This section describes how to install a virtual Network Security appliance on a KVM server using the KVM Virtual Machine Manager UI.
Important
This procedure uses KVM version libvert 4.5 on Ubuntu 18.04. The navigation instructions and user interface may vary if you are using CentOS or a different version of Ubuntu.
Note
This procedure covers the required settings for a Trellix virtual appliance. You can accept the default values for the other settings, or specify values that are appropriate for your setup.
Before starting the virtual appliance installation, ensure you have the required prerequisite software installed. See KVM requirements .
In the following procedure, you will create the virtual appliance and configure its management, OOB, and data ports.
Important
A virtual Network Security appliance supports ten NICs: one management interface, one out-of-band interface, and eight monitoring (data) interfaces. You must provision a NIC for each interface. This is because KVM needs to know the total number of interfaces, even if some of those interfaces are not used.
Screen | Action |
|---|---|
Step 1 of 4 |
|
Step 2 of 4 |
|
Step 3 of 4 |
|
Step 4 of 4 |
The KVM installation page opens. |
Tab | Action |
|---|---|
Overview |
|
VirtIO Disk 1 |
|
Tab | Action |
|---|---|
Controller |
|
Network (for OOB) | Add the OOB (ether2) port for the virtual Network Security appliance.
|
Network (for data ports) | Repeat the following steps to configure each of the data ports required for your virtual Network Security appliance.
|
Download the Network Security KVM deployment
.zipfile from the Trellix DTI network to a KVM server and extract the files within it. The.zipfile name is based on your appliance model. For example, the.zipfile for NX 4500 isimage-wmps-fireeyenx4500v.zip.In KVM Virtual Machine Manager, select File > New Virtual Machine.
Complete the Create a new virtual machine screens:
In the KVM installation page, configure the basic information and disk IO for the virtual Network Security appliance:
In the KVM installation page, add the virtual hardware for the controller and networks:
At the bottom left of the KVM installation page, click Add Hardware.
In the Add New Virtual Hardware page, select the tab for the type of hardware to add and enter the values according to the following table.
You must click Finish after adding each hardware entry and click Add Hardware again to select the next type of hardware to add.
After adding the data ports, click Begin installation.
Check the console for the virtual Network Security appliance boot status.
Continue with Performing the initial Network Security configuration for the virtual appliance.