The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Requirements to deploy Trellix Virtual IPS with Azure Gateway Load Balancer

Prev Next

The following table lists the requirements to deploy vIPS with Azure Gateway Load Balancer

Requirement

Purpose

Role

Azure GUI access

To launch Trellix vIPS and configure setup

Privilege: Contributor

Virtual IPS Sensor

To install a Virtual IPS Sensor

Privilege: Contributor

Gateway Load Balancer

To forward the traffic flow to the Sensor

Privilege: Contributor

Web server (or) Virtual Machines to be protected

---

Privilege: OS Administrator

The following table lists the requirements of vIPS solution components for the deployment of Trellix vIPS in the Azure environment.

Component

Azure Virtual Machine Type

Software Requirements

Network Requirements

Trellix IPS Manager

D2s_v3

Trellix IPS Manager image

1 Network Interface (management subnet)

Virtual IPS Sensor

  • For IPS-VM600-VSS-SSL Sensor, use F8s_v2

  • For other Sensor models, use F4s_v2

Virtual IPS Sensor image

1 Network Interface for both management and data subnet

Protected virtual machines

Any

Customer Supplied

1 or more (see deployment)

The following table lists the ports for network security group settings required to deploy Trellix vIPS in the Azure environment.

Important

For more information about ports and traffic destinations used by Trellix IPS, see KB59342.

Ports

Purpose

Source/ Destination

Manager

Inbound rules

8501–8504, 8506–8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Sensor

443

TCP port used for the Web UI access on the Manager

Sensor

22

TCP port used for Manager CLI access (via SSH).

---

Outbound Rules

8500

UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Sensor

Sensor

Inbound rules

8500

The UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Manager

9001

TCP port used to send Health Check details between Sensor and GWLB.

GWLB

10800, 10801

UDP protocols are used for all internal traffic with a VXLAN header.

GWLB

Outbound Rules

8501-8504, 8506-8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Manager

443

TCP Port is used for vIPS Sensor registration onto the Manager.

Manager

10800, 10801

UDP protocols are used for all internal traffic with a VXLAN header.

GWLB