Deploy and install the Trellix DLP Network Prevent appliance using the Amazon Machine Image (AMI)

Prev Next

Trellix DLP Network Prevent is offered as an Amazon Machine Image (AMI). Using this AMI you can launch an instance of the Trellix DLP Network Prevent virtual appliance, which can be integrated with cloud web or email gateways. Deploy the appliance software from EC2 > Images > AMI Catalog.

Note

Creating a cluster of Trellix DLP Network Prevent appliances is not supported on the AWS platform.

DLP Capture is not supported on the AWS platform.

Prerequisites

Deploy and install ePO - On-prem on an instance of Windows server deployed on AWS. For information about installing ePO - On-prem, see the Trellix ePolicy Orchestrator - On-prem Installation Guide.

You can also manage the appliances from ePO - SaaS. For more information, see Trellix Data Loss Prevention Network Prevent – SaaS Installation Guide.

Task

  1. Login to your Amazon Web Services account using administrator privileges.

  2. Go to AMI Catalog > AWS Market Place AMIs, browse to Trellix DLP Network Prevent AMI image. Click Select and then click Subscribe on instance launch.

    The licensing model offered is Bring Your Own License (BYOL), which implies that your subscription in AWS allows you to only run an instance of the appliance. However, you must purchase the appliance license from Trellix and activate it from ePO - On-prem.

  3. Click Launch instance from AMI to open the Launch an instance page. This page allows you to create an instance of appliance that runs in AWS Cloud.

    1. In Name and tags, provide a host name for the Trellix DLP Network Prevent appliance.

    2. In Application and OS Images (Amazon Machine Image), select Trellix DLP Network Prevent AMI.

    3. In Instance type select the required specification. Trellix recommends a minimum of 32 GB RAM/8 CPU and 64 GB RAM/8 CPU for an appliance with EDM configuration. Only with a minimum of these specifications, you can Connect from the AWS console.

    4. Select the Key pair value or create a new key pair. Access to the appliance is based on SSH key pair based authentication. Use this key pair to login into the appliance.

    5. Select the required Security group or create a new Security group.

    6. Trellix DLP Network Prevent requires two networking interfaces. One of the interface is used for redirecting the traffic and the other is used for Out-of-band management. By default, AWS provides one network interface. To create the second network interface, use one of these methods:

      1. In Network Settings, click Edit.

      2. Select the default Virtual Private Cloud (VPC) and then select a subnet. Selecting a subnet allows you to create the second network interface.

      3. Select the existing security group or create a security group.

      4. Disable the Auto-assign public IP option.

      5. Click Advanced Network Configuration and click Add network interface.

        Enter the network details in the Network interface 2 section.

      OR

      Create an interface as described in https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html#eni-basics.

  4. Click Launch Instance. After successful creation of the instance, you can see a message with the instance ID.

    The appliance comes up with SSH enabled, which is configured with the key pair.

    The authorized SSH key for the "admin" account is updated with the key pair provided during instance creation and the default password is set to instance id.

  5. To configure the network settings, login to the appliance using the SSH (Secure Shell) login and enter the required details:

    ssh -i <key_pair> admin@<ip_address>

    The MASH menu provides you options to update the network setup and ePO - On-prem registration details.

    1. Enter the details for the initial network setup:

      1. Select Appliance network information and enter the values for Host name, Domain name, Default gateway, IP address and Network mask.

        Click OK.

      2. Select DNS configuration and enter the values for Primary DNS Server and Secondary DNS Server.

        Click OK.

      3. Select Management Interface Configuration enter the values for IP address and Network Mask.

        Click OK.

    2. Register the appliance with Trellix-ePO on-prem. Select EPO - on-prem Registration and enter the values for Server details, server port, gateway address, logon name, and password.

      Note

      Gateway address is required only when OOB is configured and when the appliance has to go through a different gateway to reach ePO - On-prem .

  6. Log on to ePO - On-prem.

    You can find the appliance in the System Tree. If needed, move the entry to the correct location in the hierarchy.