The following table lists the requirements of different vIPS compute engine types to run Trellix vIPS compute engines.
Component | GCP Compute Engine | Software Requirements | Network Requirements |
|---|---|---|---|
Manager | n1-standard-4 | Manager AMI | 1 Network Interface |
Sensor | For IPS-VM600-VSS-SSL Sensor, use n2-standard-8 For IPS-VM600-VSS Sensor, use n1-standard-4 | Sensor AMI | 1 Network Interface |
You can find the cost estimates for your deployments from Google Cloud's pricing calculator.
The following section lists the other component requirements to integrate Trellix vIPS with the NSI in-band.
Requirement | Purpose | Privileges/ Other requirements |
|---|---|---|
Healthchecks | Monitors backend security instance health and availability. | Configure a standard load balancer health check. |
Internal Passthrough Loadbalancer | Distributes intercepted traffic across backend security appliances. | High availability configuration; requires a frontend IP. |
Forwarding Rule | Acts as the entry point for traffic being directed to the load balancer. | Must be associated with the Internal Passthrough NLB. |
Intercept Deployment Group | A zonal resource representing the producer's inspection service in a specific zone. | This references the Load Balancer’s forwarding rule. |
Intercept Deployment | A global resource that groups multiple zonal intercept deployments for easy consumption. | Used to scale the service across multiple zones. |
Intercept Endpoint Group | Expresses the consumer’s intent to route traffic to a specific backend service. | The Endpoint Service is mandatory for specifying the endpoint. |
Intercept Endpoint Group Association | Connects the consumer’s VPC network to the producer’s Intercept Endpoint Group. | Required to enable traffic flow from the VPC. |
Network Security Profile | Defines specific security parameters or behaviors for the intercepted traffic. | Must be referenced within a Security Profile Group. |
Network Security Profile Group | Enables traffic processing based on the associated security profiles. | The Endpoint Service is mandatory for specifying the endpoint. |
Network Firewall Policy | A container for the rules that determine which traffic is intercepted. | Applied at the VPC or Organization level. |
Network Firewall Policy Rules | Forwards specific traffic flows (matching rules) to the load balancer. | Endpoint Service is mandatory; uses the apply_security_profile_group action. |
Network Firewall Policy Association | Links the firewall policy to the target VPC or folder. | Determines the scope of protection. |
Network Security Integration In-band | Forwards the actual traffic flow to the Sensor for real-time inspection. | Trellix recommends having at least two availability zones before deployment. |
Google Cloud Console | Used to launch Trellix vIPS AMIs and perform the manual setup. |
|
Trellix IPS Manager AMI | To deploy the Manager instance | |
Trellix vIPS Sensor AMI | To deploy the Virtual IPS Sensor instance |
The following table lists the ports for firewall rules required to integrate Trellix vIPS with the NSI In-band.
Important
For more information about ports and traffic destinations used by Trellix IPS, see KB59342.
Component | Rules | Ports | Purpose | Source/Destination |
|---|---|---|---|---|
Manager | Inbound rules | 8501–8504, 8506–8510 | TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Sensor |
443 | TCP port used for web UI access on the Manager. | --- | ||
TCP port is used to establish trust between the Manager and the Sensor | Sensor | |||
22 | TCP port used for Manager CLI access (via SSH). | Sensor | ||
Outbound Rules | 8500 | The UDP port is used by the Manager to make real-time configuration changes on the Sensor. | Sensor | |
Sensor | Inbound rules | 8500 | The UDP port is used by the Manager to make real-time configuration changes on the Sensor. | Manager |
22 | TCP port used for Sensor CLI access. | Manager | ||
6081 | UDP protocol for all incoming traffic with GENEVE header. | NSI In-band | ||
9001 | TCP port used to send Health Check details between the Sensor and internal passthrough network load balancer. | NSI In-band | ||
Outbound Rules | 8501-8504, 8506-8510 | TCP ports are used to install the Sensor, send alerts and packet captures to the Manager, and transfer files between them. | Manager | |
443 | TCP Port is used for vIPS Sensor registration onto the Manager. | Manager |