Before you deploy your Network Detection and Response Console instance on a VMware ESXi host, make sure the following requirements are met.
Note
This guide provides the basic steps for creating and deploying an instance. For comprehensive information about deploying virtual machines, see the documentation provided by VMware, Inc.
VMware requirements
VMware ESXi host version 6.5 or later. Earlier ESXi versions are not supported.
VMware vSphere Web Client.
VMware vCenter Server.
Additional hard disk with the required memory (see Storage requirements).
Standard virtual switch attached to a physical network adapter on the ESXi server. Required for NDR Console cluster.
Sufficient physical network adapters on the ESXi server to accommodate clusters.
One interface is required for management. A second interface is required for private network clustering.
Virtual machine requirements
The following minimum requirements must be met.
CPU cores: 16 (minimum)
Note
Add CPU cores as needed to meet your anticipated network bandwidth.
RAM: 64 GB
Hard Disk Space:
Disk 1 (Operating System): 120 GB
Disk 2 (Capture Meta Data): See Storage requirements and Setting up storage
Note
A minimum storage recommendation of 100 Mbps throughput.
Important
The OVA image includes a single hard disk. You must add a second hard disk with the required memory to accommodate the capture metadata. Be sure to add the disk or increase other resources before you power on the metadata virtual machine the first time and perform the initial configuration. Otherwise, your licenses will be invalidated.
Storage requirements
The storage space that packet captures require depends on the traffic rate and the length of time they are retained. The following table shows the storage requirements at various traffic rates and the space required over time.
Events/minute | 1 month retention | 3 months retention | 6 months retention | 12 months retention |
|---|---|---|---|---|
200,000 | 5TB | 15 TB | 30 TB | 60 TB |
600,000 | 10 TB | 30 TB | 60 TB | 120 TB |
1,000,000 | 15 TB | 45 TB | 90 TB | 180 TB |
Network requirements
Network information— Gather the following information from your network administrator:
One of the following:
DHCP allocated IP address for the virtual machine.
Static IP address, subnet mask, and default gateway address for the virtual machine.
IP address for each Domain Name System (DNS) server.
IP address for each Network Time Protocol (NTP) server.
Network access— See the Trellix Ports and Protocols Reference Guide for a list of the required ports for network access.
License requirements
The following license is required for system operation.
FIREEYE_APPLIANCE is the base product license that is tied to your activation code. It enables NDR Console features and functionality.
NDR License is either the ESSENTIALS/CORE or ENTERPRISE license keys for NDR functionality.
CONTENT_UPDATES for downloading security content packages from the DTI server.
Minimum System Requirements for NDR-CORE and NDR-ENTERPRISE Licenses
Minimum RAM: 64 GB
Minimum CPU: 16 cores
Note
These requirements apply to all Virtual NDR Console variants when using an NDR Console-CORE or NDR Console-ENTERPRISE license.
Limitations
You cannot change the number of network interfaces on a virtual appliance.
Changing storage policy and adding partitions is not supported.
The following VMware features are not supported:
Virtual SMP
Update Manager
Data Protection
High Availability (HA)
vMotion (including Storage vMotion, Enhanced vMotion Compatibility, and Cross-vSwitch vMotion)
Storage APIs for Data Protection
Memory hot add
Endpoint
Replication
Fault Tolerance
Virtual Volumes
Offline operational mode