The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Hybrid deployment for Trellix vIPS

Prev Next

Organizations deploy hybrid cloud architectures to maintain consistent security across physical data centers and cloud environments. The Trellix Virtual Intrusion Prevention System (vIPS) bridges this gap by delivering advanced threat detection, real-time deep-packet inspection, and proactive network defenses tailored for dynamic infrastructures.

Scenario 1: On-Premises Sensor Managed by Cloud-Hosted Manager

An enterprise hosts its primary Trellix vIPS Manager in a cloud environment (e.g., AWS) while maintaining physical or virtual IPS Sensors on-premises to monitor local data center traffic.

  • Configuration on Manager: The administrator logs into the cloud-hosted Trellix OS Manager console, navigates to the Device Manager page, and creates an entry for the on-premises sensor using its details (e.g., IP address, sensor name). During this process, a shared secret key is generated.

  • Trust Establishment on Sensor: The administrator opens the local sensor's Command Line Interface (CLI) on-premises and executes the trust command using the generated shared secret key. This establishes an encrypted control channel between the local sensor and the cloud-hosted Manager.

Scenario 2: Cloud Sensor Managed by On-Premises Manager

A customer maintains a central Trellix IPS Manager on a dedicated physical appliance or virtual machine within an on-premises data center, but deploys virtual IPS (vIPS) Sensors in AWS to protect cloud workloads.

  • Cluster Creation on Manager: The administrator logs into the on-premises Manager console and creates a new vIPS Sensor cluster designated for the AWS environment. Upon saving the configuration, the Manager generates a unique User Data script containing activation parameters, IP configurations, and trust keys.

  • AWS Sensor Provisioning: The administrator copies the User Data block from the on-premises Manager and pastes it directly into the AWS EC2 instance deployment configuration (Instance Details → User Data) when launching the vIPS Sensor AMI.

The following is a high-level procedure that you can consider for hybrid deployment for Trellix vIPS:

  1. Verify system requirements and Gateway Load Balancer (GWLB) parameters. For details, see Trellix IPS Sensor instance requirements and Requirements to integrate Trellix vIPS with AWS Gateway Load Balancer.

  2. Configure ports and security groups. For details, see Requirements to integrate Trellix vIPS with AWS Gateway Load Balancer

  3. To create a protected group for the AWS cloud, see Create a protected group for the AWS cloud.

  4. Install the Trellix OS Manager. For installation, refer to Launch a virtual instance of the Manager on Trellix OS.

  5. Install the virtual IPS Sensor. For installation, refer to Launch the Virtual IPS Sensor.

  6. Add a Sensor to the Manager. For more details, see Add a Sensor to the Manager.

  7. Add a Virtual Sensor in the Manager. For more details, see the section Add the Virtual Sensor in the Manager.

  8. To launch an instance of the Virtual IPS Sensor in the AWS environment, see Launch the Virtual IPS Sensor AMI instance.