Prerequisites
Before enabling TrendAI Vision One™ Cloud IPS, ensure you have the following:
AWS requirements and permissions
- Active AWS account with appropriate permissions
- Existing AWS Network Firewall deployment (or plan to create one)
Required AWS IAM permissions
networkfirewall:*: To manage Network Firewall policies and rule groups.aws-marketplace:Subscribe: To subscribe to Trend-managed rule groups.ec2:DescribeVpcs: To view VPC configuration.ec2:DescribeSubnets: To view subnet configuration.
Network Firewall deployment
If you don't have AWS Network Firewall deployed yet, refer to AWS documentation:
Subscribe to TrendAI Vision One™ managed rule groups in AWS marketplace
- Sign in to the AWS Management Console.
- Navigate to .
- Select the AWS Marketplace tab.
- Locate TrendAI Vision One™ Cloud IPS.
- Click View subscription options.
- Review the subscription details:
- Pricing: $0.010 per GB inspected
- Terms: Review AWS Marketplace terms
- Click Subscribe to complete the subscription.
NoteYou can subscribe to one or all rule groups. Pricing is $0.010/GB total, regardless
of how many rule groups you enable.
|
Add managed rule groups to Firewall policy
Option A: Add to an existing Firewall Policy
- Navigate to .
- Select your existing Firewall policy.
- Click .
- Select the TrendAI Vision One™ managed rule groups you subscribed to:
TrendAI-MalwareBlockStrictOrderTrendAI-CVEClientBlockStrictOrderTrendAI-CVEServerBlockStrictOrder

Note
TrendAI Vision One™ recommends that you enable Run in alert mode to test this configuration before blocking traffic. - Click Add to policy.
- Review the updated policy configuration.
- Click Save to apply changes.
Option B: Create New Firewall Policy
- Navigate to .
- Click Create Firewall policy.
- Configure policy settings:
- Name: Enter a descriptive name (e.g., "production-firewall-policy")
- Description: Document the policy purpose
- In the Stateful rule groups section, click Add partner managed rule groups and select TrendAI Vision One™ managed rule groups.
- (Optional) Add AWS managed rule groups or custom rule groups.
- Configure stateless rule groups if needed.
- Click Create Firewall policy.
Associate policy to Network Firewall
- Navigate to .
- Select your Network Firewall.
- Click .
- Select the firewall policy containing TrendAI Vision One™ managed rule groups.
- Click Associate.
- Wait for the association to complete (typically 1-2 minutes).
Verify configuration
- Navigate to your Network Firewall details.
- Click the Firewall policy tab.
- Verify TrendAI Vision One™ managed rule groups are listed under Stateful rule groups.
- Verify the Status shows "Active".
Configure alert mode
By default, TrendAI Vision One™ managed rule groups block and alert on matching traffic. Alert mode can be enabled
to only alert without blocking. Alert mode can also be used for initial testing to
validate detection accuracy for the first 24-48 hours of deployment.
To enable alert mode:
- Navigate to your firewall policy.
- Find the TrendAI Vision One™ managed rule group in Stateful rule groups.
- Click Edit next to the rule group.
- Enable Alert mode.
- Click Save.
To return to default block and alert behavior, disable alert mode following the same
steps.
