As part of Trellix vIPS deployment, you have to launch an instance of the Virtual IPS Sensor in the AWS environment. The Sensor image provided to you in the form an AMI is the template AMI. To launch an instance using the template AMI, follow the steps below.
Note
Sensors can be launched as part of an AWS Auto Scaling group. You should create a Launch Configuration similar to the settings provided below. See Create an auto scaling group for Virtual IPS Sensors in AWS for more information on how to use sensor auto scaling.
Task
- Log in to the AWS console, and navigate to Services → Compute → EC2.
- In the left panel, under IMAGES, click AMIs.
-
Search for
AMI Name of the Virtual IPS Sensor (Trellix_vIPS_Sensor_10.1.7.x) and click
Launch.
Note
Consider the latest version of Virtual IPS Sensor.
Note
For ease of search, you can filter the images using the 519405898872 Owner ID.
-
Under the
Choose an Instance type step, select the instance type as
c5.xlarge (vCPUs: 4, Memory 8GB), and click
Next: Configure Instance Details.
-
In the
Configure Instance Details step, from the drop-down lists for
Network and
Subnet, choose the Management network and the corresponding subnet.
-
The
User Data to launch the Sensor instance. In the
Advanced area, enter the
User data to register the Sensor with the Manager.
An example for user data is given below:
{"Primary Manager IP" : "IPS_PRIMARY_MANAGER_PRIVATE_IP", "Secondary Manager IP" : "", "Cluster Name" : "CLUSTER_NAME", "Sensor Shared Key" : "SHARED_KEY"}User data parameters Parameters Description Primary Manager IP Primary IP address of the primary Manager Secondary Manager IP Private IP address of the secondary Manager Cluster Name Name of the Cluster in the Manager where the auto scale group will be launched Sensor Shared Key Shared secret key to establish trust with the Sensor For more information on User Data, see the section Custom/User data for establishing trust. -
Under the
Add Storage step, use the default Size (64 GiB), and click
Next: Add Tags.
-
Define a tag for your Sensor instance, and click
Next: Configure Security Group.
-
In the
Configure Security Group page, you can create a new Security Group to define the firewall rules to control traffic to the Sensor or choose an existing Security group.
Once you have configured the Security Group, click on Review and Launch.
-
Under the
Review Instance Launch step, review the details provided for the creation of the instance. You can either edit specific details, or click on
Launch to assign a key pair to your Sensor instance.
-
In the
Select an existing key pair or create a new key pair window, you can either choose an existing key pair or create a new key pair, and click
Launch instances. The instance is now launched.
Note
Even though you provide a key pair, you cannot login to the Sensor instance using the key pair. You should use the Sensor's user account to login.