As part of Trellix vIPS deployment, you have to launch an instance of the Virtual IPS Sensor in the AWS environment. The Sensor image provided to you in the form of an AMI is the template AMI.
Prerequisite:
You must obtain the AMI image by contacting Trellix support with your AWS account number and region name.
Steps:
To launch an instance using the Sensor AMI, perform the following:
Note
Sensors can be launched as part of an AWS Auto Scaling group. You should create a Launch Configuration similar to the settings provided below. See Create an auto-scaling group for Virtual IPS Sensors in AWS for more information on how to use sensor auto-scaling.
Log in to the AWS console, and navigate to Services → Compute → EC2.
In the left panel, under IMAGES, click AMIs.
Search for the AMI Name of the Virtual IPS Sensor (
Trellix_vIPS_Sensor_11.1.7.x) and click Launch.Launch configuration.png)
Provide the Name in Name and tags section. You can also define a tag for your Sensor instance by selecting Add additional tags.
Name and tags.png)
Go to Instance type, and select the instance type as c6i.xlarge.
Instance type details.png)
Go to Key pair (login), you can either choose an existing key pair or create a new key pair. To add an existing key pair, select the required key pair name from the drop-down.
Key pair (login) details.png)
To create a new key pair, select Create a new key pair. A Create key pair dialog box is displayed. Provide the Key pair name, Key pair type as RSA, and Private key file format as .pem. Now, select Create key pair. Ensure to store this key pair in a secured location as you will need this key pair to connect to your instance.
Create key pair dialog box.png)
Note
Even though you provide a key pair, you cannot login to the Sensor instance using the key pair. You should use the Sensor's user account details along with a key pair to login.
Go to Network settings and click Edit. From the VPC - required drop-down, choose the required VPC network and corresponding subnet. You can create a new Security Group to define the firewall rules to control traffic to the Sensor or choose an existing Security group.
Network settings details.png)
Go to Configure storage , provide 1*64 GiB, and select gp2 from Root volume drop-dow.
Configure storage details.png)
Go to Advanced details, and provide the User Data to register the Sensor with the Manager. Login to the required Manager setup. Go to Devices → <Admin Domain Name> → Global → Device Manager. Select the vIPS Clusters tab. Select the hyperlink of a required cluster. The Cluster Details panel will display all Sensor User Data details.
An example of user data is given below:
Sensor User Data: { "Primary Manager IP" : "IPS_PRIMARY_MANAGER_PRIVATE_IP", "Secondary Manager IP" : "IPS_SECONDARY_MANAGER_PRIVATE_IP", "Cluster Name" : "CLUSTER_NAME", "Sensor Shared Key" : "SHARED_KEY", "Traffic Source" : "GWLB" }Note
Only for an MDR pair, the secondary Manager IP is required.
The Sensor Shared Key provided in the Manager must be the same as the Sensor Shared Key provided during Sensor deployment.
User data parametersParameters
Description
Primary Manager IPPrimary IP address of the primary Manager
Secondary Manager IPPrivate IP address of the secondary Manager
Cluster NameName of the Cluster in the Manager where the auto scale group will be launched
Sensor Shared KeyShared secret key to establish trust with the Sensor
Traffic SourceType of traffic source used for traffic inspection.
For more information on User Data, see the section Custom/User data for establishing trust.
Go to Summary, and review the details provided for the creation of the instance. You can either edit specific details or click on Launch instance to launch the Sensor instance.
Summary details.png)