As part of Trellix vIPS deployment, you have to launch an instance template of the Virtual IPS Sensor in the GCP environment. The Sensor image is provided to you in a machine image template.
To launch an instance template, follow the steps below:
Note
Sensors can be launched as part of a GCP Auto Scaling group. You should create a Launch Configuration similar to the settings provided below. See Create an auto-scaling group for Virtual IPS Sensors in GCP for more information on how to use sensor auto-scaling.
Log in to the Google Cloud and select Compute Engine.
In the left panel, under Virtual machines, select Instance templates and click create instance template.
The Create an instance template page is displayed.
Name: Define the name for your Manager instance.
Tip
The instance name must begin with a letter. It can contain only lowercase letters and hyphens (-) as special characters.
Location: Select Region and the required region from the drop-down.
Go to Machine configuration and provide the following details:
Go to General purpose tab and select N1 series from the list.
In the PRESET tab of Machine type section, choose n2-standard-8 (8 vCPU, 4 core, 32 GB memory) for IPS-VM600-VSS-SSL Sensor and n1-standard-4 (4 vCPU, 2 core, 15 GB memory) for IPS-VM600-VSS Sensor.
(Optional) Go to Firewall and enable the required firewall rules.
Navigate to the Networking section, (Optional) you can provide the Network tags and Hostname for the network.
Go to Network interfaces section and define the following parameters:
Network: Define the required network from the drop-down.
Subnetwork: Define the appropriate subnetwork from the drop-down.
Network interface card: Select VirtIO from the drop-down.
Navigate to the Security section and expand MANAGE ACCESS drop-down. Now, go to Add manually generated SSH keys and click Add item. Enter the RSA key in the SSH key 1 field.
Navigate to the Management section, go to in Metadata, and click Add item. Now, provide the following details:
Key 1: Enter user-data in the key field.
Value 1: Enter the Sensor user data details.
An example of user data is given below:
{ "Primary Manager IP" : "IPS_PRIMARY_MANAGER_PRIVATE_IP", "Secondary Manager IP" : "IPS_SECONDARY_MANAGER_PRIVATE_IP", "Cluster Name" : "CLUSTER_NAME", "Sensor Shared Key" : "SHARED_KEY", "Traffic Source" : "GCPNSI", "GCP ILB forwarding rule IP": "10.0.0.10" }User data parametersParameters
Description
Primary Manager IPPrimary IP address of the primary Manager
Secondary Manager IPPrivate IP address of the secondary Manager
Cluster NameName of the Cluster in the Manager where the auto scale group will be launched
Sensor Shared KeyShared secret key to establish trust with the Sensor
Traffic SourceType of traffic source used for traffic inspection.
GCP ILB forwarding rule IPLoad balancer IP address or forwarding IP address.
Tip
Only for an MDR pair, the secondary Manager IP is required.
The Sensor Shared Key provided in the Manager must be the same as the Sensor Shared Key provided during Sensor deployment.
Review the configuration details provided for deploying the instance and then click CREATE.
Note
Trellix recommends you reboot the Sensor once it is up and running.