This section discusses the requirements for deploying Virtual Sensors.
Software Version Requirements
The following table provides the compatible versions for the Trellix vIPS deployment in the ESXi server, KVM and public cloud:
Sensor model | Virtual IPS Sensor | Manager |
|---|---|---|
IPS-VM600 | 10.1.7.1, 10.1.7.42, 10.1.7.51, 10.1.7.65, 10.1.7.86, 10.1.7.96, 10.1.7.123, 10.1.7.135, 10.1.7.155, 10.1.7.156 (Cloud) | 10.1.7.7, 10.1.7.29, 10.1.7.35, 10.1.7.40, 10.1.7.44, 10.1.7.50, 10.1.7.55, 10.1.7.61, 10.1.7.65, 10.1.7.66 (Cloud), 10.1.7.66.3, 10.1.7.66.11 |
11.1.7.1, 11.1.7.22, 11.1.7.44, 11.1.7.56, 11.1.7.72, 11.1.7.81, 11.1.7.98, 11.1.7.111, 11.1.7.121, 11.1.7.136, 11.1.7.152 | 11.1.7.3, 11.1.7.3.5, 11.1.7.26, 11.1.7.41, 11.1.7.41.2, 11.1.7.56, 11.1.7.71, 11.1.7.84, 11.1.7.97, 11.1.7.98 (Cloud), 11.1.7.111, 11.1.7.121, 11.1.7.136, 11.1.7.154 | |
IPS-VM5000 | 11.1.7.44, 11.1.7.56, 11.1.7.72, 11.1.7.81, 11.1.7.98, 11.1.7.111, 11.1.7.121, 11.1.7.136, 11.1.7.152 | 11.1.7.41, 11.1.7.41.2, 11.1.7.56, 11.1.7.71, 11.1.7.84, 11.1.7.97, 11.1.7.98 (Cloud), 11.1.7.111, 11.1.7.121, 11.1.7.136, 11.1.7.154 |
IPS-VM600-SSL, IPS-VM5000-SSL and IPS-VM600-VSS-SSL | 11.1.7.121, 11.1.7.136, 11.1.7.152, 11.1.7.167 | 11.1.7.121, 11.1.7.136, 11.1.7.154, 11.1.7.168 |
Note
Virtual IPS Sensor deployments are supported on KVM from 11.1 Update 2 release onwards.
Trellix IPS Manager deployments on KVM are supported from 11.1 Update 4 release onwards.
The following table provides the hardware and server requirements for the Trellix vIPS deployment in the ESXi server and KVM:
Sensor model | Virtualization Platform | Hardware |
|---|---|---|
IPS-VM600 |
|
|
IPS-VM5000 |
|
|
IPS-VM600-SSL |
|
|
IPS-VM600-VSS-SSL | AWS, Azure, and GCP |
|
IPS-VM5000-SSL |
|
|
Note
If you are using a distributed virtual switch, you can install Manager and Sensor only on hosts running ESXi 7.0 Update 3 or later versions.
Other requirements
You need Manager running on version 10.1.7.7 or later for VMware ESXi installed on a virtual or physical machine.
You need Manager running on version 11.1.7.71 or later for KVM installed on a virtual or physical machine.
If you plan to install the Virtual Sensor using an OVA image, you need a VMware vCenter Server. Using the VMware vSphere Client to deploy the Virtual Sensor OVA file is not recommended. For subsequent management of your VMware ESXi server, you might use VMware vSphere Client.
If you plan to install the Sensor using a .qcow image, you need a KVM-based hypervisor.
Follow these guidelines for proxy-based SSL decryption:
The ESXi and KVM CPU version should be Skylake and above.
Fresh OVA image and qcow2 file should be used for deployment.
Add the Serial Port as another device after deploying the Sensor.
Only one SSL license per Virtual IPS Sensor.
While deploying IPS-VM5000-SSL in ESXi:
If the CPU per socket is less than 16, manually update the CPU core.
If the CPU per socket is more than 16, deployed Sensor will use 16 CPU cores.
You require one or more licenses per Virtual IPS Sensor depending on the model. The license is also specific to the Virtual IPS Sensor model you purchased. Make sure you have secured the required number of licenses from Trellix.
Note
IPS-VM600 requires 1 vIPS license while IPS-VM5000 requires 5 vIPS licenses.
You must exclude the Virtual Sensor from the VMware Distributed Resource Scheduler (DRS).
Do not install VMware tools for a Virtual Sensor.
For optimal and predictable performance, follow these guidelines:
You must configure each Virtual Sensor VM to execute on as many cores as required for the Sensor model by assigning CPU affinity to the VM. For instance, an IPS-VM600 VM must be affinitized to 4 logical cores and an IPS-VM5000 VM must be affinitized to 12 logical cores.
No other virtual machines running on the same ESXi host can be allowed to share the CPU cores that are assigned to a Virtual Sensor virtual machine. For example, if there are 16 CPU cores on an ESX server and you deploying IPS-VM600, the Virtual Sensor VM can be affinizied to the first 4 CPUs. All other VMs running on the same ESX server must be excluded from using the first 4 CPUs by affinitizing them to use the remaining CPUs on the host.