Support Level: Tier 2 (Compatible Platform)
AWS is categorized as a Tier 2 (Compatible) deployment platform under Outpost24's Supported Deployment Platforms for RC-Scanners.
-
Software Support: Outpost24 Support provides best-effort assistance for RC-Scanner software functionality once the VM has successfully booted and meets minimum requirements.
-
Infrastructure & Cloud Scope: Cloud-specific infrastructure configuration, disk image conversion, and AWS import processes remain the customer's responsibility.
Purpose
This article describes how to deploy RC-Scanner as a virtual appliance in AWS. It covers preparation of the installation image, upload to Amazon S3, import into Amazon EC2, instance configuration, SSH access, and bootstrap registration in the OUTSCAN Portal.
Introduction
AWS cannot boot an ISO image directly. The RC-Scanner ISO must first be installed in a virtual machine and converted into a supported virtual disk image. This guide uses Microsoft Hyper-V to prepare the disk and AWS CLI to upload and import it.
The deployment consists of five phases:
-
Prepare the RC-Scanner VHD in Hyper-V.
-
Upload the VHD to an Amazon S3 bucket.
-
Import the VHD as an EC2 AMI.
-
Launch and validate an EC2 instance.
-
Connect over SSH and complete the RC-Scanner bootstrap.
Important: Keep the AWS region consistent throughout the process. The S3 bucket and imported AMI must be available in the region where you intend to launch the scanner.
Prerequisites
-
Access to the latest RC-Scanner ISO from the OUTSCAN Portal under Configurations → RC SCANNER.
-
Microsoft Hyper-V and permission to create and manage virtual machines.
-
Windows PowerShell access.
-
An account for your organization's AWS access portal, such as
https://<yourcompany>.awsapps.com/start/. -
AWS CLI version 2 installed and available in PowerShell.
-
Permission to use Amazon S3, Amazon EC2, and AWS Identity and Access Management (IAM).
-
An existing
vmimportIAM role, or access to an AWS administrator who can create or update it. -
Network access for SSH and the RC-Scanner communication ports.
Review the applicable RC-Scanner system requirements and sizing guidance before selecting the EC2 instance type.
Phase 1: Prepare the VHD in Hyper-V
The AWS VM Import process requires a supported virtual disk format. This procedure creates a Generation 2 Hyper-V VM, installs RC-Scanner from the ISO, and converts its disk to a fixed VHD.
Create the virtual machine
-
Download the latest RC-Scanner ISO from the OUTSCAN Portal.
-
Open Hyper-V Manager.
-
Select New → Virtual Machine.
-
Configure the VM with the following settings:
|
Setting |
Recommended value |
|---|---|
|
Name |
|
|
Generation |
Generation 2 |
|
Memory |
At least 2048 MB; 4096 MB recommended for preparation |
|
Network |
An active virtual switch with DHCP, such as Default Switch |
|
Virtual disk |
30 GB |
|
Installation media |
The downloaded RC-Scanner ISO |
-
Finish the wizard to create the VM.
Configure Secure Boot
-
Right-click the new VM and select Settings.
-
Select Security.
-
Ensure Enable Secure Boot is selected.
-
Set the template to Microsoft UEFI Certificate Authority.
-
Select Apply, then OK.
The Microsoft UEFI Certificate Authority template is required for the Debian-based RC-Scanner installer to boot correctly in a Generation 2 VM.
Run the unattended installation
-
Right-click the VM and select Start.
-
Open the VM console by selecting Connect.
-
Allow the installer to run. It installs the Debian base operating system and RC-Scanner packages automatically.
-
Wait for the VM to shut down when installation is complete.
-
Start the VM again and confirm that it reaches the login prompt.
-
Shut down the VM before converting the disk.
Convert the disk to a fixed VHD
AWS requires a fixed VHD for this workflow. Do not upload the dynamic .vhdx file.
PowerShell
Open PowerShell as Administrator and run:
Convert-VHD -Path "C:\Path\To\RC-Scanner-Prep.vhdx" -DestinationPath "C:\Path\To\RC-Scanner-AWS.vhd" -VHDType Fixed
Hyper-V Manager
-
Select Edit Disk….
-
Locate the Hyper-V
.vhdxfile. -
Select Convert.
-
Choose VHD as the disk format.
-
Choose Fixed size as the disk type.
-
Select the destination path and complete the wizard.
Use the resulting RC-Scanner-AWS.vhd file in the next phase.
Phase 2: Upload the VHD to Amazon S3
Install and verify AWS CLI
In PowerShell, run:
aws --version
If PowerShell reports that aws is not recognized, install AWS CLI v2 for Windows from AWS Command Line Interface. Close all PowerShell windows, open a new one, and run the version command again.
If the command still fails, check whether the executable exists:
Test-Path "C:\Program Files\Amazon\AWSCLIV2\aws.exe"
& "C:\Program Files\Amazon\AWSCLIV2\aws.exe" --version
Configure AWS credentials
-
Open your organization's AWS access portal.
-
Select Accounts, then open the appropriate AWS account.
-
Select Access keys.
-
Use the PowerShell instructions to obtain the access key ID, secret access key, and session token.
-
Configure the AWS CLI:
aws configure
Verify the credentials:
aws sts get-caller-identity
aws s3 ls
AWS access keys and session tokens are sensitive credentials. Do not paste them into tickets, documentation, scripts committed to source control, or chat messages.
Create the S3 bucket
Choose a globally unique bucket name and create it:
aws s3 mb s3://<bucket-name>;
Verify that the bucket exists:
aws s3 ls
Upload the VHD
Locate the generated VHD, then upload it to the bucket:
aws s3 cp `
"C:\Path\To\RC-Scanner-AWS.vhd" `
"s3://<bucket-name>/"
Verify the object and its size:
aws s3 ls s3://<bucket-name>/
Phase 3: Import the VHD as an AMI
Verify EC2 import access
aws ec2 describe-import-image-tasks
An empty ImportImageTasks result is acceptable.
Verify the vmimport role
aws iam get-role --role-name vmimport
The command should return a role named vmimport. If the role does not exist, contact an AWS administrator.
Verify the vmimport policy
aws iam get-role-policy `
--role-name vmimport `
--policy-name vmimport
The policy must allow the import service to read the S3 bucket and register the imported image. If the policy does not include the bucket, an AWS administrator can update it with a policy similar to the following:
You need to append your new bucket to the existing list. If you only add your new bucket to the policy it will overwrite the existing ones.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetBucketLocation",
"s3:GetObject",
"s3:ListBucket",
"s3:GetBucketAcl"
],
"Resource": [
"arn:aws:s3:::<bucket-name1>",
"arn:aws:s3:::<bucket-name1>/*"
"arn:aws:s3:::<bucket-name2>",
"arn:aws:s3:::<bucket-name2>/*"
"arn:aws:s3:::<your-new-bucket>",
"arn:aws:s3:::<your-new-bucket>/*"
]
},
{
"Effect": "Allow",
"Action": [
"ec2:ModifySnapshotAttribute",
"ec2:CopySnapshot",
"ec2:RegisterImage",
"ec2:Describe*"
],
"Resource": "*"
}
]
}
Save the approved policy as C:\Temp\vmimport-policy.json and apply it:
aws iam put-role-policy `
--role-name vmimport `
--policy-name vmimport `
--policy-document file://C:\Temp\vmimport-policy.json
Updating IAM policies requires elevated AWS permissions. Use the organization's approved change process and least-privilege access.
Create the disk container definition
Create C:\Temp\containers.json:
[
{
"Description": "RC Scanner VM",
"Format": "VHD",
"UserBucket": {
"S3Bucket": "<bucket-name>",
"S3Key": "RC-Scanner-AWS.vhd"
}
}
]
Start the import
aws ec2 import-image `
--description "RC Scanner VM" `
--disk-containers file://C:\Temp\containers.json
Save the returned ImportTaskId. You need it to monitor the conversion.
Monitor the import
aws ec2 describe-import-image-tasks `
--import-task-ids import-ami-<task-id>
|
Status |
Meaning |
|---|---|
|
|
The import task is in progress. |
|
|
The import task is being canceled. |
|
|
The import task is canceled. |
|
|
Import status is updating. |
|
|
The imported image is being validated. |
|
|
The imported image was validated. |
|
|
The imported image is being converted into an AMI. |
|
|
The import task is completed and the AMI is ready to use. |
When the import completes, the response includes an AMI identifier similar to:
{
"Status": "completed",
"ImageId": "ami-xxxxxxxxxxxxxxxxx"
}
Phase 4: Launch and Validate the EC2 Instance
Locate the AMI
-
Open the AWS access portal and enter the appropriate account.
-
Open the AWS Management Console with the required administrative role.
-
Open EC2.
-
Confirm that the selected AWS region matches the region used for the S3 bucket and import.
-
Open Images → AMIs.
-
Locate the AMI created during the import.
-
Give the AMI a descriptive name and record its AMI ID.
Configure and launch the instance
For Instance size and firewall rules please refer to the following guides:
RC-Scanner Dimensioning Guide
Firewall Rules RC-Scanners
-
Select the AMI and choose Launch instance from AMI.
-
Enter a descriptive instance name.
-
Select an instance type that meets the RC-Scanner sizing requirements.
-
Select an existing EC2 key pair. Create or import one if required.
-
Under Network settings, select the required VPC and subnet.
-
Enable automatic public IP assignment if the instance must be reached directly over the internet.
-
Configure security group rules according to the approved RC-Scanner firewall requirements.
-
Allocate 30 GB of storage, or the amount required by the approved sizing guidance.
-
Launch the instance.
Validate the instance
-
Open EC2 → Instances.
-
Confirm that the instance state is Running.
-
Confirm that all displayed status checks have passed.
-
Record the public IPv4 address, if one is assigned.
From PowerShell, test SSH connectivity:
Test-NetConnection <public-ip> -Port 22
Ping is not required for this test and may be blocked by the security group.
Phase 5: Connect and Complete Bootstrap
Connect over SSH
Use the instance public IPv4 address:
ssh rcscanner@<public-ip>
Use the following initial account details:
-
Username:
rcscanner -
Default password:
outpost24
Change the default password immediately after the first login. Never leave the default credential active on a deployed scanner.
Please note that when you have changed your password you will be disconnected and need to reconnect using the new credentials.
Change the password
At first login, enter the default password when prompted, then provide a new password. Store the new credential according to your organization's password-management policy.
Retrieve the one-time bootstrap token
-
Sign in to the OUTSCAN Portal.
-
Open Configurations → RC SCANNER.
-
Select the green + button.
-
Select Continue.
-
Copy the displayed one-time token.
Run the bootstrap
Run the following command in the SSH session:
rc-scanner-bootstrap --token <your-token>
For unattended setup, use:
rc-scanner-bootstrap --token <your-token> --headless
During an interactive installation, follow the prompts and press F3 when requested.
Verify registration
-
Return to Configurations → RC SCANNER in the OUTSCAN Portal.
-
Locate the new scanner.
-
Confirm that its status changes from Initializing to Connected.
-
Begin scanning only after the scanner shows as connected.