The following steps describe how to install a Virtual IPS Sensor through the KVM user interface:
Log on to the Linux server user interface using the IP address and the credentials.
Launch the virt-manager application by executing the
virt-managercommand through the server's command line terminal.Note
It is recommended to use MobaXterm for remotely accessing the virtual machine manager.
It will direct you to a UI prompt where you can create the required virtual machine. If you have any instances running, you see these instances listed in this window.
.png)
Click the
icon to create a new virtual machine.The Create a new virtual machine wizard window appears.
In Step 1 of the wizard, you will be choosing the operating system (OS) installation format and the Architecture. Since you are installing the operating system from an image, you need to select the Import existing disk image radio button.
Click Forward to proceed to Step 2 of the wizard.
.png)
In Step 2, you will be setting the:
Path where the image file is located
OS type
OS Version
From the OS type drop-down list, select Linux.
From the Version drop-down list, select Fedora Rawhide.
Browse to the location where the Virtual IPS Sensor image is placed and select the .qcow image. Upon selecting the image, click Forward.
Note
Trellix recommends that you place the software image in a folder other than the root folder.
.png)
You come to Step 3 in the deployment where you will be setting the memory and CPU requirements for the Virtual IPS Sensor.
Manually enter the Memory (RAM) and the number of CPUs required.
For memory and CPU requirements of each Virtual IPS Sensor model, refer the section Requirements for deploying the Virtual Sensor.
Click Forward to proceed to Step 4.
.png)
In Step 4 of the wizard:
Enter a name for the Virtual IPS Sensor.
Select the Customize configuration before install checkbox.
Expand the Network selection option.
Click the Network selection drop-down list and select Specify shared device name.
Note
This option is meant to specify a shared device which facilitates communication with the Virtual IPS Sensor management port.
Specify a dummy name for the bridge network in the Bridge Name field. You may edit this value post virtual machine creation.
Note
This network interface acts as the primary interface for connecting to the Management port of the Sensor.
Click Finish to apply all the changes.
.png)
You are routed to the next step in the deployment where you can review the entire configuration tab-by-tab.
The configuration wizard appears with the Overview tab selected by default. This tab displays the basic configuration details of the VM.
Make sure that the Hypervisor is KVM and the Architecture is x86_64.
From the Firmware drop-down list, make sure BIOS is selected.
.png)
Click the CPUs tab.
Make sure that the Current and Maximum allocations of CPUs are set to:
4 if you are installing IPS-VM600
12 if you are installing IPS-VM5000
Under the Configuration section, click on the Model drop-down list and select Westmere.
Expand Topology, select the Manually set CPU topology checkbox and make sure that the number of Sockets is
1, Cores are4or12depending on the Sensor model, and Threads is1for better performance.Click Apply to confirm your changes.
.png)
Click the Virtio Disk 1 tab.
Expand the Advanced options tab. From the Disk bus drop-down list, select IDE.
Leave the other options set to default and click Apply to confirm your changes.
.png)
Click the NIC tab.
From the Device model drop-down list, select virtio and click Apply to confirm your changes. You may edit the Bridge name if needed.
.png)
Click Add Hardware button.
The Add New Virtual Hardware wizard appears. You require additional NICs (beyond the management NIC) for a Virtual IPS Sensor to function normally.
Click the Network tab.
Choose any Network source from the drop-down menu. Enter Bridge name if required.
Make sure that MAC address check box is selected.
Click Finish to confirm your changes. You can modify the interfaces post virtual machine creation by editing the machine's XML configuration file.
.png)
A new NIC with a MAC address appears in the menu on the left. The MAC address in the menu refers to that of the Virtual IPS Sensor interface.
Follow this procedure and create another Six NICs. You are creating a total number of 8 NICs. These 8 NICs are associated with 8 ports of the Sensor — 1 Management port, 1 Response port, and 6 Monitoring ports (3 port pairs) respectively.
.png)
Click Begin Installation.
Creation of the Virtual IPS Sensor virtual machine begins. This process takes a few minutes.
After installation of the Virtual IPS Sensor, you are routed to the login prompt for the Virtual IPS Sensor CLI. Shut down the machine and edit the XML configuration file of the using a command line utility such as
vi.Refer to the Sample XML file and update the Sensor virtual machine configuration file by - assigning the available cores, updating the Sensor ports to map to vhostuser interface, updating the cpu mode, and the hugepage size.
Upon saving the file changes, restart the virtual machine for the changes to take place. To restart, issue the commands
virsh destroy <VM_NAME>andvirsh start <VM_NAME>, where<VM_NAME>denotes the name of the Sensor virtual machine.Provide default credentials (admin/admin123) for the Virtual IPS Sensor and set it up like you would on any other IPS Sensor.
When you are in the Sensor CLI, you can execute the command
show mgmtportto view the management port details along with the MAC address. You can refer to this MAC address to map the Sensor port to the interface in the Virtual Machine Manager configuration window.For example, command to view the Management port details:
intruShell@kvm> show mgmtportPort MAC Address : 52:54:00:f4:f7:c4MGMT port Link Status : link upMGMT port Additional Info : Network adapter 1Similarly, you can execute the command
show intfport <port>to view the interface port details along with the MAC address. You can refer to this MAC address to map the Sensor port to the interface in the Virtual Machine Manager configuration window.For example, Command to view the Interface port 1 details:
intruShell@kvm> show intfport 1----------------------Administrative Status : ENABLEDOperational Status : UPOperating Mode : INLINE_FAIL_OPEN_ACTIVEPort Connected to : INSIDEAdditional Porttype Info: Network adapter 3Total Packets Received : 0Total Bytes Received : 0Total Errors Rcvd : 0Total Packets Sent : 0Total Bytes Sent : 0Total Errors Sent : 0Flow Control Status : OFFPort MAC Address : 52:54:00:76:0d:53Fail-Open Switch : ABSENTFail-Open Port : ABSENT
Result: After you complete the setup of the Virtual IPS Sensor, you will be able to assign it to a Manager. Managing the Virtual IPS Sensor through the Manager is the same as managing any other Sensor.