The procedure to install a vIPS Probe on your instance is specific to the Operating System running on it. This section provides the installation steps for Linux and Windows instances.
Prerequisite:
Trellix recommends you to update all the operating system packages before installing vIPS Probe in Windows or Linux machines.
For Linux instances
Prerequisites:
Ensure that the additional Linux packages are available in the distributed repository and the instances have access to the repository.
vIPS Probe requires jsoncpp library installed on certain Linux instances.
To install the vIPS Probe on your Linux machines, as a root user, follow the steps below:
Move the downloaded Probe Installation Package vIPS_Probe_Linux.tar.gz into an appropriate folder.
To unzip the package, execute the command
$ tar xzf vIPS_Probe_Linux.tar.gz.Navigate to the extracted folder and go to the agent directory.
Note
When you download the Probe, the
ip.txtfile within the downloaded folder automatically takes the IP address of the Manager. Open the file and ensure that it contains the private IP address of the Manager.To install the package, run the command
sudo ./install.shThe vIPS Probe is now installed on your Linux machine.
To verify the Probe installation, execute the command
service trellix_vips_probe status(Optional) To start the service after it is stopped, execute the command
sudo service trellix_vips_probe start(Optional) To restart the Probe, execute the command
sudo service trellix_vips_probe restart(Optional) To stop the service, execute the command
sudo service trellix_vips_probe stopTo verify if the Probe is successfully installed, perform the following steps:
Click Analysis → Virtual Machines. This displays the Virtual Machines page.
Check the state of the Probe in the State column of vIPS Probe. If the Probe is successfully running, the status is green in color.
You can also run the
stats_client.pyscript in sudo mode for checking the inspected traffic statistics on the virtual machines. Thestats_client.pyscript is used to confirm and troubleshoot connectivity with the other components. The script displays details, such as Sensor details, inspection mode, and Controller status. Sample output forstats_client.pyscript is given below:Packets read from queue[0]: 561825 Bytes read from queue[0]: 321796393 Time waiting for packets from queue(ns): 26871840090079 Timed out reading packet from queue: 4723 Packets accepted[0]: 561339 Packets rejected[0]: 486 Time spent in verdicting(ns)[0]: 9441122857 Packets send to node[0]: 561082 Bytes send to node[0]: 333875820 Pings sent to node[0]: 11115 Packets received from node[0]: 560596 Bytes received from node[0]: 333375590 Time spent waiting to read from sensor(ns): 26803282492008 Time receiving packets from node(ns)[0]: 1870116120 Ping responses received[0]: 11115 Failed open after sending to sensor: 743 Queue Number[0]: 1 Node Address[0]: 10.1.1.1 Probe Id: f37d39e7-3517-4934-a82a-e5a42b3992e5 Inspection Mode: ips Failure Handling: fail_open Control State: CONTROLLER_CONNECTED IPv4 packets: 561815 IPv6 packets: 10 TCP packets: 556894 UDP packets: 4921 Netfilter Queue Statistics ========================== Q[1]: total pkts = 561082 current queued = 0, q_drops = 0, msg_drops = 0
Note
The script requires Python for Windows version 2.x for it to work.
For Windows instances
To install the vIPS Probe on your Windows machines, perform the following steps:
Move the downloaded Probe installation package vIPS_Probe_Windows.zip into an appropriate folder.
Unzip the package.
Open the Windows command prompt with administrator privileges.
Navigate to the vIPS_Probe_Windows folder.
Note
When you download the Probe, the
agent.configfile within the download folder automatically takes the IP address of the Manager. Open the file and ensure that it contains the private IP address of the Manager.Run the install.bat aws script to install the vIPS Probe.
C:\Users\Administrator\Downloads\vIPS_Probe_Windows>install.bat aws [SC] OpenService FAILED 1060: The specified service does not exist as an installed service. McafeeVNSPService is installed. [SC] ChangeServiceConfig2 SUCCESS [SC] ChangeServiceConfig2 SUCCESS The McafeeVNSPService service is starting. The McafeeVNSPService service was started successfully.
Note
To uninstall the vIPS Probe, run the uninstall.bat script.
You must run
stats_client.pyscript for checking the inspected traffic statistics on the virtual machines. Thestats_client.pyscript is used to confirm and troubleshoot connectivity with the other components. The script displays details, such as Sensor details, inspection mode, and Controller status. Sample output forstats_client.pyscript is given below:Packets read from queue[0]: 561825 Bytes read from queue[0]: 321796393 Time waiting for packets from queue(ns): 26871840090079 Timed out reading packet from queue: 4723 Packets accepted[0]: 561339 Packets rejected[0]: 486 Time spent in verdicting(ns)[0]: 9441122857 Packets send to node[0]: 561082 Bytes send to node[0]: 333875820 Pings sent to node[0]: 11115 Packets received from node[0]: 560596 Bytes received from node[0]: 333375590 Time spent waiting to read from sensor(ns): 26803282492008 Time receiving packets from node(ns)[0]: 1870116120 Ping responses received[0]: 11115 Failed open after sending to sensor: 743 Queue Number[0]: 1 Node Address[0]: 10.1.1.1 Probe Id: f37d39e7-3517-4934-a82a-e5a42b3992e5 Inspection Mode: ips Failure Handling: fail_open Control State: CONTROLLER_CONNECTED IPv4 packets: 561815 IPv6 packets: 10 TCP packets: 556894 UDP packets: 4921 Netfilter Queue Statistics ========================== Q[1]: total pkts = 561082 current queued = 0, q_drops = 0, msg_drops = 0
Note
The script requires Python for Windows version 2.x for it to work.
To verify if the Probe is successfully installed, perform the following steps:
Click Analysis → Virtual Machines. This displays the Virtual Machines page.
Check the state of the Probe in the State column of Virtual Probe. If the Probe is successfully running, the status is green in color.
Deploy vIPS Probes through orchestration methods
Tools like Chef, Puppet, and Ansible can be used to deploy the probes in instances. It can also be installed through Cloud-Init mechanism that runs scripts during instance launch. To use install the probe programmatically through a Linux Shell, perform the following steps:
Download the Probe from Manager using an HTTPS link.
https://<Manager IP>/intruvert/webservice/api/v1/cloud/controller/agent?ostype=<OS type>
For example:
Curl -k: "https://10.1.1.1/intruvert/webservice/api/v1/cloud/controller/agent?ostype=linux" -o vIPS_Probe_Linux.tar.gz --no-check-certificateWget: "https://10.1.1.1/intruvert/webservice/api/v1/cloud/controller/agent?ostype=linux" -O vIPS_Probe_Linux.tar.gz --no-check-certificateWhere,
Manager IP is the Manager's IP address or domain name
OS type is Linux or Windows
Note
Ensure that the URL is given within double quotation marks. This is to prevent the shell from interpreting characters in the URL.
Install the Probe using the steps described earlier in this section.
To allow instances to download the probe, you have to open the security group on the Manager to allow inbound connections from your instances.
The Manager has a limitation on the number of simultaneous downloads of the probe. If the download does not succeed, try again later.