The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Install the Virtual Probe

Prev Next

The procedure to install a vIPS Probe on your instance is specific to the Operating System running on it. This section provides the installation steps for Linux and Windows instances.

Before you begin

Trellix recommends you to update all the operating system packages before installing vIPS Probe in Windows or Linux machines.

For Linux instances

Before you begin

Ensure that the additional Linux packages are available in the distributed repository and the instances have access to the repository.

vIPS Probe requires jsoncpp library installed on certain Linux instances.

To install the vIPS Probe on your Linux machines, as a root user, follow the steps below.

Task

  1. Move the downloaded Probe Installation Package vIPS_Probe_Linux.tar.gz into an appropriate folder.
  2. To unzip the package, execute the command $ tar xzf vIPS_Probe_Linux.tar.gz
  3. Go to the vIPS agent folder by entering the command cd vIPS_Probe_Linux
  4. Verify the Manager IP address in the ip.txt file.
    When you download the Probe, the ip.txt file automatically contains the private IP address of the Manager. However, if you want to use the public IP address of the Manager, specify the public IP address in the ip.txt file.
  5. To install the package, run the command sudo ./install.sh
    The vIPS Probe is now installed on your Linux machine.
  6. To verify the Probe installation, execute the command service trellix_vips_probe status
  7. (Optional) To start the service after it is stopped, execute the command sudo service trellix_vips_probe start
  8. (Optional) To restart the Probe, execute the command sudo service trellix_vips_probe restart
  9. (Optional) To stop the service, execute the command sudo service trellix_vips_probe stop
  10. To verify if the Probe is successfully installed, perform the following steps:
    1. Click Analysis → Virtual Machines. This displays the Virtual Machines page.
    2. Check the state of the Probe in the State column of vIPS Probe. If the Probe is successfully running, the status is green in color.
      You can also run the stats_client.py script in sudo mode for checking the inspected traffic statistics on the virtual machines. The stats_client.py script is used to confirm and troubleshoot connectivity with the other components. The script displays details, such as Sensor details, inspection mode, and Controller status. Sample output for stats_client.py script is given below:
      Packets read from queue[0]: 561825
      Bytes read from queue[0]: 321796393
      Time waiting for packets from queue(ns): 26871840090079
      Timed out reading packet from queue: 4723
      Packets accepted[0]: 561339
      Packets rejected[0]: 486
      Time spent in verdicting(ns)[0]: 9441122857
      Packets send to node[0]: 561082
      Bytes send to node[0]: 333875820
      Pings sent to node[0]: 11115
      Packets received from node[0]: 560596
      Bytes received from node[0]: 333375590
      Time spent waiting to read from sensor(ns): 26803282492008
      Time receiving packets from node(ns)[0]: 1870116120
      Ping responses received[0]: 11115
      Failed open after sending to sensor: 743
      Queue Number[0]: 1
      Node Address[0]: 10.1.1.1
      Probe Id: f37d39e7-3517-4934-a82a-e5a42b3992e5
      Inspection Mode: ips
      Failure Handling: fail_open
      Control State: CONTROLLER_CONNECTED
      IPv4 packets: 561815
      IPv6 packets: 10
      TCP packets: 556894
      UDP packets: 4921
      Netfilter Queue Statistics
      ==========================
      Q[1]: total pkts = 561082 current queued = 0, q_drops = 0, msg_drops = 0

      Note

      The script requires Python for Windows version 2.x for it to work.

For Windows instances

To install the vIPS Probe on your Windows machines, perform the following steps:

Task

  1. Move the downloaded Probe installation package vIPS_Probe_Windows.zip into an appropriate folder.
  2. Unzip the package.
  3. Open the Windows command prompt with administrator privileges.
  4. Navigate to the vIPS_Probe_Windows folder.
  5. Verify the Manager IP address in the agent.config file.
    When you download the Probe, the primary-nsm property in the agent.config file is automatically set to the private IP address of the Manager. However, if you want to use the public IP address of the Manager, set the primary-nsm property to the public IP address of the Manager.
  6. Run the install.bat aws script to install the vIPS Probe.
    C:\Users\Administrator\Downloads\vIPS_Probe_Windows>install.bat aws
    [SC] OpenService FAILED 1060:
    The specified service does not exist as an installed service.
    McafeeVNSPService is installed.
    [SC] ChangeServiceConfig2 SUCCESS
    [SC] ChangeServiceConfig2 SUCCESS
    The McafeeVNSPService service is starting.
    The McafeeVNSPService service was started successfully.

    Note

    To uninstall the vIPS Probe, run the uninstall.bat script.

    You must run stats_client.py script for checking the inspected traffic statistics on the virtual machines. The stats_client.py script is used to confirm and troubleshoot connectivity with the other components. The script displays details, such as Sensor details, inspection mode, and Controller status. Sample output for stats_client.py script is given below:
    Packets read from queue[0]: 561825
    Bytes read from queue[0]: 321796393
    Time waiting for packets from queue(ns): 26871840090079
    Timed out reading packet from queue: 4723
    Packets accepted[0]: 561339
    Packets rejected[0]: 486
    Time spent in verdicting(ns)[0]: 9441122857
    Packets send to node[0]: 561082
    Bytes send to node[0]: 333875820
    Pings sent to node[0]: 11115
    Packets received from node[0]: 560596
    Bytes received from node[0]: 333375590
    Time spent waiting to read from sensor(ns): 26803282492008
    Time receiving packets from node(ns)[0]: 1870116120
    Ping responses received[0]: 11115
    Failed open after sending to sensor: 743
    Queue Number[0]: 1
    Node Address[0]: 10.1.1.1
    Probe Id: f37d39e7-3517-4934-a82a-e5a42b3992e5
    Inspection Mode: ips
    Failure Handling: fail_open
    Control State: CONTROLLER_CONNECTED
    IPv4 packets: 561815
    IPv6 packets: 10
    TCP packets: 556894
    UDP packets: 4921
    Netfilter Queue Statistics
    ==========================
    Q[1]: total pkts = 561082 current queued = 0, q_drops = 0, msg_drops = 0

    Note

    The script requires Python for Windows version 2.x for it to work.

  7. To verify if the Probe is successfully installed, perform the following steps:
    1. Click Analysis → Virtual Machines. This displays the Virtual Machines page.
    2. Check the state of the Probe in the State column of Virtual Probe. If the Probe is successfully running, the status is green in color.

Deploy vIPS Probes through orchestration methods

Tools like Chef, Puppet, and Ansible can be used to deploy the probes in instances. It can also be installed through Cloud-Init mechanism that runs scripts during instance launch. To use install the probe programmatically through a Linux Shell, perform the following steps:

  1. Download the Probe from Manager using an HTTPS link.
    https://<Manager IP>/intruvert/webservice/api/v1/cloud/controller/agent?ostype=<OS type>

    For example:

    Curl -k: "https://10.1.1.1/intruvert/webservice/api/v1/cloud/controller/agent?ostype=linux" -o vIPS_Probe_Linux.tar.gz --no-check-certificate

    Wget: "https://10.1.1.1/intruvert/webservice/api/v1/cloud/controller/agent?ostype=linux" -O vIPS_Probe_Linux.tar.gz --no-check-certificate

    Where,

    • Manager IP is the Manager's IP address or domain name
    • OS type is Linux or Windows

    Note

    Ensure that the URL is given within double quotation marks. This is to prevent the shell from interpreting characters in the URL.

  2. Install the Probe using the steps described earlier in this section.

    To allow instances to download the probe, you have to open the security group on the Manager to allow inbound connections from your instances.

    The Manager has a limitation on the number of simultaneous downloads of the probe. If the download does not succeed, try again later.