Onboard CDR for AWS (Legacy)

The Legacy deployment steps are applicable for customers running CDR on TotalCloud 2.9.0 or earlier versions. If you have the latest version of TotalCloud, refer to Onboard CDR for AWS (New) to get started with CDR.

You can deploy Qualys CDR in minutes through CloudFormation and configure your Virtual Private Cloud (VPC) for agentless monitoring via AWS VPC Traffic Mirroring.

To get started, deploy Qualys CDR in standalone or high-availability auto-scaling mode, then configure traffic mirroring for your VPCs, Subnets, or tagged EC2/EKS instances.

Begin your CDR journey for AWS by following the steps below.

Prerequisites

  • You should create a deployment on the Threat Scanners tab. Refer to Deploy Threat Scanners.

  • Install Terraform to create and manage the Qualys environment on the AWS infrastructure. To install Terraform, go to Terraform downloads. Navigate to Linux > Amazon Linux, copy the commands to your terminal, and run them. 

  • Private subnets must have outbound internet access. Verify the subnets have outbound internet access before deploying the CDR appliance.

CDR monitors your network via VPC Traffic Mirroring. The regions currently supported for traffic mirroring are mentioned here. This information will be relevant when configuring CDR for your network.

Get Started

Connect Qualys to your AWS account(s) to protect your cloud with Qualys Agentless Runtime Cloud Security powered by Deep Learning AI.  Contact your TAM to proceed with connecting your accounts. After connecting your AWS account with your Qualys account, you can see instructions to follow on the CDR page before CDR can provide you accurate deep visibility into your workloads.


Deploy Threat Scanners to get your CDR Key. Follow the steps below to proceed with the rest of the configurations.

OR

Now that you have set up your traffic mirroring sessions, Qualys CDR virtual appliances will begin inspecting your network traffic as soon as traffic mirroring is enabled on your workloads, providing deep L3-L7 visibility and threat detection, surfacing security findings, and validating threats in the portal.

The new widgets on the CDR homepage provide information on your cloud workload, and you can see detailed information in TotalCloud Resources.