The following table lists the requirements to deploy Trellix vIPS in the AWS environment.
Requirement | Purpose | Privileges/ Other requirements |
|---|---|---|
AWS GUI access | To launch Trellix vIPS AMIs and configure setup |
|
AWS access key and secretkey | To establish communication between the Trellix IPS Manager and AWS environment
| |
Trellix IPS Manager AMI | To install the Manager | |
Controller AMI | To install an external Controller | |
Trellix vIPS instance AMI | To install Virtual IPS Sensor | |
Web server (or) instances to be protected | To install vIPS Probes | Admin privileges in the Operating System |
An IAM role with a minimum of the following permissions must be created. It will be assigned to the Manager/local controller or vIPS External Controller:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"ec2:DescribeInstances",
"ec2:DescribeRegions"
],
"Resource": "*"
}
]
}
The following table lists the requirements of different vIPS solution components for the deployment of Trellix vIPS in the AWS environment.
Component | AWS Instance Type | Software Requirements | Network Requirements | Other Requirements |
|---|---|---|---|---|
Manager | c7i.2xlarge | Manager AMI | 1 Network Interface (management subnet) | The instance should be EBS-optimized. |
External Controller | c5.xlarge or m5.xlarge | Controller AMI | 1 Network Interface (management subnet) | The instance should be EBS-optimized. |
Sensor | c5.xlarge or c6i.xlarge | Trellix vIPS instance AMI | 1 Network Interface (management and data subnet) | |
Probe | Any | Customer Supplied | 1 or more (see deployment) Use public IP address or NAT gateway to access Controller EIP |
|
The following table lists the ports for security group settings required to deploy Trellix vIPS in the AWS environment.
Important
For more information about ports and traffic destinations used by Trellix IPS, see KB59342.
Ports | Purpose | Source/Destination | ||
|---|---|---|---|---|
Manager | Inbound rules | 8501–8504, 8506–8510 | TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Sensor |
9798 | TCP port used to communicate Probe state and configuration. This is applicable only when the local Controller is used. | Probe, Sensor | ||
443 | TCP port used for:
| Sensor, Controller, Probe | ||
22 | TCP port used for Manager CLI access (via SSH). | --- | ||
3306 | TCP port used for database access by External Controllers to store and retrieve Probe data. This is applicable only when an External Controller is used. | Controller | ||
Outbound Rules | 443 | TCP port used by the local Controller to connect to the Amazon EC2 endpoint and discover cloud resources. This is applicable only when the local Controller is used. For more information on Amazon EC2 endpoints, refer to the AWS documentation. | EC2 Endpoint | |
8500 | UDP port used by the Manager to make real-time configuration changes on the Sensor. | Sensor | ||
Local/External Controller | Inbound rules | 9798 | TCP port used to communicate Probe state and configuration. | Sensor, Probe |
22 | TCP port used for Controller CLI access. | --- | ||
Outbound Rules | 443 | TCP port used to:
For more information on Amazon EC2 endpoints, refer to the AWS documentation. | Manager, EC2 Endpoint | |
3306 | TCP port used for database access by External Controllers to store and retrieve Probe data. This is applicable only when an external Controller is used. | Manager | ||
Sensor | Inbound rules | 8500 | UDP port used by the Manager to make real-time configuration changes on the Sensor. | Manager |
9797 | UDP port used by Probes to forward traffic to the Sensor for inspection. | Probe | ||
22 | TCP port used for Sensor CLI access. | --- | ||
Outbound Rules | 8501-8504, 8506-8510 | TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Manager | |
443 | TCP port used to discover registered Controllers. | Manager | ||
9798 | TCP port used to communicate Probe state and configuration. | Controller | ||
Probe | Inbound rules | No ports required for inbound. | --- | --- |
Outbound Rules | 9797 | UDP port used by the Probe to forward traffic to Sensors for inspection. | Sensor | |
443 | TCP port used to discover registered Controllers and Sensors. | Manager | ||
9798 | TCP port used to communicate Probe state and configuration. | Controller |
.png)