Knowledge base

Deploy RC-Scanner on AWS

Support Level: Tier 2 (Compatible Platform)
AWS is categorized as a Tier 2 (Compatible) deployment platform under Outpost24's Supported Deployment Platforms for RC-Scanners.

  • Software Support: Outpost24 Support provides best-effort assistance for RC-Scanner software functionality once the VM has successfully booted and meets minimum requirements.

  • Infrastructure & Cloud Scope: Cloud-specific infrastructure configuration, disk image conversion, and AWS import processes remain the customer's responsibility.

Purpose

This article describes how to deploy RC-Scanner as a virtual appliance in AWS. It covers preparation of the installation image, upload to Amazon S3, import into Amazon EC2, instance configuration, SSH access, and bootstrap registration in the OUTSCAN Portal.

Introduction

AWS cannot boot an ISO image directly. The RC-Scanner ISO must first be installed in a virtual machine and converted into a supported virtual disk image. This guide uses Microsoft Hyper-V to prepare the disk and AWS CLI to upload and import it.

The deployment consists of five phases:

  1. Prepare the RC-Scanner VHD in Hyper-V.

  2. Upload the VHD to an Amazon S3 bucket.

  3. Import the VHD as an EC2 AMI.

  4. Launch and validate an EC2 instance.

  5. Connect over SSH and complete the RC-Scanner bootstrap.

Important: Keep the AWS region consistent throughout the process. The S3 bucket and imported AMI must be available in the region where you intend to launch the scanner.

Prerequisites

  • Access to the latest RC-Scanner ISO from the OUTSCAN Portal under Configurations → RC SCANNER.

  • Microsoft Hyper-V and permission to create and manage virtual machines.

  • Windows PowerShell access.

  • An account for your organization's AWS access portal, such as https://<yourcompany>.awsapps.com/start/.

  • AWS CLI version 2 installed and available in PowerShell.

  • Permission to use Amazon S3, Amazon EC2, and AWS Identity and Access Management (IAM).

  • An existing vmimport IAM role, or access to an AWS administrator who can create or update it.

  • Network access for SSH and the RC-Scanner communication ports.

Review the applicable RC-Scanner system requirements and sizing guidance before selecting the EC2 instance type.

Phase 1: Prepare the VHD in Hyper-V

The AWS VM Import process requires a supported virtual disk format. This procedure creates a Generation 2 Hyper-V VM, installs RC-Scanner from the ISO, and converts its disk to a fixed VHD.

Create the virtual machine

  1. Download the latest RC-Scanner ISO from the OUTSCAN Portal.

  2. Open Hyper-V Manager.

  3. Select New → Virtual Machine.

  4. Configure the VM with the following settings:

Setting

Recommended value

Name

RC-Scanner-Prep, or another descriptive name

Generation

Generation 2

Memory

At least 2048 MB; 4096 MB recommended for preparation

Network

An active virtual switch with DHCP, such as Default Switch

Virtual disk

30 GB

Installation media

The downloaded RC-Scanner ISO

  1. Finish the wizard to create the VM.

Configure Secure Boot

  1. Right-click the new VM and select Settings.

  2. Select Security.

  3. Ensure Enable Secure Boot is selected.

  4. Set the template to Microsoft UEFI Certificate Authority.

  5. Select Apply, then OK.

The Microsoft UEFI Certificate Authority template is required for the Debian-based RC-Scanner installer to boot correctly in a Generation 2 VM.

Run the unattended installation

  1. Right-click the VM and select Start.

  2. Open the VM console by selecting Connect.

  3. Allow the installer to run. It installs the Debian base operating system and RC-Scanner packages automatically.

  4. Wait for the VM to shut down when installation is complete.

  5. Start the VM again and confirm that it reaches the login prompt.

  6. Shut down the VM before converting the disk.

Convert the disk to a fixed VHD

AWS requires a fixed VHD for this workflow. Do not upload the dynamic .vhdx file.

PowerShell

Open PowerShell as Administrator and run:

PowerShell
Convert-VHD -Path "C:\Path\To\RC-Scanner-Prep.vhdx" -DestinationPath "C:\Path\To\RC-Scanner-AWS.vhd" -VHDType Fixed

Hyper-V Manager

  1. Select Edit Disk….

  2. Locate the Hyper-V .vhdx file.

  3. Select Convert.

  4. Choose VHD as the disk format.

  5. Choose Fixed size as the disk type.

  6. Select the destination path and complete the wizard.

Use the resulting RC-Scanner-AWS.vhd file in the next phase.

Phase 2: Upload the VHD to Amazon S3

Install and verify AWS CLI

In PowerShell, run:

PowerShell
aws --version

If PowerShell reports that aws is not recognized, install AWS CLI v2 for Windows from AWS Command Line Interface. Close all PowerShell windows, open a new one, and run the version command again.

If the command still fails, check whether the executable exists:

PowerShell
Test-Path "C:\Program Files\Amazon\AWSCLIV2\aws.exe"
& "C:\Program Files\Amazon\AWSCLIV2\aws.exe" --version

Configure AWS credentials

  1. Open your organization's AWS access portal.

  2. Select Accounts, then open the appropriate AWS account.

  3. Select Access keys.

  4. Use the PowerShell instructions to obtain the access key ID, secret access key, and session token.

  5. Configure the AWS CLI:

PowerShell
aws configure

Verify the credentials:

PowerShell
aws sts get-caller-identity
aws s3 ls

AWS access keys and session tokens are sensitive credentials. Do not paste them into tickets, documentation, scripts committed to source control, or chat messages.

Create the S3 bucket

Choose a globally unique bucket name and create it:

PowerShell
aws s3 mb s3://<bucket-name>;

Verify that the bucket exists:

PowerShell
aws s3 ls

Upload the VHD

Locate the generated VHD, then upload it to the bucket:

PowerShell
aws s3 cp `
"C:\Path\To\RC-Scanner-AWS.vhd" `
"s3://<bucket-name>/"

Verify the object and its size:

PowerShell
aws s3 ls s3://<bucket-name>/

Phase 3: Import the VHD as an AMI

Verify EC2 import access

PowerShell
aws ec2 describe-import-image-tasks

An empty ImportImageTasks result is acceptable.

Verify the vmimport role

PowerShell
aws iam get-role --role-name vmimport

The command should return a role named vmimport. If the role does not exist, contact an AWS administrator.

Verify the vmimport policy

PowerShell
aws iam get-role-policy `
--role-name vmimport `
--policy-name vmimport

The policy must allow the import service to read the S3 bucket and register the imported image. If the policy does not include the bucket, an AWS administrator can update it with a policy similar to the following:

You need to append your new bucket to the existing list. If you only add your new bucket to the policy it will overwrite the existing ones.

JSON
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetBucketLocation",
        "s3:GetObject",
        "s3:ListBucket",
        "s3:GetBucketAcl"
      ],
      "Resource": [
        "arn:aws:s3:::<bucket-name1>",
        "arn:aws:s3:::<bucket-name1>/*"
        "arn:aws:s3:::<bucket-name2>",
        "arn:aws:s3:::<bucket-name2>/*"
        "arn:aws:s3:::<your-new-bucket>",
        "arn:aws:s3:::<your-new-bucket>/*"        
      ]
    },
    {
      "Effect": "Allow",
      "Action": [
        "ec2:ModifySnapshotAttribute",
        "ec2:CopySnapshot",
        "ec2:RegisterImage",
        "ec2:Describe*"
      ],
      "Resource": "*"
    }
  ]
}

Save the approved policy as C:\Temp\vmimport-policy.json and apply it:

PowerShell
aws iam put-role-policy `
--role-name vmimport `
--policy-name vmimport `
--policy-document file://C:\Temp\vmimport-policy.json

Updating IAM policies requires elevated AWS permissions. Use the organization's approved change process and least-privilege access.

Create the disk container definition

Create C:\Temp\containers.json:

JSON
[
  {
    "Description": "RC Scanner VM",
    "Format": "VHD",
    "UserBucket": {
      "S3Bucket": "<bucket-name>",
      "S3Key": "RC-Scanner-AWS.vhd"
    }
  }
]

Start the import

PowerShell
aws ec2 import-image `
--description "RC Scanner VM" `
--disk-containers file://C:\Temp\containers.json

Save the returned ImportTaskId. You need it to monitor the conversion.

Monitor the import

PowerShell
aws ec2 describe-import-image-tasks `
--import-task-ids import-ami-<task-id>


Status

Meaning

active

The import task is in progress.

deleting

The import task is being canceled.

deleted

The import task is canceled.

updating

Import status is updating.

validating

The imported image is being validated.

validated

The imported image was validated.

converting

The imported image is being converted into an AMI.

completed

The import task is completed and the AMI is ready to use.

When the import completes, the response includes an AMI identifier similar to:

JSON
{
  "Status": "completed",
  "ImageId": "ami-xxxxxxxxxxxxxxxxx"
}

Phase 4: Launch and Validate the EC2 Instance

Locate the AMI

  1. Open the AWS access portal and enter the appropriate account.

  2. Open the AWS Management Console with the required administrative role.

  3. Open EC2.

  4. Confirm that the selected AWS region matches the region used for the S3 bucket and import.

  5. Open Images → AMIs.

  6. Locate the AMI created during the import.

  7. Give the AMI a descriptive name and record its AMI ID.

Configure and launch the instance

For Instance size and firewall rules please refer to the following guides:
RC-Scanner Dimensioning Guide
Firewall Rules RC-Scanners

  1. Select the AMI and choose Launch instance from AMI.

  2. Enter a descriptive instance name.

  3. Select an instance type that meets the RC-Scanner sizing requirements.

  4. Select an existing EC2 key pair. Create or import one if required.

  5. Under Network settings, select the required VPC and subnet.

  6. Enable automatic public IP assignment if the instance must be reached directly over the internet.

  7. Configure security group rules according to the approved RC-Scanner firewall requirements.

  8. Allocate 30 GB of storage, or the amount required by the approved sizing guidance.

  9. Launch the instance.

Validate the instance

  1. Open EC2 → Instances.

  2. Confirm that the instance state is Running.

  3. Confirm that all displayed status checks have passed.

  4. Record the public IPv4 address, if one is assigned.

From PowerShell, test SSH connectivity:

PowerShell
Test-NetConnection <public-ip> -Port 22

Ping is not required for this test and may be blocked by the security group.

Phase 5: Connect and Complete Bootstrap

Connect over SSH

Use the instance public IPv4 address:

Bash
ssh rcscanner@<public-ip>

Use the following initial account details:

  • Username: rcscanner

  • Default password: outpost24

Change the default password immediately after the first login. Never leave the default credential active on a deployed scanner.

Please note that when you have changed your password you will be disconnected and need to reconnect using the new credentials.

Change the password

At first login, enter the default password when prompted, then provide a new password. Store the new credential according to your organization's password-management policy.

Retrieve the one-time bootstrap token

  1. Sign in to the OUTSCAN Portal.

  2. Open Configurations → RC SCANNER.

  3. Select the green + button.

  4. Select Continue.

  5. Copy the displayed one-time token.

Run the bootstrap

Run the following command in the SSH session:

Bash
rc-scanner-bootstrap --token <your-token>

For unattended setup, use:

Bash
rc-scanner-bootstrap --token <your-token> --headless

During an interactive installation, follow the prompts and press F3 when requested.

Verify registration

  1. Return to Configurations → RC SCANNER in the OUTSCAN Portal.

  2. Locate the new scanner.

  3. Confirm that its status changes from Initializing to Connected.

  4. Begin scanning only after the scanner shows as connected.

Troubleshooting

S3 access denied during import

Symptom: The import reports that the vmimport role is not authorized to perform s3:GetObject.

Cause: The role policy does not grant access to the bucket or object containing the VHD.

Resolution: Ask an AWS administrator to update the vmimport policy with access to the required bucket and object, then retry the import.

The vmimport role does not exist

Symptom: aws iam get-role --role-name vmimport returns NoSuchEntity.

Cause: The EC2 VM Import service role has not been created in the account.

Resolution: Contact an AWS administrator to create the role and its required trust and permissions policies.

Unsupported kernel version

Symptom: The import fails with an error such as Unsupported kernel version.

Cause: The kernel included in the RC-Scanner ISO is not supported by the AWS import process.

Resolution: Confirm whether a newer AWS-compatible RC-Scanner image is available. If not, escalate to the appropriate product or platform owner for guidance on a supported image.

The AWS CLI command is not recognized

Symptom: PowerShell reports that aws is not recognized.

Resolution: Install AWS CLI v2, close existing PowerShell windows, open a new session, and verify the executable path and PATH configuration.

SSH connectivity fails

Checks:

  • Confirm that the EC2 instance is running and status checks have passed.

  • Confirm that the public IPv4 address is current.

  • Confirm that TCP port 22 is allowed from the source network.

  • Confirm that the correct key pair and username are being used.

  • Use Test-NetConnection <public-ip> -Port 22 to isolate network reachability.