The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to upgrade components deployed in AWS

Prev Next

Prerequisite:

If you have deployed an MDR, suspend the MDR before you upgrade the Manager and resume the MDR after an upgrade.

The following sections describe the procedure to upgrade the components deployed in AWS:

  1. Upgrade the Manager first. In the case of MDR, upgrade both the Managers to the latest Manager version.

    If the Manager is deployed in AWS and you plan to use a Local Controller, an IAM role has to be assigned to the Manager instance for authentication. Assign an IAM role to the Manager if not assigned.

    Traffic inspection continues after the Manager is upgraded to the latest Manager software version even though the Virtual IPS Sensor and vIPS Controller are still running on the older software version.

  2. Upgrade the Controller to the latest version available. To upgrade the controller, you should launch new instances of the controller with the new AMI and existing user data. The old instance of the controller should be deleted.

    After the controller upgrade, the Virtual Probes installed on all the protected virtual machines are automatically upgraded to the latest available version. If the Probes are not automatically upgraded, you must download the Probe upgrade file from the Manager. Copy the upgrade file to the protected virtual machine where the Probe has to be upgraded. Install the Probe with the latest software image. For steps on installing the Probe, see Install the Virtual Probe. For more information on downloading the Probe, see Download the vIPS Probe.

  3. To upgrade a standalone Virtual IPS Sensor, launch a new Sensor instance with latest Sensor software version along the existings user data so that the Sensors are launched in the existing cluster. Terminate the Sensors with older software versions. Signature set upgrade fails for the vIPS Cluster till the older Sensor versions are terminated.

  4. In case of auto scaling group, you must replace the Sensor AMI in the launch configuration.

  5. Once the Sensors are upgraded, verify that the connection between the Sensor and Probe are established.

  6. Verify that the attack detection is successful.