest software version available> (<latest date available>) from the Software Version drop-down.
  8. Select the region where you want to deploy the CFT from the Region drop-down.
  9. Click Continue to Launch.
  10. Verify the configuration details and select Launch CloudFormation. Click Launch.
  11. In the Create stack page, under Specify template section, ensure Specify an Amazon S3 template URL is selected and a URL is provided in the text box. Click Next.
  12. In the Specify stack details page, specify the following parameter values:
    Parameter Values
    Stack name Name of the Stack
    Network Configurations
    Service VPC IPv4 CIDR for VPC
    Public Subnet IPv4 CIDR for Public Subnet
    Private Subnet IPv4 CIDR for Private Subnet
    Availability Zone for Service VPC Subnets Availability Zone for creating Service VPC Subnets
    Instance SSH Settings
    Key Name Name of an existing EC2 KeyPair to enable SSH access to the EC2 Instances
    Trellix Intrusion Prevention System Manager settings
    Source CIDR for RDP and HTTPS Access Allowed Inbound Source Address Range for RDP and HTTPS access to the Manager
    vIPS Controller settings
    Launch External controller? Select Yes do deploy a vIPS External Controller.
    ControllerName Name of the External Controller in the Manager

    Note

    You must use the same controller name while creating the External Controller in the Manager.

    vIPS Controller - Trellix IPS Manager Shared Secret Key Shared secret key used to establish trust between the Controller and the Manager

    Note

    You must use the same shared secret key while creating the External Controller in the Manager.

    Virtual IPS Sensor settings
    ClusterName Name of the Sensor cluster in the Manager

    Note

    You must use the same cluster name while creating the cluster in the Manager.

    ClusterSecret Shared secret key for Manager to establish trust with the Sensor

    Note

    You must use the same shared secret key while creating the cluster in the Manager.

    AutoScaling configuration for virtual IPS Sensor
    Max Size Maximum number of Sensor instances to be launched from the AutoScaling Group
    AutoScaling - Alarm configuration settings [Alarm Metric : CPU]
    CPU Average for Upper Threshold Alarm Average CPU utilization for upper threshold alarm in percentage

    Note

    The value must be a number less than 100.

    CPU Average for Lower Threshold Alarm Average CPU utilization for lower threshold alarm in Percentage

    Note

    The value must be a number less than 100.

    Alarm Monitoring Time Interval Monitoring time interval for the alarm configurations defined for the Sensor

    Note

    The time intervals must be specified in seconds. The default value in 300 seconds.

  13. [Optional] In the Specify Details page, specify the following parameter values:
    Parameter Values
    Tags Tags are arbitrary key-value pairs that can be used to identify your stack for purposes such as cost allocation.
    Permissions An existing AWS Identity and Access Management (IAM) service role that AWS CloudFormation can assume
    Stack policy Defines the resources that you want to protect from unintentional updates during a stack update
    Rollback configuration Specifies alarm for the CFT when creating and using the stack
    Notification options A new or existing Amazon Simple Notification Service topic where notifications about stack events are sent.
    Syack creation options Specifies whether the stack should be rolled back if stack creation fails and prevents a stack from being accidently deleted
  14. Verify the configuration details, select I acknowledge that AWS CloudFormation might create IAM resources with custom names.
  15. Click Create stack.
  16. Once the instances are running, you can access the Manager using the public IP address for the same.

    The default credentials for the Manager application are the following:

    Username: admin

    Password: <Last 6 digit of the Manager instance ID>.

    Note

    The CFT output includes the Manager public IP address and the Manager instance ID required to access the Manager application.

  17. Register the Manager with Trellix. For more information, see Product Registration.
  18. Make sure to configure the Controller and the Cluster in the Manager as described in the Configure a Controller in the Manager and Create a vIPS Cluster for AWS.
  19. Download the Virtual Probe from the Manager and install it in the instances that are to be protected.
    For steps to download Virtual Probe, see Download the Virtual Probe.
    For steps to install Virtual Probe, see Install the Virtual Probe.