For the complete documentation index, see llms.txt. This page is also available as Markdown.

Deployment

Overview of the RUX deployment process, how to do your initial login, deployment steps along with requirements and documentation links.

Deployment Process Overview

  • A decision is made to engage in a Vectra Respond UX trial or purchase.

  • A welcome email will be sent after Vectra deploys a customer specific tenant where you can access the Respond UX.

    • The customer admin should validate access and configure additional user accounts and/or set up SAML SSO and role mapping for additional users as required. See Respond UX initial login for details.

    • Non network data sources can be configured at any time.

  • For network data sources

    • A Vectra Brain appliance is deployed by the customer or with the assistance of Vectra or a partner.

    • After the Brain is ready to be linked, Vectra links the Brain with your Vectra tenant.

    • All network data sources and graphical functionality are managed though the Respond UX.

      • There should be no requirement to access the Quadrant UX GUI before your Brain is linked to your Vectra tenant. The Quadrant UX is served from a Brain appliance locally before it is linked with Vectra for a Respond UX for Network deployment (using network data sources with the Respond UX).

  • Sensors are added and network traffic capture is initiated.

    • This should be done AFTER linking your Brain with Vectra.

  • Backup configuration (required for network data sources)

    • Some parts of your deployment (metadata, detections, triage rules, etc) are backed up in Vectra’s cloud but the Brain appliance must still be backed up locally in your environment.

    • Please see Backing up your Brain in Recommended next steps after deployment is completed for additional guidance.

Respond UX Initial Login

Once your Vectra tenant has been created, you will receive a welcome email from no-reply@vectra.ai with initial login details for the Respond UX. This will include a temporary password that expires in 7 days.

  • Please login within 7 days and create a permanent password.

    • Passwords must be between 15 and 128 characters and contain at least: 1 number, both lowercase and uppercase letters, and 1 symbol (e.g. ~!@#$%^&*,.?-_+=).

Please Note:

The initial admin password sent from Vectra is 18 characters long. Any new accounts created in the RUX UI will follow the password rules above. It is a best practice to configure SSO for most accounts where the IdP controls all password rules based on your policies and to use a strong password tied to MFA for "local" login to RUX for at least this admin account.

Brain Deployment

Per the introduction and overview earlier, when using network data sources, a Brain appliance must be deployed in your environment. The Brain appliance can be physical or virtual.

  • For physical Brain appliances:

    • You will need CLI (Command Line Interface) access to the appliance.

    • The initial configuration at the CLI is covered in the Quick Start Guide for your appliance.

    • Please refer to that guide to configure an IP address, network mask, default gateway, and proxy (if required) on the Brain.

    • See NDR physical appliances for quick start guides for appliances:

      • Physical appliances must be B-Series or X-Series to be used as a Brain or in Mixed-Mode.

      • The quick start physical appliance guides are meant just for getting the appliance installed and available on your network.

  • For virtual Brains deployed in IaaS clouds:

  • For virtual Brains deployed in traditional hypervisor environments such as VMware or Nutanix:

You may have already configured DNS following the quickstart for your physical appliance or the deployment guide for your virtual Brain. If you did not configure DNS as part of your initial Brain deployment, this guide will cover configuration of DNS later in the Data Sources → Network → Brain Setup section. It is recommended to have your Brain registered in your DNS to make failover scenarios easier to deal with and to enable reverse DNS lookup.

Proxy Support

If a proxy is required in your environment to communicate with Vectra from your Brain, this can be set at the CLI of your Brain. Login to your Brain’s CLI is done using the vectra user account. The default password is changethispassword for a newly deployed Brain. For Brains deployed in IaaS clouds (AWS, Azure), part of the deployment process includes creating an SSH key pair for login as the vectra user. The deployment guides for Brains in IaaS clouds include instructions for how to create and use those key pairs to log in to the Brain’s CLI.

  • Proxy commands (v7.9+)

    • show proxy

    • set proxy config [IP or Hostname] [port] [USERNAME] [PASSWORD]

    • set proxy enable [on|off]

    • Any of these with -h option will show command help with syntax.

Examples:

Converting Your Brain to Ready It for Linking to the Respond UX

Vectra engineering will convert your Brain into a different state from the base state (where it serves the Quadrant UX locally) into a state where it can be linked to the Vectra cloud for use with the Respond UX. Some virtual Brains have an option to deploy in a Respond UX ready state where they will not serve a local Quadrant UX UI. For Brains that are not put into this Respond UX ready state, the conversion/linking is kicked off by Vectra engineering after your Brain checks in with Vectra. After Vectra links to your Brain, the Respond UX (served from Vectra’s cloud) communicates with your locally installed Brain.

Once your Brain is installed (following the instructions from your Brain Quick Start or Deployment Guide, see links in the Requirements and Documentation Links above), please ensure it can communicate with Vectra

Guidance:

  • Ensure that if a proxy is required for communication with Vectra, it is configured per Proxy Support earlier.

  • Use the debug connectivity command at your Brain’s CLI to check connectivity to the following endpoints (from the firewall requirements earlier):

    • update2.vectranetworks.com

    • api.vectranetworks.com

    • rp.vectranetworks.com

    • rs.vectranetworks.com

    • You may also wish to check for connectivity to other Vectra cloud endpoints associated with the region of your RUX deployment. See endpoints in firewall requirements.

  • Use the show version command at your Brain’s CLI to see the current version and whether an upgrade is currently being applied.

    • New Brain versions may be in the process of downloading and preparing to be installed even while the result of the show version command shows Upgrading: False.

    • Please work with your Vectra team for additional detail. If your Brain is successful in communicating with Vectra, additional detail about the current state will be available to Vectra team members.

Examples:

Last updated

Was this helpful?