The following table lists the requirements to deploy vIPS with Azure Gateway Load Balancer
Requirement | Purpose | Role |
|---|---|---|
Azure GUI access | To launch Trellix vIPS and configure setup | Privilege: Contributor |
Virtual IPS Sensor | To install a Virtual IPS Sensor | Privilege: Contributor |
Gateway Load Balancer | To forward the traffic flow to the Sensor | Privilege: Contributor |
Web server (or) Virtual Machines to be protected | --- | Privilege: OS Administrator |
The following table lists the requirements of vIPS solution components for the deployment of Trellix vIPS in the Azure environment.
Component | Azure Virtual Machine Type | Software Requirements | Network Requirements |
|---|---|---|---|
Trellix IPS Manager | D2s_v3 | Trellix IPS Manager image | 1 Network Interface (management subnet) |
Virtual IPS Sensor |
| Virtual IPS Sensor image | 1 Network Interface for both management and data subnet |
Protected virtual machines | Any | Customer Supplied | 1 or more (see deployment) |
The following table lists the ports for network security group settings required to deploy Trellix vIPS in the Azure environment.
Important
For more information about ports and traffic destinations used by Trellix IPS, see KB59342.
Ports | Purpose | Source/ Destination | ||
|---|---|---|---|---|
Manager | Inbound rules | 8501–8504, 8506–8510 | TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Sensor |
443 | TCP port used for the Web UI access on the Manager | Sensor | ||
22 | TCP port used for Manager CLI access (via SSH). | --- | ||
Outbound Rules | 8500 | UDP port is used by the Manager to make real-time configuration changes on the Sensor. | Sensor | |
Sensor | Inbound rules | 8500 | The UDP port is used by the Manager to make real-time configuration changes on the Sensor. | Manager |
9001 | TCP port used to send Health Check details between Sensor and GWLB. | GWLB | ||
10800, 10801 | UDP protocols are used for all internal traffic with a VXLAN header. | GWLB | ||
Outbound Rules | 8501-8504, 8506-8510 | TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Manager | |
443 | TCP Port is used for vIPS Sensor registration onto the Manager. | Manager | ||
10800, 10801 | UDP protocols are used for all internal traffic with a VXLAN header. | GWLB |