Configure Endpoint Protection

Configuring Endpoint Protection is required in order to protect existing VMs with Deep Security Virtual Appliance's Anti-Malware feature.

Follow the steps below to configure a service profile for the Deep Security Virtual Appliance:

  1. Still in NSX-T Manager, click Security at the top, select POLICY at the top, and then on the left, find Endpoint Protection and click Endpoint Protection Rules.
  2. In the main pane, click SERVICE PROFILES.
  3. From the Partner Service drop-down list, select Trend Micro Deep Security if it is not already selected.
  4. Click ADD SERVICE PROFILE and fill out the fields as follows:
    • For the Service Profile Name, specify a name. Example: dsva-service-profile-epp.
    • For the Service Profile Description, enter a description. Example: Deep Security Service Profile for Endpoint Protection.
    • For the Vendor Template, select Default (EBT). This template was loaded at the same time as the Trend Micro Deep Security service.

    The ADD SERVICE PROFILE page should now look similar to the following:

  5. Click SAVE.
  6. On the main pane, select the RULES tab and click + ADD POLICY.
  7. In the Name column, click within the New Policy cell and change the name. For example, use dsva-policy-epp.
  8. Select the check box next to dsva-policy-epp and click + ADD RULE. A rule appears under dsva-policy-epp.
  9. Name the rule and select the corresponding groups and service profiles. For example, name the rule dsva-rule-epp, and select dsva-protection-group and dsva-service-profile-epp. There is now a mapping between the VMs in the dsva-protection-group and the Default (EBT) template specified in the dsva-service-profile-epp.

    The policy should now look similar to the following:

  10. Click PUBLISH to finish the policy and rule creation.

    You have now configured Endpoint Protection in NSX-T.