---
title: "Provisioning the PayGo Instance of vNIOS for AWS"
canonical: "https://docs.infoblox.com/space/NAIG/880115730/Provisioning%20the%20PayGo%20Instance%20of%20vNIOS%20for%20AWS"
format: markdown
---
This topic outlines the procedure to launch and provision an Infoblox vNIOS PayGo instance for your AWS VPC in the AWS console. This procedure is designed for users who want to provision an Infoblox vNIOS PayGo instance, which includes built-in licenses. It provides a comprehensive sequence of steps to manually provision a new Infoblox vNIOS PayGo instance in AWS in a non-HA and HA setup.

> Macro (toc)

When using the PayGo licensing model, the Infoblox vNIOS service can be directly installed from the AWS marketplace with a built-in license, eliminating the need for separate license purchases. This simplifies the deployment process, as the necessary licenses are included and automatically managed.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ DHCP services can run on NIOS instances deployed on AWS to offer instances that are outside AWS. Due to AWS restriction, DHCP cannot be offered for instances running on AWS.

If you are provisioning instances with an HA setup, an ability available from NIOS 9.0.4, then see the *[About Deploying a vNIOS for AWS Instance with High Availability](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/1867448335)* topic for a consolidated list of steps you must perform to deploy instances with HA.

# Obtaining the vNIOS for AWS AMI

Installation of the vNIOS for AWS AMI involves a series of steps in the AWS console on which you can configure and launch a new Infoblox vNIOS for AWS instance. You can launch an instance from the Amazon EC2 console or the AWS Marketplace console. For information about navigating to the **AWS Marketplace AMIs** tab, see the AWS Marketplace Documentation at [https://docs.aws.amazon.com/marketplace/](https://docs.aws.amazon.com/marketplace/)

## Obtaining the AMI Using the Amazon EC2 Console

To obtain the vNIOS for AWS AMI image from the EC2 console, complete the following steps:

1. Sign in to the Amazon EC2 console using your AWS account credentials.
2. On the *Console Home* page, in the **Services** box, search for and click **EC2** in the search results.
3. On the **EC2 Dashboard** tab > *Launch instance* section, expand **Launch** **instance**, and then choose **Launch instance**.  
The *Launch an instance* page is displayed.
4. Expand*** Application and OS Images (Amazon Machine Image)*** and click **Browse more AMIs**.
5. On the** *****Choose an Amazon Machine Image (AMI)*** page, click the **AWS Marketplace AMIs **tab.
6. Search for the name ***Infoblox NIOS PayGo*** and click **Select**.

## Obtaining the AMI from the AWS Marketplace Console

The AWS Marketplace console provides multiple ways to launch of an instance.

To launch an instance by using the AWS Marketplace URL:

1. Open the AWS Marketplace console:  
[https://aws.amazon.com/marketplace/pp/prodview-x5eshyamnuyc2](https://aws.amazon.com/marketplace/pp/prodview-x5eshyamnuyc2)
2. On the product overview page, click **View purchase options**.
3. Sign in with your credentials.
4. On the *Subscribe to Infoblox NIOS for AWS *page > in the *Offer details* section, click **Launch your software**.
5. On the *Launch Infoblox NIOS for AWS* page:
  1. **Setup**: Select **Amazon EC2**.
  2. **Launch** **method**: Select **Launch from EC2 Console**.  
Additional fields appear on the page.
  3. **Version**: The version is auto populated.
  4. **Region**: The region is auto populated.
6. From the **Choose Action** drop-down list, select **Launch through EC2**.
7. Click **Launch**.  
The *Launch an instance* page is displayed.

To launch an instance, complete the following steps:

1. Sign in to the Amazon web console using your AWS account credentials.
2. On the *Console Home* page, search for and click the **AWS Marketplace** service.
3. To launch an instance by using the **Manage subscriptions** option:
  1. In the left navigation pane, click **Manage Subscriptions**.
  2. Under *Active subscriptions*, type **Infoblox** in the search box to search for active subscriptions of Infoblox.  
Subscriptions appear in search results.
  3. In the **Infoblox NIOS PayGo** row, click **Launch**.
  4. On the *Infoblox NIOS for AWS AMI* page, click the **Launch a new instance** button.
4. To launch an instance by using the **Discover products** option:
  1. In the left navigation pane, click **Discover products**.
  2. In the **Search AWS Marketplace products** field enter **Infoblox** to search for Infoblox AMIs.
  3. In the displayed list, click ***Infoblox NIOS PayGo***.
  4. On the product overview page, click **View purchase options**.
  5. In the *Subscribe *page > *Offer details* section, click **Launch your software**.
5. On the *Launch* page, configure the following settings:
  1. **Setup**: Select **Amazon EC2**.
  2. **Launch** **method**: Select **Launch from EC2 Console**.  
Additional fields appear on the page.
  3. **Version**: The version is auto populated based on prior input.  
You can choose a prior version of NIOS from the drop-down list if needed.
  4. **Region**: The region is auto populated.
6. Click the **Launch from EC2** button.  
The *Launch an instance* page is displayed.

## Selecting an EC2 Shape

After launching an instance, configure the settings defined in this and the following sections to deploy it.

3. In the **Name and tags** section, enter the name and optional tags for the instance.
4. The **Application and OS Images** section displays the details of the selected image.
5. From the **Instance type** drop-down list, select the shape from the drop-down list. Ensure that the selected shape meets the minimum requirements of 8 CPU cores and 32 GB memory.

The following is a complete list of licenses that would be installed for PayGo images in AWS:  

| **NIOS** **VM** **Models** | **vCPU** | **Memory (GiB)** | **Amazon** **EC2** **Shape** | **Amazon EC2 Shape for Melbourne, Jakarta, Spain** | **Grid** **Master/ Grid** **Master** **Candidate** **(Yes/No)** |
| --- | --- | --- | --- | --- | --- |
| IB-V926 | 8 | 32 | m6i.2xlarge | m5.2xlarge | Yes |
| IB-V1516 | 16 | 64 | m6i.4xlarge | m5.4xlarge | Yes |
| IB-V1526 | 16 | 128 | r6i.4xlarge | r5d.4xlarge | Yes |
| IB-V2326 | 32 | 256 | r6i.8xlarge | r5d.8xlarge | Yes |
| IB-V4126 | 48 | 384 | r6i.12xlarge | r5d.12xlarge | Yes |

Hence, when you select an 8 vCPU configuration, the PayGo instance best suited for deployment on a **m6i.2xlarge **virtual machine will be the IB-V926.

6. Expand **Key pair (login)** and configure a key pair to securely connect to your instance. When you configure a key pair in AWS, the public key is uploaded to NIOS.  
Do one of the following:
7. In the **Key pair name** drop-down list, choose an existing key pair.
8. Click **Create new key pair** and complete the following in the *Create key pair* window:
  1. **Key pair-name**: Enter a name for the key pair.
  2. **Key pair type**: Select the required type.
  3. **Private key file format**: Select the format to use for the private key.
  4. Click **Create key pair**.
9. (Not recommended) If you want to perform a simple deployment, proceed without configuring a key pair.
10. Proceed to configure the network settings as defined in the *Defining Network Settings for the vNIOS for AWS Instance* section.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ If the vNIOS for AWS instance is a Grid Master, according to the authentication method configured for AWS SSH access for the admin account, you must use the key pair or key pair and password as the SSH login for all members in that Grid. For more information, see the *Creating Local Admins* topic in the* **[Infoblox NIOS Documentation](https://docs.infoblox.com)*.

# Defining Network Settings for the vNIOS for AWS Instance

Infoblox vNIOS virtual appliances require two network interfaces (MGMT and LAN1) for proper Grid communications. These interfaces must be assigned to separate subnets within the same VPC. Configuring the AWS member Management (MGMT) network and the Grid Master's LAN1 network in the same subnet is not supported. This can cause connectivity issues.

Note that the NIOS GUI communicates through the MGMT port. If for any reason you must make changes to the MGMT port, such as swapping NICs or changing the MGMT IP address from static to dynamic, ensure that you use the same IP address for the MGMT port before and after the changes. Otherwise, you might not be able to access the NIOS GUI.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ Network settings configured in your AWS cloud environment override changes made through the NIOS GUI or CLI. Therefore, when making changes such as adding, modifying, or deleting network interfaces through the NIOS GUI or CLI, ensure that the changes made to settings in NIOS are consistent with the corresponding settings in cloud networks.

<span style="color: #000000">On the </span><span style="color: #000000">*Launch an instance*</span><span style="color: #000000"> page of the AWS wizard, define the network settings for the new vNIOS for AWS instance, including the required network interfaces. Note that networks with IPv6 addresses are supported from NIOS 8.6.x onwar</span>ds. HA is not supported with IPv6 networks.

1. Expand **Network settings** and click **Edit**.
2. <span style="color: #000000">In the </span><span style="color: #000000">**VPC**</span><span style="color: #000000"> drop-down list, choose your VPC.</span>
3. In the **Subnet** drop-down list, choose the subnet to which the new instance must be assigned. Ensure that each VPC has a default subnet. You can select this subnet value for your configuration.  
If you have not yet created a subnet for your VPC, use the **Create new subnet** link to create a subnet.  
You may create more than one subnet. The subnet prefix values appear in the **Subnet** field for each network interface in your AWS console.
4. In the **Auto-assign** **Public** **IP** drop-down list, keep the default option, **Disable**.  
As you are creating an instance with two interfaces, AWS does not allow a Public IP assignment to the new vNIOS for AWS instance. AWS displays a warning to this effect when you create the second interface. (You may use an Elastic IP address or a private IP address.)
5. In the **Auto-assign IPv6 IP** drop-down list, perform one of the following:
  1. Keep the default option, **Disable** to assign only IPv4 addresses to the vNIOS instance.
  2. Choose **Enable** to also assign IPv6 addresses to the vNIOS instance. When the instance starts, it will be associated with both IPv4 and IPv6 addresses.  
For information on Infoblox NIOS appliances that support IPv6, see *[vNIOS for AWS X6 Series](https://docs.infoblox.com/space/vniosspec/1488781383/vNIOS+for+AWS+X6+Series)* and *[vNIOS for AWS X5 Series](https://docs.infoblox.com/space/vniosspec/1488551967/vNIOS+for+AWS+X5+Series)*.
6. Proceed to configure the security group as defined in the *Defining an AWS Instance Security Group* section.

## Defining an AWS Instance Security Group

> ⚠️ **Note**
> ⚠️ 
> ⚠️ - Configure the AWS Security Group for your instance to only accept traffic for SSH (22) and HTTPS (443) from the specific computers or subnets that are used to manage the Infoblox appliance.
> ⚠️ - If you are distributing the ports across multiple security groups, ensure that every security group that has the port required for NIOS is attached to the vNIOS instance.

In the **Network settings** > *Firewall (security groups)* section, define the firewall security settings for your new vNIOS for AWS instance. Amazon Web Services enforces a default Deny All policy for all security groups. Your new security group consists of a set of simple firewall rules that specifically allow known IP addresses and network prefixes to access your vNIOS for AWS instance and to use specific protocols. These are defined as Inbound rules. You may create a new security group or add new rules to an existing security group definition provided by your AWS administrator, depending on your AWS IAM privileges.

Use the following points and take appropriate action for creating new inbound rules:

- Permit SSH traffic (TCP/22) from the preferred prefix.
- Open the port for DNS (UDP/53).
- Permit secure web traffic (HTTPS/443) only from a Custom IP prefix representing the network of hosts that access the vNIOS instance for management and configuration.
- Open two ports for NIOS Grid Joining traffic:
  - UDP/1194
  - UDP/2114
- Open the port for the Infoblox API Proxy (TCP/8787).
- Open a port for VM VRRP (UDP/802) if the node is a member in an HA pair.
- Open the following ports if you want to deploy the reporting appliance IB-V5005 that is supported in NIOS 8.6.2 and later versions:
  - 7000 WebUI (Master,Indexer)
  - 7089 Management
  - 7887 Replication
  - 9997 Data Forwarding
  - 8000 WebUI
  - 8089 Management
  - 9185 Splunk REST API

Configure a minimum of six rules based on the list above.

> ⚠️ **Note**  
> ⚠️ You can also add a rule, named '**myip**' or similar, to allow access from your desktop computer to the VPC. Simply select **My** **IP** from the **Source** drop-down list.

Avoid using any prefixes other than those that must access the Infoblox vNIOS for AWS instances in the VPC.

1. In the *Firewall (security groups)* section, select **Select existing security group**, and then select an existing group from the **Common security groups** drop-down list, or create a new security group as follows:
  1. Select **Create security group**.
  2. In the **Security group name** field, enter a name for the security group.
  3. In the **Description** field, write a description for the security group.
  4. To add the first rule to the group, complete the following:
    1. Click **Add security group rule**.
    2. In the **Type** drop-down list, choose **Custom SSH**,
    3. In the **Source type** drop-down list, choose **Custom**.
    4. In the **Source** field, enter the IPv4 prefix containing the computer hosts that use SSH connections to the new vNIOS for AWS  instance.   
Note that you may need more than one rule if you have users from multiple networks accessing your instance.
  5. To add another rule to the group:
    1. Click **Add** **security group rule**.
    2. In the **Type** drop-down, choose **Custom HTTPS**.
    3. In the **Source type** drop-down list, choose **Custom**.
    4. In the **Source** field, enter the IPv4 prefix containing the computer hosts that connect to Grid Manager for the new vNIOS for AWS instance.  
Note that you may need more than one rule if you have multiple networks accessing your instance.
2. Proceed to add network interfaces as defined in the *Defining Advanced Network Configuration* section.

## Defining Advanced Network Configuration

For a non-HA deployment, you must use two interfaces for the new vNIOS for AWS instance, network interface 1 and network interface 2 that are labelled as MGMT and LAN1 respectively in NIOS. Use network interface 1 to join the Infoblox vNIOS for AWS instance to a NIOS Grid. By default, the network interface 1 is assigned with an IPv4 address.

For an HA deployment, complete the steps defined in the *Defining Advanced Network Configuration for HA* section.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ When you need to add a network interface to an existing vNIOS for AWS instance, you must power off the instance, add the interface, and then start the instance.

1. Under Network interface 1, which is for the MGMT port, retain the settings as is.   
You will notice that the subnet selected in the **Subnet** field is displayed here.  
**Note**:  
If you need to set a static IP address on the MGMT interface when configuring a vNIOS instance with multiple interfaces (LAN1 and MGMT), set it from the Grid Manager UI; for steps, refer to the *[Infoblox NIOS documentation](https://docs.infoblox.com/)**. *If you try to set the IP address by using the `set interface mgmt` command, the command will fail to enable the MGMT interface because NIOS assumes that the LAN1 IP address of a vNIOS instance deployed on any cloud platform is always dynamic.
2. To add the LAN1 port, click **Add network interface**.
3. Under Network interface 2, in the **Subnet** drop-down list, choose a subnet.  
The selected subnet and security groups must be in the same VPC.
4. For SSH access to the vNIOS for AWS instance, you must always use the IP address associated with the **LAN1** port.
  1. Choose the default **Subnet** from the drop-down list. (For more information on usage of Elastic IP addresses for interfaces in your Infoblox vNIOS for AWS instances, see *[Using an Elastic IP Address](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37650876)*.)
  2. To set the AWS server to also assign IPv6 address to the interface, in the *IPv6 IPs* drop-down list, select **Add IP**.
5. Proceed to configure storage settings as described in the *Defining Storage Settings for the vNIOS for AWS Instance* section.

## Defining Advanced Network Configuration for HA

> Macro (excerpt-include)



# Defining Storage Settings for the vNIOS for AWS Instance

You can use the settings under **Configure storage** to define the storage resources to be used by the new instance. Infoblox vNIOS for AWS instances provide a defined amount of instance data storage. The storage size varies according to the AMI you have chosen for the instance. For more information, see *[vNIOS for AWS X6 Series](https://docs.infoblox.com/space/vniosspec/1488781383/vNIOS+for+AWS+X6+Series)* and *[vNIOS for AWS X5 Series](https://docs.infoblox.com/space/vniosspec/1488551967/vNIOS+for+AWS+X5+Series)*. You can adjust the amount of instance storage to its maximum value and attach external storage volumes for an additional cost.

1. For a root volume, retain the default values for size and volume type.  
The default values differ based on the AMI that you select.
2. To define settings for Elastic Block Storage volumes, click **Advanced**.  
The default configuration of volume 1 is displayed.
3. In the **Storage (volumes)** > *EBS Volumes* > *Volume 1 (AMI Root)* section, complete the following steps for Elastic Block Storage (EBS) volumes:
  1. **Size (GiB)**: Retain the default value.
  2. **Volume type**: Choose **gp3** from the drop-down list.
  3. **Delete on termination**: Choose **Yes** if you want to delete the volume when the instance is terminated, or choose **No** to keep the volume.  
You can use this setting for your vNIOS for AWS instances to de-couple the root partition deletion from the state of the new EC2 instance. This allows retention of the volume for debugging and event log inspection.  
Infoblox recommends keeping at least the minimum storage capacity defaults for the new Infoblox vNIOS for AWS instance.
  4. **Encrypted**: To enable encryption on the EBS volume, choose **Encrypted**.  
Encryption of EBS volumes is supported only in NIOS 8.6.3 and later versions of 8.6.x.
  5. **KMS key**: Select a key that must be used to encrypt the volume.  
This field is accessible only when encryption is enabled.
4. (For reporting appliances only) If you are deploying the vNIOS for AWS instance for reporting, you must create two virtual hard disks. One as the default disk used for storing regular NIOS data and a second disk for storing the reporting data. To add a second disk:
  1. In the **Configure storage***/****Storage (volumes)*** section, click the **Add New Volume** button.
  2. In the **Size (GiB)** field, specify a size for the disk. Infoblox recommends that you allocate a minimum of 250 GB of additional disk space for the reporting storage requirements.

# Defining Advanced Details

Use the settings under **Advanced Details** to define settings such as user data, IAM role, and Tenancy.

## Initializing vNIOS for AWS Instances with the AWS User Data Field

You can provision the vNIOS for AWS PayGo instance through the **Advanced** **Details** -> **User** **data** field without using Elastic Scaling. For more information about cloud-init configuration supported in vNIOS, see <u>*[cloud-init Configuration in vNIOS for AWS](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/1929510916)*</u>.

Follow these instructions to define administrator login settings and initial configuration for the new instance::

1. Expand **Advanced Details** and scroll down to the **User data** field.
2. Define the following plain-text values in the **User data** field:
  1. `remote_console_enabled`: Enables or disables the remote SSH CLI console for a new instance (syntax: y or n).
  2. `default_admin_password`: Sets the password for the NIOS admin user during the first boot. This value does not have to be a default; it can be the password of any administrator who initializes the new instance. The minimum password length is four characters. If an invalid password is passed by this method, it will be ignored, and the default "infoblox" password remains in effect for the instance. Note that if you want to include a symbol character at the beginning of the password, ensure that you put the password in quotes ('') to avoid login issues. Example: '!Infoblox'.
    - For a Grid Master or a standalone vNIOS for AWS instance, the default NIOS password must be reset on the first login in the NIOS UI. Otherwise, you can configure the new password in the **User data** field and log in to the NIOS UI using that password. The minimum password length is four characters. It must consist of at least one uppercase character, one lowercase character, one numeric character, and one symbol character. Example: Infoblox1!  
Consider the following points for defining a password:
      - If the symbol character is at the beginning of the password, then include the password within quotes (''). Example: '@Infoblox123'.
      - If you enter an invalid password, you will be prompted to reset the password in the NIOS UI on the first login.
      - The password that you set for the Grid Master is propagated to all its members.
    - To access the NIOS CLI, you must either use the key pair or key pair + password authentication that is configured in NIOS, because access to the CLI by using only the NIOS UI password is blocked.

All user data settings are optional directives that can be included or left out of a configuration. For example, you can include the `remote_console_enabled` and `default_admin_password` to the Elastic Scale configuration in Figure *Adding the Grid Master, Token and Certificate information to the AWS vNIOS Instance* in topic *[Provisioning Infoblox vNIOS for AWS using Elastic Scaling](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37716415)*. In the PayGo model, the `temp_license` command is not required since all necessary licenses are automatically included with the instance. Therefore, there is no need to manage or specify licenses manually, and the absence of the `temp_license` command will not affect the operation or scaling of the instance.* *For more information, see *[Provisioning Infoblox vNIOS for AWS using Elastic Scaling](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37716415)*.  
  
<span style="color: #000000">Example:</span>

`#infoblox-config `

`gridmaster: `

`ip_addr: 172.16.1.2`  
` remote_console_enabled: y `

`default_admin_password: '#$&$#!' `


> ⚠️ **Note**  
> ⚠️ <span style="color: #000000">The SSH key will not be uploaded if the ssh_authorized_keys parameter is given in the User data. For information to upload the SSH key, see the </span><span style="color: #000000">*Completing Your Infoblox vNIOS for AWS Instance Launch*</span><span style="color: #000000"> section.</span>

## Attaching an IAM Role to the Instance

In the **Advanced details** section, you can configure the IAM role for the vNIOS for AWS instance.

### For a Non-HA Instance

To define, from the **IAM instance profile** drop-down list, choose a profile. 

You may use default settings for your initial testing. It can also be defined on the *Identity* *and* *Access* *Management* page in the AWS console. Your AWS administrator may not allow custom IAM accounts for your deployment, so this may not be a selectable value.

### For an HA Instance

Assign the IAM role that you created as part of *[prerequisites](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/636354593)* to the vNIOS instances of node1 and node2 that you are creating.  
To assign, expand **Advanced Details** and select the IAM role from the **IAM instance profile** drop-down list.

For more information about Amazon IAM, see the Amazon IAM documentation page at [http://docs.aws.amazon.com/IAM/latest/UserGuide/IAM_Introduction.html](http://docs.aws.amazon.com/IAM/latest/UserGuide/IAM_Introduction.html).

## Defining Tenancy Setting

In the **Advanced details** section, you can configure the tenancy settings for the vNIOS for AWS instance from the Tenancy drop-down list. Keep the tenancy setting as is. For information about tenant settings, see *[About Tenants](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37454198)*.

# Defining Name and Tags for the vNIOS for AWS Instance

An AWS tag is a name-value pair. You can define tags for categorizing, searching, and identifying Amazon objects such as EC2 instances, subnets, VPCs, and IP addresses.

Use AWS tags with Infoblox extensible attributes to identify resources for IP address assignments. If you already have extensible attributes defined for your Infoblox Grid, you can add the same extensible attributes to the new vNIOS for AWS instance. The tags that you define here apply only to the instance. You can choose to create tags when provisioning an instance or at a later time.

You can use extensible attributes to tag Infoblox network containers and networks, and to tag corresponding Amazon VPCs and subnets for assigning IP addresses to the new resources in the cloud. Without the NIOS extensible attributes definitions, the tags defined on the AWS objects will only be meaningful in AWS, and you cannot search and match against managed AWS objects in Grid Manager. For information about cloud extensible attributes, see *Extensible* *Attributes* *for* *Cloud* *Objects* in the *[Infoblox NIOS Documentation](https://docs.infoblox.com/)*.

> ⚠️ **Note**  
> ⚠️ AWS Tags that have a matching tag defined in NIOS extensible attributes have the tag value replicated into NIOS.

1. In the *Name and tags* section of the *Launch an instance* page, type a name for your instance in the **Name** field.  
The name is a tag defined by a key-value pair in which **Name** is the key and the value that you specify is the value.
2. To define an additional tag, click **Add additional tags** and specify values in the **Key** and **Value** fields.

## Tagging Existing AWS Objects

To tag existing objects in AWS,  select a VPC > subnet within a VPC > an EC2 instance or other object types residing in AWS, and then use the **Manage tags** button on the **Tags** tab.

*Adding Tags to AWS Objects*

![image](media://d22221f3-06ef-45ae-a2a7-df1cb4c587b7)

In NIOS, define the extensible attributes for each network in the **Cloud** -> **Networks** page, or under IPAM within the network view.

When you consistently use AWS tags and extensible attributes in your networks, they become more useful and valuable. For example, you can use Infoblox API extensions with the extensible attributes that are appropriate for your applications. For more information, see *[Infoblox Extensions to the AWS API](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37748981)*.

# <span style="color: #000000">Completing Your Infoblox vNIOS for AWS Instance Launch</span>

<span style="color: #000000">The S</span><span style="color: #000000">*ummary*</span><span style="color: #000000"> panel on the </span><span style="color: #000000">*Launch*</span><span style="color: #000000"> </span><span style="color: #000000">*an Instance*</span><span style="color: #000000"> page lists settings that you have configured. Each setting is a link. You may click on a setting to navigate to that section directly and make appropriate changes.</span>

<span style="color: #000000">Click the </span><span style="color: #000000">**Launch instance**</span><span style="color: #000000"> button to launch the vNIOS for AWS instance. </span>After a brief period of time, the vNIOS for AWS instance will be active in your VPC.  
You can p<span style="color: #000000">erform additional tasks for the vNIOS for AWS configuration to ensure that the virtual appliance is functioning prope</span>rly. For more information, see *[Additional Configuration for vNIOS for AWS](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37552414)*.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ - Access to the CLI using the NIOS password is blocked, except for the root user. To gain CLI entry, other users have to allow SSH keys in the NIOS Grid Manager.
> ⚠️ - For a Grid Master or a standalone vNIOS for AWS instance, the default NIOS password must be reset on the first login in the NIOS UI.
> ⚠️ - The Infoblox standard configuration for vNIOS for AWS deployment requires use of a VPN connection or a direct connection to the Amazon VPC(s) on which you are deploying and operating vNIOS for AWS instances. This connection does not require an Internet-connected IP address or a secure key pair.
> ⚠️ - All AWS Proxy API operations require use of an assigned and regularly rotated AWS-generated key pair assigned to the **cloud-api-only** account in Grid Manager. For information, see *[Assigning AWS User Credentials to the NIOS Cloud Admin Account](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37454198)*.

# Connecting to the EC2 Serial Console of the Instance

vNIOS for AWS instances running on NIOS 8.6.3 or later versions of 8.6.x and deployed with r6i EC2 shapes, support connecting to the EC2 serial console on the vNIOS for AWS instance. You can connect to the serial console to perform activities such as installing licenses or for troubleshooting purposes.  
To connect to the EC2 serial console, complete the following steps:

1. In the Amazon EC2 console, navigate to the *Instances* page.
2. Select the instance for which you want to access the serial console and click **Connect**.
3. On the *Connect to instance* page > **EC2 serial console** tab, click **Connect**.

# License List

The following is a complete list of licenses that will be installed for PayGo instances in AWS:

- DNS
- DHCP
- GRID
- NIOS
- DNS Traffic Control
- Response Policy Zone
- Cloud Network Automation

# vNIOS PayGo Configuration Guidelines

The following guidelines apply to vNIOS Paygo instances:

- PayGo instances cannot be switched to non-PayGo instances.
- PayGo instances are licensed immediately upon launch, and the licenses remain in force as long as you pay for the instance.
- You cannot downgrades PayGo instances to versions below NIOS 9.0.5.
- If there are temporary licenses in cloud-init data, they are skipped during configuration.
- Infoblox does not recommend restoring AWS/Azure snapshots, AMIs, or images for PayGo instances.
- If a PayGo instance lacks sufficient resources and does not meet the minimum requirements, it fails to boot into NIOS, and an error message is displayed on the console. If a PayGo instance does not meet the required CPU or memory specifications, NIOS fails to start and triggers an error message indicating insufficient resources.
- If the memory or CPU configuration of a PayGo instance is altered from the original NIOS model, the instance does not start, and an error message regarding a NIOS license mismatch is triggered on the console.