Install a vScanner in an AWS Environment
You can install an Arctic Wolf® Virtual Scanner (vScanner) in an AWS environment.
Note:
- vScanners do not support auto-scaling in Amazon Web Services (AWS)®.
- For more information about AWS best practices, see Best practices of Amazon EC2 and Security best practices for your VPC.
- During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
These actions are required:
- Make sure you have the appropriate Arctic Wolf permissions to install the appliance. Contact your Concierge Security® Team (CST) at security@arcticwolf.com to identify who in your organization has these permissions.
- Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click , and then view the IP addresses in the section for your product.
- If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
- If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
- If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.
- Amazon GuardDuty® flags vScanners as containing malware because vScanners contain code that is used to detect vulnerabilities. To avoid this behavior, create a suppression rule to exclude the vScanner from GuardDuty monitoring. For more information, see Suppression rules in GuardDuty.
- Schedule host identification and vulnerability scans. For more information, see Configure a scanner.
Provide AWS account IDs to Arctic Wolf
Note: It can take up to 24 hours for the vScanner AMI to become visible.
Create a vScanner instance
Configure network settings for the vScanner instance
Configure security group rules for the vScanner instance
- Find the Firewall (security groups) section.
- Do one of these actions:
- To use an existing security group — Click Select an existing security group, select the appropriate security group, and then continue to Launch and verify the EC2 instance.
- To create a new security group — Click Create a new security group.
- Remove default security rules.
- In the Security group name section, enter a name for the security group.
- In the Description section, enter a description for the security group.
- Remove the default inbound security group rule.
- Add a rule to allow all outgoing traffic, if it does not already exist.
Launch and verify the EC2 instance
Connect to the serial console
- If you have not used the serial console before, complete these steps to configure serial console access:
- Click .
- In the Account Attributes section, select EC2 Serial Console.
- In the EC2 Serial Console section, select the Allow checkbox.
- Click Update.
- In the EC2 management console, select Instances, and then enter the vScanner instance ID.
- Click .
Configure the vScanner
Use the serial console to configure the vScanner. For more information on using the serial console, see Serial console.
Activate the vScanner
Note: Only the user who configured the vScanner can activate the vScanner.