The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

High-level steps for configuring Trellix vIPS in AWS environment

Prev Next

We assume that your VPCs and Availability Zones are configured in line with your organization's requirement. The Virtual IPS Sensor can be installed in the same VPC as your instances or in a separate VPC. Before installing the Manager, ensure that you have selected the appropriate region in the AWS console.

For recommendations on the various deployment options, see the topic Use case scenarios.

This section provides the high-level steps for deploying individual Trellix vIPS components in AWS environment.

Note

For an existing deployment, you will need to redeploy the solution due to design change for the Controller and vIPS Probe components. Any upgrade is not supported.

Recommendation for deployment:

  • It is recommended that you follow the steps below to configure Trellix vIPS in AWS environment. After installing the Manager, you can deploy any of the remaining components.
  • Trellix recommends you to deploy the Sensor in the same Availability Zone or Region as your instances that are to be secured.
  • For each account you wish to secure, Trellix recommends you to create a separate protected group for different accounts. In the event of an attack, this will help in identifying the account that was attacked.
  1. Launch the Trellix IPS Manager instance with the appropriate role.
  2. Create Protected Groups for instances.
  3. Configure Local Controller or External Controller based on your requirement for the Protected Group.
  4. Configure a Cluster for a Protected Group.
  5. Configure Cloud Account in Controller for AWS Cloud Discovery.
  6. (Optional) Launch an External Controller if you have configured the External Controller.
  7. Launch the Virtual IPS Sensor instance.
  8. Once the Sensor instance is active, download and Install vIPS Probe.
  9. Validate your deployment.
  10. Repeat steps 2-7 in any order to complete the desired deployment.