The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Install a Virtual IPS Sensor through the KVM user interface

Prev Next

The following steps describe how to install a Virtual IPS Sensor through the KVM user interface:

  1. Log on to the Linux server user interface using the IP address and the credentials.

  2. Launch the virt-manager application by executing the virt-manager command through the server's command line terminal.

    Note

    It is recommended to use MobaXterm for remotely accessing the virtual machine manager.

    It will direct you to a UI prompt where you can create the required virtual machine. If you have any instances running, you see these instances listed in this window.

    GUID-16C7F29E-14CB-4BD8-BC82-131169B1B057-low.png
  3. Click the GUID-0186445C-CBEA-4DFB-9806-66D05AAA4DB8-low.png icon to create a new virtual machine.

    The Create a new virtual machine wizard window appears.

  4. In Step 1 of the wizard, you will be choosing the operating system (OS) installation format and the Architecture. Since you are installing the operating system from an image, you need to select the Import existing disk image radio button.

  5. Click Forward to proceed to Step 2 of the wizard.

    GUID-7F2C203B-4510-4604-9FEB-101D7E2952CF-low.png

    In Step 2, you will be setting the:

    • Path where the image file is located

    • OS type

    • OS Version

  6. From the OS type drop-down list, select Linux.

  7. From the Version drop-down list, select Fedora Rawhide.

  8. Browse to the location where the Virtual IPS Sensor image is placed and select the .qcow image. Upon selecting the image, click Forward.

    Note

    Trellix recommends that you place the software image in a folder other than the root folder.

    GUID-A523A1B3-E1D3-404E-9802-AD373F697CBE-low.png

    You come to Step 3 in the deployment where you will be setting the memory and CPU requirements for the Virtual IPS Sensor.

  9. Manually enter the Memory (RAM) and the number of CPUs required.

    For memory and CPU requirements of each Virtual IPS Sensor model, refer the section Requirements for deploying the Virtual Sensor.

  10. Click Forward to proceed to Step 4.

    GUID-320DF44A-38C8-48A5-8251-83575FFC5A57-low.png
  11. In Step 4 of the wizard:

    1. Enter a name for the Virtual IPS Sensor.

    2. Select the Customize configuration before install checkbox.

    3. Expand the Network selection option.

    4. Click the Network selection drop-down list and select Specify shared device name.

      Note

      This option is meant to specify a shared device which facilitates communication with the Virtual IPS Sensor management port.

    5. Specify a dummy name for the bridge network in the Bridge Name field. You may edit this value post virtual machine creation.

      Note

      This network interface acts as the primary interface for connecting to the Management port of the Sensor.

  12. Click Finish to apply all the changes.

    GUID-BAF2E8E4-3010-4763-81D3-28910F0DA99C-low.png

    You are routed to the next step in the deployment where you can review the entire configuration tab-by-tab.

  13. The configuration wizard appears with the Overview tab selected by default. This tab displays the basic configuration details of the VM.

    1. Make sure that the Hypervisor is KVM and the Architecture is x86_64.

    2. From the Firmware drop-down list, make sure BIOS is selected.

      GUID-08C201D7-8018-4345-8BEA-24D9AC054DD3-low.png
  14. Click the CPUs tab.

    1. Make sure that the Current and Maximum allocations of CPUs are set to:

      • 4 if you are installing IPS-VM600

      • 12 if you are installing IPS-VM5000

    2. Under the Configuration section, click on the Model drop-down list and select Westmere.

    3. Expand Topology, select the Manually set CPU topology checkbox and make sure that the number of Sockets is 1, Cores are 4 or 12 depending on the Sensor model, and Threads is 1 for better performance.

    4. Click Apply to confirm your changes.

      GUID-927076BA-3740-4BDB-8FA6-F6AC9C36DA53-low.png
  15. Click the Virtio Disk 1 tab.

    1. Expand the Advanced options tab. From the Disk bus drop-down list, select IDE.

    2. Leave the other options set to default and click Apply to confirm your changes.

    3. GUID-43B2EBCC-860C-4FB6-982F-8B815F5F6FED-low.png
  16. Click the NIC tab.

    1. From the Device model drop-down list, select virtio and click Apply to confirm your changes. You may edit the Bridge name if needed.

      GUID-95868856-6070-4C6A-A500-F724D4244325-low.png
  17. Click Add Hardware button.

    The Add New Virtual Hardware wizard appears. You require additional NICs (beyond the management NIC) for a Virtual IPS Sensor to function normally.

    1. Click the Network tab.

    2. Choose any Network source from the drop-down menu. Enter Bridge name if required.

    3. Make sure that MAC address check box is selected.

    4. Click Finish to confirm your changes. You can modify the interfaces post virtual machine creation by editing the machine's XML configuration file.

      GUID-35D85E1D-6233-4E0F-A533-3C0216C07E8F-low.png
  18. A new NIC with a MAC address appears in the menu on the left. The MAC address in the menu refers to that of the Virtual IPS Sensor interface.

  19. Follow this procedure and create another Six NICs. You are creating a total number of 8 NICs. These 8 NICs are associated with 8 ports of the Sensor — 1 Management port, 1 Response port, and 6 Monitoring ports (3 port pairs) respectively.

    GUID-1A7857FE-6B94-46E1-B75A-9B6C2B8299E0-low.png
  20. Click Begin Installation.

    Creation of the Virtual IPS Sensor virtual machine begins. This process takes a few minutes.

  21. After installation of the Virtual IPS Sensor, you are routed to the login prompt for the Virtual IPS Sensor CLI. Shut down the machine and edit the XML configuration file of the using a command line utility such as vi.

  22. Refer to the Sample XML file and update the Sensor virtual machine configuration file by - assigning the available cores, updating the Sensor ports to map to vhostuser interface, updating the cpu mode, and the hugepage size.

  23. Upon saving the file changes, restart the virtual machine for the changes to take place. To restart, issue the commands virsh destroy <VM_NAME> and virsh start <VM_NAME>, where <VM_NAME> denotes the name of the Sensor virtual machine.

  24. Provide default credentials (admin/admin123) for the Virtual IPS Sensor and set it up like you would on any other IPS Sensor.

  25. When you are in the Sensor CLI, you can execute the command show mgmtport to view the management port details along with the MAC address. You can refer to this MAC address to map the Sensor port to the interface in the Virtual Machine Manager configuration window.

    For example, command to view the Management port details:

    intruShell@kvm> show mgmtport

    Port MAC Address : 52:54:00:f4:f7:c4

    MGMT port Link Status : link up

    MGMT port Additional Info : Network adapter 1

    Similarly, you can execute the command show intfport <port> to view the interface port details along with the MAC address. You can refer to this MAC address to map the Sensor port to the interface in the Virtual Machine Manager configuration window.

    For example, Command to view the Interface port 1 details:

    intruShell@kvm> show intfport 1

    ----------------------

    Administrative Status : ENABLED

    Operational Status : UP

    Operating Mode : INLINE_FAIL_OPEN_ACTIVE

    Port Connected to : INSIDE

    Additional Porttype Info: Network adapter 3

    Total Packets Received : 0

    Total Bytes Received : 0

    Total Errors Rcvd : 0

    Total Packets Sent : 0

    Total Bytes Sent : 0

    Total Errors Sent : 0

    Flow Control Status : OFF

    Port MAC Address : 52:54:00:76:0d:53

    Fail-Open Switch : ABSENT

    Fail-Open Port : ABSENT

Result: After you complete the setup of the Virtual IPS Sensor, you will be able to assign it to a Manager. Managing the Virtual IPS Sensor through the Manager is the same as managing any other Sensor.