Trellix vIPS for AWS is a GWLB-based solution that is capable of inspecting traffic flowing into and out of protected AWS instances. The solution has been designed to adapt to a public cloud environment and to scale with the requirements of your organization's subnets.
Deployment of Trellix vIPS can be fulfilled to suit your requirements based on the direction of traffic and inspection mode. In this section, we provide you with some scenarios which can serve as basic guidelines for your deployment.
Scenario 1: Protecting VPC using distributed control plane (GWLB and Trellix vIPS Solution) and data plane (GWLBe)
This section provides only a few deployment scenarios for AWS GWLB. For more information, see Introducing AWS Gateway Load Balancer: Supported architecture patterns.
This deployment represents VPCs that require Trellix vIPS to be placed between resources inside the VPC and outside of the VPC, such as over the Internet.
You can deploy the following components:
Manager (A minimum of 1 Manager instance is required)
Virtual IPS Sensor (A minimum of 1 Sensor instance is required)

Scenario 2: Protecting VPC using distributed data plane (GWLBe) and centralized control plane (GWLB and Trellix vIPS Solution)
This deployment represents VPCs that require Trellix vIPS to be placed between resources inside the VPC and outside of the VPC, such as over the Internet.
You can deploy the following components:
Manager (A minimum of 1 Manager instance is required)
Virtual IPS Sensor (A minimum of 1 Sensor instance is required)

Note
This section represents only Outbound traffic. Similarly, you can use the above method for inbound and East-West traffic.
Scenario 3: Protecting multiple account VPCs using distributed data plane (GWLBe) and centralized control plane (GWLB and Trellix vIPS Solution)
When you want to secure your resources distributed across multiple AWS accounts, you can protect your resources by using GWLBe.
You can deploy the following components in one account:
Manager (A minimum of 1 Manager instance is required)
Virtual IPS Sensor (A minimum of 1 Sensor instance is required)
Deploy the instances in the second AWS account and connect the accounts.

Note
This section represents only Outbound traffic in another account. Similarly, you can use the above method for inbound and East-West traffic in another account.
Scenario 4: Protecting VPC using centralized data and control plane (GWLBe, GWLB, and Trellix vIPS Solution)
You can use this type of deployment for scaling or inspecting either North-South or East-West traffic. GWLB and GWLBe make appliance fleets easier to deploy and scale. You can protect the AWS by combining it with other networking services such as using AWS Transit Gateway.
AWS Transit Gateway is a regional highly available and scalable service that enables customers to connect multiple VPCs, as well as with the on-premises networks over Site-to-Site VPN and/or Direct Connect using a single centralized gateway. You can use the Transit Gateway for centralized IPS inspection and egress control between VPCs, between VPCs and the Internet, and between VPCs and on-premises networks. VPCs can be in the same or different AWS accounts.
GWLB is designed specifically to address these architectural challenges and make deploying, scaling, and running vIPS appliances easier. Since GWLBe's are a routable target, you can route traffic moving to and from Transit Gateway to the fleet of Trellix vIPS appliances that are configured as targets behind a GWLB.
To complete this deployment, you will require the following:
An AWS Transit Gateway
A Transit Gateway attachment to a VPC
Routes between the Transit Gateway and the VPCs
For more information about the Transit Gateway deployments, refer to Getting started with Transit Gateways.
Note
The workload VPC can be either in the same or different AWS accounts.
For more information about distributed inspection architecture, see Distributed Inspection Architectures with Gateway Load Balancer.

For more information, refer to the Centralized inspection architecture with AWS Gateway Load Balancer and AWS Transit Gateway.
Scenario 5: Protecting the AWS Lambda service traffic using distributed data plane (GWLBe) and centralized control plane (GWLB and Trellix vIPS Solution)
You can use this deployment to inspect the traffic generated from the Lambda function or traffic generated to the S3 bucket.
You should disable the amazonaws.com domain name from the IPS Inspection Exclusions tab of Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Domain Names for the traffic to be inspected.
To complete this deployment, you will require the following:
An Amazon S3 bucket.
Lambda function that returns the type of objects in an Amazon S3 bucket.
A Lambda trigger that invokes your function when objects are uploaded to the S3 bucket.
The lambda function should be associated with a private subnet in the workload VPC.

For more information, refer to Using an Amazon S3 trigger to invoke a Lambda function section.