Before you deploy your NDR Console instance in AWS, make sure the following requirements are met.
Security group requirements
Network interfaces:
Management interface
Security groups:
Inbound
TCP port 22—SSH management
TCP port 443—HTTPS Web UI and API access
Outbound
TCP port 443—HTTPS connection to cloud.fireeye.com to fetch license based on activation key
Network requirements
Network information—Gather the following information from your network administrator:
One of the following:
DHCP allocated IP address for the virtual machine
Static IP address, subnet mask, and default gateway address for the virtual machine
IP address for each Domain Name System (DNS) server
IP address for each Network Time Protocol (NTP) server
Network access—See the Trellix Ports and Protocols Reference Guide for a list of the required ports for network access.
License requirements
FIREEYE_APPLIANCE is the base product license that is tied to your activation code. It enables NDR Console features and functionality.
NDR License is either the ESSENTIALS/CORE or ENTERPRISE license keys for NDR functionality.
CONTENT_UPDATES for downloading security content packages from the DTI server.
Limitations
Only single-node data clusters are currently supported for AWS deployments. A node can be either a data node or a director node.