Loading

Sorry

Your web browser doesn't support some required capabilities.

This interactive simulation works best with the latest version of Chrome, Firefox, or Safari.

Sorry

An error occurred. Please reload the page or report this error to:
hol-feedback@vmware.com

Sorry

Sorry

Unable to initialize the simulation player:

Please reload the page or report this error to:
hol-feedback@vmware.com

X
↩ Return to the lab
Installation and Configuration of Trend Deep Security

This is an interactive demo

Drive it with your mouse, your finger, or just use the arrow keys.

Use Learn mode to learn the demo. The orange boxes show where to click.

Use Present mode to hide the orange boxes and notes.

Click a Shortcut to jump to a specific part of the demo.

X
Hide notes
Restore notes
Open notes window
Increase font size
Decrease font size

Deploy and configure Trend Micro Deep Security services

This part of the lab is presented as a Hands-on Labs Interactive Simulation. This will allow you to experience steps which are too time-consuming or resource intensive to do live in the lab environment. In this simulation, you can use the software interface as if you are interacting with a live environment.

The orange boxes show where to click, and the left and right arrow keys can also be used to move through the simulation in either direction.

In this Interactive Simulation, we will be configuring Trend Micro Deep Security Manager and NSX to protect vm's with agent-less antivirus.

  1. Click on esx-01a.corp.local to gain focus on the object.
  2. Click Configure.
    • Note that we are in the Agent VM Settings.
  3. Click the Edit button to assign the default Datastore and Network settings for agent appliances.
  4. Click the Datastore assignment box
  5. Click the Datastore Local-esx01a.
  6. Click the Network assignment box and
  7. Click the Network ESXi-RegionA01-vDS-COMP.
  8. Click the OK button to accept the changes.

Next we will deploy the NSX Guest introspection services.  From now on, we continue working on the Cluster level.

  1. Click the Home button at the top of the page.
  2. Click  Networking & Security from the list.
  3. Click Installation and Upgrade on the Navigator menu.
  4. Click on Host Preparation.
  5. Click on RegionA01-COMP01 to verify NSX is installed and enabled.
  6. Click on the Service Deployments tab.
  7. Click the Green Plus Sign to open the Deploy Network & Security Services Wizard.
  8. Click Guest Introspection selection box
  9. Click Next to continue.
  10. Click the Cluster object RegionA01-COMP01.
  11. Click Next to continue.
  12. Click the drop down box under Datastore to select the proper Datastore.
  13. Click Specified on-host.
  14. Click the drop down box under Network to select the proper Network.
  15. Click Specified on-host.
  16. Click Change in the IP Assignment column.
  17. Click Use IP Pool.
  18. Click guest-intro and t..  entry.
  19. Click OK.
  20. Click Next to continue.
  21. Verify your settings and click Finish.
  22. Verify Installation status and Service Status are "Succeeded" and "Up".

We will now go to the Trend Micro Deep Security Manager interface to continue the configuration.

  1. Click the Trend Micro Deep Security tab.
  2. Click on the Computers tab.
  3. Click Add.
  4. From the drop down menu, click on Add VMware vCenter.
  5. Enter vcsa-01a.corp.local for the vCenter Server.
  6. Click on Name and it will auto populate with "vCenter - vcsa-01a.corp.local"
  7. Click on User name and enter - Administrator@vsphere.local
  8. Click on Password and enter - VMware1!
  9. Click Next to continue.
  10. Click Accept to accept the VCSA certificate.

Configure Trend Micro Deep Security Manager to communicate with the NSX Manager.

  1. Enter the NSX Manager IP Address 192.168.110.42
  2. Click User name and enter - admin
  3. Click Password and enter - VMware1!
  4. Click Next to continue.
  5. Click Accept to accept the NSX manager certificate.
  6. Click Finish to complete the Wizard.
  7. Leave the check box checked to create an automatic Event-Based task and click Close.

Now that Deep Security is connected with vCenter and NSX, we can deploy the Deep Security Virtual Appliances (DSVA).  Note that these appliances are deployed from vCenter and not from Deep Security Manager.

  1. Click on the vSphere Web Client tab.
  2. Click on the Green Plus Sign.
  3. Click on the Trend Micro Deep Security service selection.
  4. Click Next to continue.
  5. Click on Cluster object RegionA01-COMP01.
  6. Click Next to continue.
  7. Click the drop down box under Datastore to select the proper Datastore.
  8. Click on Specified on-host.
  9. Click the drop down box under Network to select the proper Network.
  10. Click on Specified on-host.
  11. Click Change in the IP Assignment column.
  12. Click on Use IP Pool.  
  13. Click on guest-intro and t..  entry to select the IP Pool.
  14. Click OK.
  15. Click Next to continue
  16. Verify your settings and click Finish.

Now we will create a Security Group and include the VMs that will be protected by Deep Security

  1. Click on Service Composer in the Navigator pane.
  2. Click on the Green Plus Sign to create a new Security Group.
  3. Enter Trend_micro_security_group for the name of our new Security Group.
  4. Click on Next to continue.
  5. We will leave the membership criteria at default values, click Next to continue.
  6. Click on Cluster object RegionA01-COMP01.
  7. Click on the Arrow to move RegionA01-COMP01 to the Selected Objects group.
  8. Click on Next to continue.
  9. Click Next again to skip objects to exclude.
  10. Click Finish.

Next we will Create 3 security policies to redirect traffic to Trend Micro Deep Security: one policy for Guest Introspection (Anti-Malware and Integrity Monitoring) and two policies for Network Introspection (one for incoming traffic and one for outgoing traffic; both for the Intrusion Prevention Service)

  1. Click the Security Policies tab.
  2. Click on the Green Plus Sign to create a new Security Policy.
  3. Click on the Name field.
  4. Name the Policy Trend Security.
  5. Click Next to continue.
  6. Click the Green Plus Sign to start the Security Policy wizard.
  7. In the Name field, enter Anti-Malware.
  8. Click OK.
  9. Click Next to continue.
  10. Click Next again to skip firewall rule creation for now.
  11. Click on the Green Plus Sign to configure the Network Introspection Services.
  12. In the Name field, enter Incoming.
  13. Click on Change.
  14. Click on the Any selection for the Source.
  15. Click OK.
  16. Click OK to continue.
  17. Click on the Green Plus Sign to configure additional Network Introspection Services.
  18. In the Name field, enter Outgoing.
  19. Click OK.
  20. Notice both the Incoming and Outgoing services are in place.  Click Finish.

Next Step - Assign Policy to a Security Group.

  1. Click on the Green Plus Sign to Apply the policy to a security group.
  2. Click the Trend_micro_security_group.
  3. Click OK.

Let's look at the Deep Security Manager Interface to verify........

  1. Click on the Trend Micro Deep Security tab.
  2. Click on Administration.
  3. Click on Event-Based Tasks under System Settings.  Note that An event-based task has been created. This will automatically apply protection by Deep Security to any VM as soon as it has been created in vCenter
  4. Click on Computers.
  5. Click the Scroll Bar on the right side of the screen to scroll down.  Notice that the Deep Security Policy is applied.

Navigate back to the vSphere Web Client to add the NSX filter driver plugin to the VMtools in the VMs.  We will do the Interactive Method, but this can also be scripted.

  1. Click on the vSphere Web Client tab.
  2. Click on the Home button.
  3. Click on the selection Hosts and Clusters from the Drop down menu.
  4. Click on the Win10-View-01A VM in the Navigator pane.
  5. Click on Actions.
  6. Click Open Console from the drop down menu.
  7. Install VMware tools.  Click Next to continue.
  8. Notice we are Customizing the VMware Tools installation, click Next to continue.
  9. Click the Scroll Bar to scroll down.
  10. Click to select NSX File Introspection.
  11. Click on Will be installed on local hard drive.
  12. Click on NSX Network Introspection.
  13. Click on Will be installed on local hard drive.
  14. Click Next to continue.
  15. Click Next again to continue.
  16. Click Install to begin the installation.
  17. The installation is complete, click on Finish.
  18. Click Yes to reboot the vm.

Let's look at the Deep Security Manager Interface to verify........

  1. Click the Trend Micro Deep Security tab.
  2. Click Dashboard.
    • Notice we have 6 managed machines now.
  3. Click on Computers
  4. Click the scroll bar to scroll down.
    • Notice that Win10-View-01a is Managed (Online) now.

To return to the lab, click the link in the top right corner or close this browser tab.

Copyright © 2018 VMware, Inc. All rights reserved.