Views:
  • Deep Discovery Inspector AMI
    AMI of the Deep Discovery Inspector virtual appliance from the AWS Marketplace
  • Deep Discovery Inspector Activation Code
    Activation Code for the Deep Discovery Inspector virtual appliance
  • AWS VPC and subnet
    A VPC configured with public and private subnets, according to AWS best practices, to provide you with your own virtual network on AWS.
    Note
    Note
    For details about creating a VPC and subnet, see https://docs.aws.amazon.com/vpc/latest/userguide/working-with-vpcs.html.
    Public subnets and:
    Private subnets and:
    • Management port and Data port of the Deep Discovery Inspector virtual appliance which can be in the same subnet or different subnets in your VPC.
  • AWS VPC Traffic Mirror
    Traffic Mirroring is an AWS VPC feature that you can use to copy network traffic from an elastic network interface (ENI) of Amazon EC2 instances. The security and monitoring appliances can be deployed as individual instances, or as a fleet of instances behind a Network Load Balancer (NLB) with a UDP listener.
  • AWS EC2 Security Group
    Inbound/Outbound Rule
    Type
    Protocol
    Port
    Source
    Description
    Inbound
    HTTPS
    TCP
    443
    CIDR that can reach your instance
    For accessing the Deep Discovery Inspector virtual appliance management console
    Inbound
    SSH
    TCP
    22
    CIDR that can reach your instance
    For accessing the Deep Discovery Inspector virtual appliance pre-configuration console
    Inbound
    Custom UDP
    UDP
    4789
    CIDR of your mirror source or the NLB
    For VXLAN traffic required by the AWS traffic mirror
    Inbound
    Custom TCP
    TCP
    14789
    CIDR of NLB
    (Optional) Implemented by the Deep Discovery Inspector virtual appliance for answering the NLB health check.
    Note
    Note
    Outbound Rules in the default security group should allow all traffic. The Deep Discovery Inspector virtual appliance works well with the default outbound rules. The following exceptions may apply: