In case of an upgrade, a new launch configuration has to be created with the new Sensor AMI. The new launch configuration has to be associated with the auto-scaling group. You can create a copy of the existing launch configuration, add the new Sensor AMI to the launch configuration, and associate it with the auto-scaling group.
The following section describes steps to upgrade Sensors in an auto-scaling group so that there is no disruption to traffic inspection. The Sensors with the latest software version are deployed first. The Sensors with the older software version are deleted only after the new Sensors are deployed.
To upgrade the Virtual IPS Sensors launched in an auto-scaling group, perform the following steps in the AWS console:
In the Launch Templates page, select the template you want to create a copy of.
In the template page, click the Action drop-down menu next to the template name and select Modify template (Create new version).
In the Modify template (Create new version) page, choose the AMI of your choice and click Create template version.
Note
This creates a new template version. You can check this version in the template page under the Versions tab.
Go to the Auto Scaling Groups page and click Create Auto Scaling group.
Choose launch template or configuration page appears. Specify a name in the Auto Scaling group name field, choose the template under the Launch template drop-down menu, choose the latest version under the Version drop-down menu and click Next.
Provide the necessary configuration details in the next sections and complete the setup.
For more information on auto-scaling groups, see the section Auto scaling of Sensors to improve traffic throughput in the Trellix Virtual Intrusion Prevention System Product Guide.