Hyper-V prerequisites

Prev Next

Before you deploy your Network Detection and Response Console instance on a Hyper-V, make sure the following requirements are met.

Hyper-V requirements

  • Windows server with sufficient resources to bring up NDRC and other VM’s if required.

  • Hyper-V feature/server roles are installed.

  • Standard virtual switch, connected to an external network and shared by the operating system.

Windows servers and hypervisor versions:

Windows Server

Hypervisor Version

Windows 2025 Server

Edition : Windows Server 2025 Datacenter Evaluation

Version : 24H2 or above

Os Build : 26100.1742

Hyper-V Manager

Microsoft Corporation

Version: 10.0.26100.1 or above

Windows 2022 Server

Edition : Windows Server 2022 Datacenter Evaluation

Version : 21H2 or above

Os Build : 20348.587 or above

Hyper-V Manager

Microsoft Corporation

Version: 10.0.20348.1 or above

Windows 2019 Server

Edition : Windows Server 2019 Standard

Version: 10.0.17763 or above

Build:17763 or above

Hyper-V Manager

Microsoft Corporation

Version: 10.0.17763.1 or above

Note

Hyper-V Manager might fail to create a new Generation 1 VM on a host with more than 128 logical CPUs when running Wndows Server 2025. In this situation, use PowerShell commands to create a Generation 1 VM instead. See the Setup using PowerShell (Generation 1) section.

After the VM is successfully created using the VM name via PowerShell commands, you can proceed with the standard configuration steps using the Hyper-V Manager interface.

Virtual machine requirements

The following sections list the virtual machine requirements in virt-manager and Proxmox Virtual Environment (VE) deployments.

  • CPU cores: 16 (minimum)

    Note

    Add CPU cores as needed to meet your anticipated network bandwidth.

  • RAM: 64 GB

  • Hard disk space:

    Important

    A minimum storage recommendation of 100Mbps throughput.

    • Disk 1 (Operating System): 120 GB

    • Disk 2 (Capture Data): 200 GB

  • Storage: SCSI

Network requirements

  • Network information— Gather the following information from your network administrator:

    • DHCP allocated IP address for the virtual machine.

      OR

    • Static IP address, subnet mask, and default gateway address for the virtual machine.

    • IP address for each Domain Name System (DNS) server.

    • IP address for each Network Time Protocol (NTP) server.

  • Network access— See the Trellix Ports and Protocols Reference Guide for a list of the required ports for network access.

License requirements

The following license is required for system operation.

  • FIREEYE_APPLIANCE is the base product license that is tied to your activation code. It enables NDR Console features and functionality.

  • CONTENT_UPDATES for downloading security content packages from the DTI server.

  • NDR License is either the ESSENTIALS/CORE or ENTERPRISE license keys for NDR functionality.

  • Minimum System Requirements for NDR-CORE and NDR-ENTERPRISE Licenses

    Note

    These requirements apply to all Virtual NDR Console variants when using an NDR Console-CORE or NDR Console-ENTERPRISE license.

    • Minimum RAM: 64 GB

    • Minimum CPU: 16 cores