As part of Trellix vIPS deployment, you have to launch an instance of the Controller in the AWS environment. The Controller image is provided to you in the form of an AMI.
You need the following before launching a Controller instance:
Security group with the ports opened as specified in Requirements to deploy Trellix IPS in AWS environment
Shared Secret configured in the Manager for this Controller
The instance can be launched through AWS API or CLI using the below steps. To launch an instance using the Controller AMI provided through the AWS console, perform the following:
Log in to the AWS console, and navigate to Services → Compute → EC2.
In the left panel, under IMAGES, click AMIs.
Search for the AMI Name of the Controller (
Trellix_vIPS_Controller_2.5.x) and click Launch instance from AMI.Note
For ease of search, you can filter the images using the
519405898872Owner ID.Define a name and tag for your Controller instance under Name and tags.
Go to Instance type, select the instance type as c5.xlarge (vCPUs: 4, Memory 8GiB) or m5.xlarge (vCPUs: 4, Memory 16GiB).
Go to Key pair (login), you can either choose an existing key pair or create a new key pair.
Note
You cannot login to Controller instance even though you provide a key pair.
Go to Network settings and click Edit. Select the required VPC and Subnet from drop-down.
(Optional) If you have not configured NAT, enable Auto-assign Public IP for cloud discovery to succeed.
In the Firewall (security groups), you can create a new Security Group to define the firewall rules to control traffic to the Controller or choose an existing Security group.
For a Controller HA, you have to enable ports 22, 3306, and 443.
Go to Configure storage, use the default size (64 GiB).
Go to Advanced details, provide the required IAM role in the IAM instance profile for the Controller. Also, ensure EBS-optimized instance is enabled.
In the Advanced details, go to User Data and enter the User data to register the Controller with the Manager.
An example for user data is given below:
{ "Primary Manager IP":"IPS_PRIMARY_MANAGER_PRIVATE_IP", "Secondary Manager IP" : "", "Controller Name":"CONTROLLER_NAME", "Controller Shared Key":"SHARED_KEY" }User data parametersParameters
Description
Primary Manager IPPrivate IP address of the primary Manager
Secondary Manager IPPrivate IP address of the secondary Manager
Controller NameName of the Controller defined in the Manager
Controller Shared KeyShared secret key of the Controller provided in the Manager
For more information on User Data, see the section Custom/User data for establishing trust.
Go to Summary, review the details provided for the creation of the instance. You can edit the details by selecting the hyperlink. Click Launch instance to launch the Controller instance.
When the Controller is online on the Controllers tab of the Manager, perform the following steps:
Stop the Controller instance.
Delete the Controller Shared Key from the user data of the instance.
Restart the instance.
Once the Controller starts, it establishes communication with the Manager.