The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Requirements to deploy Trellix vIPS in AWS environment

Prev Next

The following table lists the requirements to deploy Trellix vIPS in the AWS environment.

Requirement Purpose Privileges/ Other requirements
AWS GUI access To launch Trellix vIPS AMIs and configure setup
  • Identify the AMI instance for deployment
  • Identify the instances to be protected
  • Create IAM role to discover AWS instances
  • The IAM role must have permission to launch EC2 instances
AWS access key and secretkey To establish communication between the Trellix IPS Manager and AWS environment

Note

Trellix recommends you to use the IAM role method to establish communication between the Manager and the AWS environment.

Trellix IPS Manager AMI To install the Manager
Controller AMI To install an external Controller
Trellix vIPS instance AMI To install Virtual IPS Sensor
Web server (or) instances to be protected To install vIPS Probes Admin privileges in the Operating System

An IAM role with a minimum of the following permissions must be created. It will be assigned to the Manager/local controller or vIPS External Controller:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeInstances",
                "ec2:DescribeRegions"
            ],
            "Resource": "*"
        }
    ]
} 

The following table lists the requirements of different vIPS solution components for the deployment of Trellix vIPS in the AWS environment.

Component AWS Instance Type Software Requirements Network Requirements Other Requirements
Manager m4.xlarge/c4.xlarge MLOS

1 Network Interface (management subnet)

The instance should be EBS-optimized.
External Controller c4.large Controller AMI

1 Network Interface (management subnet)

The instance should be EBS-optimized.
Sensor c4.xlarge/c5.xlarge Trellix vIPS instance AMI

1 Network Interface (management and data subnet)

Internet access is required to access AWS APIs.
Probe Any Customer Supplied

1 or more (see deployment) Use public IP address or NAT gateway to access Controller EIP

  • No overlapping CIDR blocks across protected VPCs.
  • VPC peering required for the data subnet.
  • Access to the OS distribution repository is required to install vIPS Probe. This can be a local repository or the public Internet.

The following table lists the ports for security group settings required to deploy Trellix vIPS in the AWS environment. For more information about ports used by the IPS, see KB59342.

Ports Purpose Source/Destination
Manager Inbound rules 8501–8504, 8506–8510 TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. Sensor
9798 TCP port used to communicate Probe state and configuration. This is applicable only when the local Controller is used. Probe, Sensor
443 TCP port used for:
  • Controllers to register with the Manager
  • Sensors and Probes to discover registered Controllers
  • Web UI access on the Manager
Sensor, Controller, Probe
22 TCP port used for Manager CLI access (via SSH). ---
3306 TCP port used for database access by External Controllers to store and retrieve Probe data. This is applicable only when an External Controller is used. Controller
Outbound Rules 443 TCP port used by the local Controller to connect to the Amazon EC2 endpoint and discover cloud resources.

This is applicable only when the local Controller is used.

For more information on Amazon EC2 endpoints, refer to the AWS documentation.

EC2 Endpoint
8500 UDP port used by the Manager to make real-time configuration changes on the Sensor. Sensor
Local/External Controller Inbound rules 9798 TCP port used to communicate Probe state and configuration. Sensor, Probe
22 TCP port used for Controller CLI access. ---
Outbound Rules 443 TCP port used to:
  • Register with the Manager
  • Connect to the Amazon EC2 endpoint and discover cloud resources

For more information on Amazon EC2 endpoints, refer to the AWS documentation.

Manager, EC2 Endpoint
3306 TCP port used for database access by External Controllers to store and retrieve Probe data. This is applicable only when an external Controller is used. Manager
Sensor Inbound rules 8500 UDP port used by the Manager to make real-time configuration changes on the Sensor. Manager
9797 UDP port used by Probes to forward traffic to the Sensor for inspection. Probe
22 TCP port used for Sensor CLI access. ---
Outbound Rules 8501-8504, 8506-8510 TCP ports used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. Manager
443 TCP port used to discover registered Controllers. Manager
9798 TCP port used to communicate Probe state and configuration. Controller
Probe Inbound rules No ports required for inbound. --- ---
Outbound Rules 9797 UDP port used by the Probe to forward traffic to Sensors for inspection. Sensor
443 TCP port used to discover registered Controllers and Sensors. Manager
9798 TCP port used to communicate Probe state and configuration. Controller