The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Requirements to integrate Trellix vIPS with AWS Gateway Load Balancer Traffic Mirroring

Prev Next

The following table lists the requirements of different vIPS instance types to run Trellix vIPS instances.

Component

AWS Instance Type

Software Requirements

Network Requirements

Manager

c7i.2xlarge

Manager AMI

1 Network Interface

Sensor

c6i.xlarge or c7i.xlarge

Sensor AMI

1 Network Interface

You can find the cost estimates for your deployments from My Estimate.

The following section lists the other component requirements to integrate Trellix vIPS with AWS GWLB traffic mirroring.

Requirement

Purpose

Privileges/ Other requirements

Endpoint Service

To create an endpoint

  • Specify the subnets

  • Specify the Loadbalancer type as Gateway

Endpoint

To forward the traffic flow to the load balancer

To specify the Endpoint, Endpoint Service is mandatory

Gateway Load Balancer

To forward the traffic flow to the Sensor

Trellix recommends you have at least two availability zones before deployment

Target group

To register the required Sensor to receive traffic

The Sensor should use the same VPC as the Manager

Traffic Mirroring

To forward the traffic flow from source to destination

Tip

  • Traffic Mirroring is available only on the following non-Nitro instance types: C4, D2, G3, G3s, H1, I3, M4, P2, P3, R4, X1, and X1e.

  • Proxy-based SSL decryption is not supported.

AWS GUI access

To launch Trellix vIPS AMIs and configure setup

  • Identify the AMI instance for deployment

  • Identify the instances to be protected

  • To create and manage resources in AWS you require any of the following:

    • IAM (Identity and Access Management) user account with appropriate permissions

    • AWS access key and secret key

Trellix IPS Manager AMI

To deploy the Manager instance

Trellix vIPS Sensor AMI

To deploy the Virtual IPS Sensor instance

The following table lists the ports for security group settings required to integrate Trellix vIPS with AWS GWLB traffic mirroring.

Important

For more information about ports and traffic destinations used by Trellix IPS, see KB59342.

Component

Rules

Ports

Purpose

Source/Destination

Manager

Inbound rules

8501–8504, 8506–8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Sensor

443

TCP port used for web UI access on the Manager.

---

TCP port is used to establish trust between the Manager and the Sensor

Sensor

22

TCP port used for Manager CLI access (via SSH).

Sensor

Outbound Rules

8500

The UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Sensor

Sensor

Inbound rules

8500

The UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Manager

22

TCP port used for Sensor CLI access.

Manager

6081

UDP protocol for all incoming traffic with GENEVE header.

GWLB

9001

TCP port used to send Health Check details between Sensor and GWLB.

GWLB

Outbound Rules

8501-8504, 8506-8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Manager

443

TCP Port is used for vIPS Sensor registration onto the Manager.

Manager