The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Requirements to integrate Trellix vIPS with the Network Security Integration In-band in GCP

Prev Next

The following table lists the requirements of different vIPS compute engine types to run Trellix vIPS compute engines.

Component

GCP Compute Engine

Software Requirements

Network Requirements

Manager

n1-standard-4

Manager AMI

1 Network Interface

Sensor

For IPS-VM600-VSS-SSL Sensor, use n2-standard-8

For IPS-VM600-VSS Sensor, use n1-standard-4

Sensor AMI

1 Network Interface

You can find the cost estimates for your deployments from Google Cloud's pricing calculator.

The following section lists the other component requirements to integrate Trellix vIPS with the NSI in-band.

Requirement

Purpose

Privileges/ Other requirements

Healthchecks

Monitors backend security instance health and availability.

Configure a standard load balancer health check.

Internal Passthrough Loadbalancer

Distributes intercepted traffic across backend security appliances.

High availability configuration; requires a frontend IP.

Forwarding Rule

Acts as the entry point for traffic being directed to the load balancer.

Must be associated with the Internal Passthrough NLB.

Intercept Deployment Group

A zonal resource representing the producer's inspection service in a specific zone.

This references the Load Balancer’s forwarding rule.

Intercept Deployment

A global resource that groups multiple zonal intercept deployments for easy consumption.

Used to scale the service across multiple zones.

Intercept Endpoint Group

Expresses the consumer’s intent to route traffic to a specific backend service.

The Endpoint Service is mandatory for specifying the endpoint.

Intercept Endpoint Group Association

Connects the consumer’s VPC network to the producer’s Intercept Endpoint Group.

Required to enable traffic flow from the VPC.

Network Security Profile

Defines specific security parameters or behaviors for the intercepted traffic.

Must be referenced within a Security Profile Group.

Network Security Profile Group

Enables traffic processing based on the associated security profiles.

The Endpoint Service is mandatory for specifying the endpoint.

Network Firewall Policy

A container for the rules that determine which traffic is intercepted.

Applied at the VPC or Organization level.

Network Firewall Policy Rules

Forwards specific traffic flows (matching rules) to the load balancer.

Endpoint Service is mandatory; uses the apply_security_profile_group action.

Network Firewall Policy Association

Links the firewall policy to the target VPC or folder.

Determines the scope of protection.

Network Security Integration In-band

Forwards the actual traffic flow to the Sensor for real-time inspection.

Trellix recommends having at least two availability zones before deployment.

Google Cloud Console

Used to launch Trellix vIPS AMIs and perform the manual setup.

  • Identify the machine image instance for deployment

  • Identify the instances to be protected

Trellix IPS Manager AMI

To deploy the Manager instance

Trellix vIPS Sensor AMI

To deploy the Virtual IPS Sensor instance

The following table lists the ports for firewall rules required to integrate Trellix vIPS with the NSI In-band.

Important

For more information about ports and traffic destinations used by Trellix IPS, see KB59342.

Component

Rules

Ports

Purpose

Source/Destination

Manager

Inbound rules

8501–8504, 8506–8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Sensor

443

TCP port used for web UI access on the Manager.

---

TCP port is used to establish trust between the Manager and the Sensor

Sensor

22

TCP port used for Manager CLI access (via SSH).

Sensor

Outbound Rules

8500

The UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Sensor

Sensor

Inbound rules

8500

The UDP port is used by the Manager to make real-time configuration changes on the Sensor.

Manager

22

TCP port used for Sensor CLI access.

Manager

6081

UDP protocol for all incoming traffic with GENEVE header.

NSI In-band

9001

TCP port used to send Health Check details between the Sensor and internal passthrough network load balancer.

NSI In-band

Outbound Rules

8501-8504, 8506-8510

TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them.

Manager

443

TCP Port is used for vIPS Sensor registration onto the Manager.

Manager