# Create Finmars CE VM

<span style="white-space: pre-wrap;">Sure! Let’s make your EC2 and name it </span>****finmars-platform-vm****. Follow these steps:

1. ****Sign in to AWS****
    - <span style="white-space: pre-wrap;">Open your browser and go to </span>[console.aws.amazon.com](https://console.aws.amazon.com).
    - Enter your AWS email and password.
2. ****Open EC2****
    - <span style="white-space: pre-wrap;">At the top, click the search box and type </span>****EC2****.
    - <span style="white-space: pre-wrap;">Click </span>****EC2****<span style="white-space: pre-wrap;"> under “Services.”</span>
3. ****Launch a new instance****
    - <span style="white-space: pre-wrap;">Click the blue </span>****Launch instances****<span style="white-space: pre-wrap;"> button.</span>
4. ****Name your instance****
    - <span style="white-space: pre-wrap;">In the </span>****Name tag****<span style="white-space: pre-wrap;"> box, type </span>****finmars-platform-vm****.
5. ****Choose AMI (****[Finmars CE](https://aws.amazon.com/marketplace/pp/prodview-55ptwgyybwzp2) ****x.x.x) - latest version****
6. - [![Screenshot 2025-06-27 at 15.44.08.png](https://docs.finmars.com/uploads/images/gallery/2025-06/scaled-1680-/screenshot-2025-06-27-at-15-44-08.png)](https://docs.finmars.com/uploads/images/gallery/2025-06/screenshot-2025-06-27-at-15-44-08.png)
    - <span style="white-space: pre-wrap;">Scroll or search for </span>****Finmars CE (e.g. Finmars CE 19.1.0)**** in AWS &amp; Trusted third-party AMIs tab.
    - <span style="white-space: pre-wrap;">Click </span>****Select****.
7. ****Select instance type (2 vCPU, 8 GiB RAM)****
    - <span style="white-space: pre-wrap;">Find and click </span>****t3.large****<span style="white-space: pre-wrap;"> (it has 2 vCPU and 8 GiB).</span>
8. ****Create or select key pair****
    - <span style="white-space: pre-wrap;">Choose </span>****Create a new key pair****.
    - <span style="white-space: pre-wrap;">Name it (e.g. </span>****finmars-platform-vm-key****).
    - <span style="white-space: pre-wrap;">Click </span>****Create Key Pair****<span style="white-space: pre-wrap;"> and save the </span>`<span class="editor-theme-code">.pem</span>`<span style="white-space: pre-wrap;"> file safely. - </span><span style="color: rgb(224, 62, 45);">Do not Lose this file, if you lose it, you will not able to connect to your VM again</span>
9. ****Configure instance details****
    - <span style="white-space: pre-wrap;">Click </span>****Edit****
    - <span style="white-space: pre-wrap;">Under </span>****Subnet - No Preference****<span style="white-space: pre-wrap;"> or</span> pick one (any is fine).
    - <span style="white-space: pre-wrap;">Turn </span>****Auto-assign Public IP****<span style="white-space: pre-wrap;"> to </span>****Enable****. (If already enabled - OK)
    - Configure Inbound Security Group Rules
    - <span style="white-space: pre-wrap;">Add </span>`<span class="editor-theme-code">Security Group Rule 1</span>`<span style="white-space: pre-wrap;"></span>
        - <span style="white-space: pre-wrap;">Type: </span>****SSH****<span style="white-space: pre-wrap;"></span>
        - <span style="white-space: pre-wrap;">Source Type: </span>****Anywhere****<span style="white-space: pre-wrap;"></span>
        - <span style="white-space: pre-wrap;">Port range: </span>****22****
    - <span style="white-space: pre-wrap;">Add </span>`<span class="editor-theme-code">Security Group Rule 2</span>`
        - <span style="white-space: pre-wrap;">Type: </span>****HTTP****
        - <span style="white-space: pre-wrap;">Source Type: </span>****Anywhere****
        - <span style="white-space: pre-wrap;">Port Range: </span>****80****
    - <span style="white-space: pre-wrap;">Add </span>`<span class="editor-theme-code">Security Group Rule 3</span>`<span style="white-space: pre-wrap;"></span>
        - <span style="white-space: pre-wrap;">Type: </span>****HTTPS****<span style="white-space: pre-wrap;"></span>
        - <span style="white-space: pre-wrap;">Source Type: </span>****Anywhere****
        - <span style="white-space: pre-wrap;">Port Range: </span>****443****
    - Add `<span class="editor-theme-code">Security Group Rule 4</span>` ****-**** <span style="color: rgb(224, 62, 45);">this is important for further Installation</span><span style="white-space: pre-wrap;"></span>
        - <span style="white-space: pre-wrap;">Type: </span>****Custom TCP****
        - <span style="white-space: pre-wrap;">Source Type: </span>****Anywhere****
        - Port Range: ****8888****
    - Leave the rest as default.
    - [![Screenshot 2025-06-26 at 20.03.45.png](https://docs.finmars.com/uploads/images/gallery/2025-06/scaled-1680-/screenshot-2025-06-26-at-20-03-45.png)](https://docs.finmars.com/uploads/images/gallery/2025-06/screenshot-2025-06-26-at-20-03-45.png)
    
    <span style="white-space: pre-wrap;">See </span>****Edit****<span style="white-space: pre-wrap;"> in Top Right Corner. Press it</span>  
    [![Screenshot 2025-06-26 at 20.04.45.png](https://docs.finmars.com/uploads/images/gallery/2025-06/scaled-1680-/screenshot-2025-06-26-at-20-04-45.png)](https://docs.finmars.com/uploads/images/gallery/2025-06/screenshot-2025-06-26-at-20-04-45.png)  
    See Configured Security groups
    - <span style="white-space: pre-wrap;">Click </span>****Next: Add Storage****.
10. ****Add storage (256 GiB)****
    - <span style="white-space: pre-wrap;">Change the size from </span>****8****<span style="white-space: pre-wrap;"> to </span>****256****<span style="white-space: pre-wrap;"> in the root volume row.</span>
    - <span style="white-space: pre-wrap;">Keep the volume type as </span>****gp3****<span style="white-space: pre-wrap;"> or </span>****gp2****.
11. ****Review and launch****
    - Check all your settings.
    - <span style="white-space: pre-wrap;">Click </span>****Launch Instance****.
12. ****Wait for your VM****
    - <span style="white-space: pre-wrap;">Click </span>****View Instances****.
    - <span style="white-space: pre-wrap;">Wait until its status is </span>****running****<span style="white-space: pre-wrap;"> and checks pass.</span>
13. ****Open Finmars Setup in your Web Browser****
    - Go to http://****Your\_Public\_IP****:8888 (for example http://203.0.113.25:8888)
    - Proceed with Setup Wizard

<span style="white-space: pre-wrap;">Your EC2 named </span>****finmars-platform-vm****<span style="white-space: pre-wrap;"> is ready! 🎉</span>

---

  
Now you need to assign your Public IP of your freshly created VM to subdomain of your domain.

1. ****Sign in to AWS****  
    <span style="white-space: pre-wrap;">Go to </span>[console.aws.amazon.com](https://console.aws.amazon.com)<span style="white-space: pre-wrap;"> and log in.</span>
2. ****Open Route 53****  
    <span style="white-space: pre-wrap;">In the top search bar, type </span>****Route 53****, then click the service.
3. ****Go to Hosted Zones****  
    <span style="white-space: pre-wrap;">In the left menu, click </span>****“Hosted zones.”****
4. ****Select your domain****  
    <span style="white-space: pre-wrap;">Find and click the zone named your\_domain.tld (for example, </span>`<span class="editor-theme-code">example.com</span>`).
5. ****Create the first record****
    - <span style="white-space: pre-wrap;">Click </span>****“Create record.”****
    - <span style="white-space: pre-wrap;">In </span>****Record name****<span style="white-space: pre-wrap;">, type </span>`<span class="editor-theme-code">finmars</span>`<span style="white-space: pre-wrap;"> (so full name is </span>`<span class="editor-theme-code">finmars.example.com</span>`). - It is Record for Actual Finmars Platform
    - <span style="white-space: pre-wrap;">For </span>****Record type****<span style="white-space: pre-wrap;">, choose </span>****A – IPv4 address****.
    - <span style="white-space: pre-wrap;">In </span>****Value****<span style="white-space: pre-wrap;">, type your EC2 public IP (for example, </span>`<span class="editor-theme-code">203.0.113.25</span>`<span style="white-space: pre-wrap;">). You can find it in EC2 details </span>
    - <span style="white-space: pre-wrap;">Leave </span>****TTL****<span style="white-space: pre-wrap;"> as default (300).</span>
    - <span style="white-space: pre-wrap;">Click </span>****“Create records.”****
6. ****Create the second record****
    - <span style="white-space: pre-wrap;">Click </span>****“Create record”****<span style="white-space: pre-wrap;"> again.</span>
    - <span style="white-space: pre-wrap;">In </span>****Record name****<span style="white-space: pre-wrap;">, type </span>`<span class="editor-theme-code">finmars-auth</span>`<span style="white-space: pre-wrap;">(so full name is </span>`<span class="editor-theme-code">finmars-auth.example.com</span>`). - It is Record for Single-Sign-On (SSO) Finmars
    - <span style="white-space: pre-wrap;">For </span>****Record type****<span style="white-space: pre-wrap;">, choose </span>****A – IPv4 address****.
    - <span style="white-space: pre-wrap;">In </span>****Value****, type the same EC2 public IP.
    - <span style="white-space: pre-wrap;">Click </span>****“Create records.”****
7. ****Wait a few minutes****  
    DNS needs a little time to spread out. After about 5 minutes, both
    - `<span class="editor-theme-code">finmars.example.com</span>`
    - `<span class="editor-theme-code">finmars-auth.example.com</span>`  
        will go to your VM’s public IP.

<span style="white-space: pre-wrap;">That’s it! Now both sub-domains point to your </span>****finmars-platform-vm****<span style="white-space: pre-wrap;"> server.</span>

You can verify it by run following command in Terminal (On Mac or Linux)  
  
`<span class="editor-theme-code">dig finmars.example.com</span>`  
`<span class="editor-theme-code">dig finmars-auth.example.com</span>`

  
Output should be like:

```bash
; <<>> DiG 9.10.6 <<>> finmars.example.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39082
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;finmars-platform-vm.finmars.com. IN	A

;; ANSWER SECTION:
finmars.example.com. 300 IN	A	203.0.113.25

;; Query time: 12 msec
;; SERVER: 192.168.178.1#53(192.168.178.1)
;; WHEN: Wed Jun 11 20:10:02 CEST 2025
;; MSG SIZE  rcvd: 76
```

---

  
  
<span style="white-space: pre-wrap;">Now go to next step: </span>[Install Finmars Platform](https://docs.finmars.com/books/installation-guide-with-aws-simple/page/setup-finmars-ce)