The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Launch the Virtual IPS Sensor AMI instance

Prev Next

As part of Trellix vIPS deployment, you have to launch an instance of the Virtual IPS Sensor in the AWS environment. The Sensor image provided to you in the form of an AMI is the template AMI.

Prerequisite:

You must obtain the AMI image by contacting Trellix support with your AWS account number and region name.

Steps:

To launch an instance using the template AMI, perform the following:

Note

Sensors can be launched as part of an AWS Auto Scaling group. You should create a Launch Configuration similar to the settings provided below. See Create an auto-scaling group for Virtual IPS Sensors in AWS for more information on how to use sensor auto-scaling.

  1. Log in to the AWS console, and navigate to Services → Compute → EC2.

  2. In the left panel, under IMAGES, click AMIs.

  3. Search for the AMI Name of the Virtual IPS Sensor (Trellix_vIPS_Sensor_11.1.7.x) and click Launch.

  4. Under the Choose an Instance type step, select the instance type as c5.xlarge (vCPUs: 4, Memory 8GB), and click Next: Configure Instance Details.

  5. In the Configure Instance Details step, from the drop-down lists for Network and Subnet, choose the Management network and the corresponding subnet.

  6. The User Data to launch the Sensor instance. In the Advanced area, enter the User data to register the Sensor with the Manager.

    An example of user data is given below:

    {
    "Primary Manager IP" : "IPS_PRIMARY_MANAGER_PRIVATE_IP", 
    "Secondary Manager IP" : "IPS_SECONDARY_MANAGER_PRIVATE_IP", 
    "Cluster Name" : "CLUSTER_NAME", 
    "Sensor Shared Key" : "SHARED_KEY",
    "Traffic Source" : "PROBE"
    }

    Note

    • Only for an MDR pair, the secondary Manager IP is required.

    • The Sensor Shared Key provided in the Manager must be the same as Sensor Shared Key provided during Sensor deployment.

    User data parameters

    Parameters

    Description

    Primary Manager IP

    Primary IP address of the primary Manager

    Secondary Manager IP

    Private IP address of the secondary Manager

    Cluster Name

    Name of the Cluster in the Manager where the auto scale group will be launched

    Sensor Shared Key

    Shared secret key to establish trust with the Sensor

    Traffic Source

    Mode of traffic source



    GUID-A0D29576-F4BB-4AC1-8D0D-8D60FA6A1965-low.png

    For more information on User Data, see the section Custom/User data for establishing trust.

  7. Under the Add Storage step, use the default Size (64 GiB), and click Next: Add Tags.

    GUID-BEF819BF-A3D0-436C-B8A9-5FDA57C14C65-low.png
  8. Define a tag for your Sensor instance, and click Next: Configure Security Group.

    GUID-2C0DCFB8-9A79-483E-A34C-C392C72B1A40-low.png
  9. In the Configure Security Group page, you can create a new Security Group to define the firewall rules to control traffic to the Sensor or choose an existing Security group.

    GUID-34EF4F53-A0FE-4261-82F2-1FAEADE436D1-low.png

    Once you have configured the Security Group, click on Review and Launch.

  10. Under the Review Instance Launch step, review the details provided for the creation of the instance. You can either edit specific details, or click on Launch to assign a key pair to your Sensor instance.

    GUID-043E8707-8876-4DAA-AE92-E0171A3CC71E-low.png
  11. In the Select an existing key pair or create a new key pair window, you can either choose an existing key pair or create a new key pair, and click Launch instances. The instance is now launched.

    GUID-2E8FDAA0-6E7A-4A2C-86EC-BB1A6B15F096-low.png

    Note

    Even though you provide a key pair, you cannot login to the Sensor instance using the key pair. You should use the Sensor's user account to login.