As part of Trellix vIPS deployment, you have to launch an instance of the Controller in the AWS environment. The Controller image is provided to you in the form an AMI. You need the following before launching a Controller instance.
- Security group with the ports opened as specified in Requirements to deploy Trellix IPS in AWS environment
- Shared Secret configured in the Manager for this Controller
To launch an instance using the Controller AMI provided through AWS console, follow the steps below. The instance can be launched through AWS API or CLI using similar steps.
Task
- Log in to the AWS console, and navigate to Services → Compute → EC2.
- In the left panel, under IMAGES, click AMIs.
-
Search for the
AMI Name of the Controller (Trellix_vIPS_Controller_2.3.x) and click
Launch.
Note
For ease of search, you can filter the images using the 519405898872 Owner ID.
-
Under the
Choose an Instance type step, select the instance type as
c4.large (vCPUs: 2, Memory 3.75GB), and click
Next: Configure Instance Details.
-
In the
Next: Configure Instance Details step, from the drop-down lists for
Network and
Subnet, choose the Management network and the corresponding subnet.
- (Optional) If you have not configured NAT, enable Auto-assign Public IP for cloud discovery to succeed.
-
Select the
IAM role for the Controller
-
Make sure EBS-optimized setting is selected.
-
Enter the
User Data to launch the Controller instance. In the
Advanced area, enter the
User data to register the Controller with the Manager.
An example for user data is given below:
{"Primary Manager IP":"IPS_PRIMARY_MANAGER_PRIVATE_IP", "Secondary Manager IP" : "", "Controller Name":"CONTROLLER_NAME", "Controller Shared Key":"SHARED_KEY"}User data parameters Parameters Description Primary Manager IP Private IP address of the primary Manager Secondary Manager IP Private IP address of the secondary Manager Controller Name Name of the Controller defined in the Manager Controller Shared Key Shared secret key of the Controller provided in the Manager For more information on User Data, see the section Custom/User data for establishing trust. -
In the
Add Storage step, use the default size (64 GiB), and click
Next: Add Tags.
-
Define a tag for your Controller instance, and click
Next: Configure Security Group.
-
In the
Configure Security Group step, you can create a new Security Group to define the firewall rules to control traffic to the Controller or choose an existing Security group.
For a Controller HA, you have to enable ports 22, 3306, and 443.Once you have configured the Security Group, click Review and Launch.
-
Under the
Review Instance Launch step, review the details provided for the creation of the instance. You can either edit specific details, or click on
Launch to assign a key pair to your Controller instance.
-
In the
Select an existing key pair or create a new key pair window, you can either choose an existing key pair or create a new key pair, and click
Launch instances. The instance is now launched.
Note
You cannot login to Controller instance even though you provide a key pair.
-
Perform the following steps once the Controller is online on the Controllers tab of the Manager.
- Stop the Controller instance.
- Delete the Controller Shared Key from the user data of the instance.
-
Restart the instance.
Once the Controller starts, it establishes communication with the Manager.