For the complete documentation index, see llms.txt. This page is also available as Markdown.

FedRAMP High environment deployment guidance (RUX)

Details specific to Vectra AI Platform Respond UX deployments in the FedRAMP High authorized environment.

Please Note:

This page of the Respond UX Deployment Guide only applies to FedRAMP High environment deployments. For commercial environment RUX deployments, this page can be skipped and you can move on to Firewall Requirements.

Introduction

Vectra AI Platform (RUX deployments) can be provisioned in our US Gov (FedRAMP High) region. This is a FedRAMP High authorized environment.

Customer Brain appliances and Sensors are deployed in the required customer premises locations and all Vectra services are provided from the FedRAMP high environment.

As it relates to firewall requirements, FedRAMP High changes are primarily to Vectra cloud connectivity and there are a few changes to the appliance connectivity requirements as well.

Please see FedRAMP High Vectra AI Platform Capabilities for details regarding specific feature/capability availability for FedRAMP high deployments.

Deployment Process for FedRAMP High

A FedRAMP High RUX deployment follows a very similar process to a commercial deployment with a few differences. It is expected that this article will provide the added details required for such deployments and the Vectra's other deployment documentation can still be relied on for the bulk of RUX deployment.

For example, when deploying a physical appliance for use as a Brain in a FedRAMP High deployment, the quick start guide for the appliance does not change. The rest of the RUX deployment guide doesn't change, but what is different is that the Brain must be licensed after the UI is available. This licensing step tells the Brain to talk to a different updater endpoint in Vectra's cloud that is only used for FedRAMP High. The Brain will then register with Vectra, and can then be linked to a RUX tenant in Vectra's FedRAMP High environment.

Please Note:

If you are not using network Sensors (network data sources) with your RUX deployment, then the rest of this Deployment Process section about Physical, Virtual, and Cloud appliances does NOT apply to your FedRAMP High deployment.

If you are using network Sensors and therefore will be deploying a Brain, the below steps are necesssary to set up your Brain. Please see the section below that matches the type of appliance you are deploying.

Please read each applicable section below for FedRAMP High deployment guidance.

Physical Appliances

1

Perform Initial Appliance Deployment

Follow the quick start guide for your specific NDR physical appliances. You should have the appliance available on your network via IP or hostname when complete.

If this is Brain appliance, please move on to step 2 below.

If you are installing a Sensor/Stream appliance after your Brain is already deployed and connected to the FedRAMP high environment, Pairing appliances will provide guidance for pairing with your Brain. You do NOT need to continue further with the steps below.

2

License the Physical Brain Appliance

In FedRAMP high deployments, licensing the Brain appliance before it is connected to a RUX tenant enables the Brain to connect to Vectra AI Updater system for FedRAMP high deployments instead of the default commercial environment Updater. Once licensed, all communications between the Brain and the Vectra cloud are to FedRAMP High endpoints.

What you see after logging in is the Quadrant UX. This UI will no longer be enabled after the appliance has been connected to a RUX tenant, and the UI is then served from the Vectra FedRAMP High environment.

  • Navigate in your UI to Configuration → Setup → Licensing.

  • Copy the authorization code using the Copy button on the right.

  • Email the authorization code to the Vectra team member you are working with for the FedRAMP High deployment. If they are not authorized themselves, they will work with team members who are authorized to access the FedRAMP High licensing system.

  • The License Key will be emailed to you.

  • Input the License Key in the window and click Activate License.

  • Upon successful processing, your Brain will then only communicate with Vectra's FedRAMP High environment and you can proceed with the rest of your RUX deployment.

Virtual Appliances

Please Note:

This section ONLY applies to virtual appliances deployed in traditional hypervisor environments such as VMware as VMware and Nutanix (among others)

This section does NOT apply to cloud deployments in environments such as AWS, Azure, and GCP.

1

Perform Initial Appliance Deployment

Follow the quick start guide for your specific NDR virtual / cloud appliances. You should have the appliance available on your network via IP or hostname when complete.

If this is Brain appliance, please move on to step 2 below.

If you are installing a Sensor/Stream appliance after your Brain is already deployed and connected to the FedRAMP high environment, Pairing appliances will provide guidance for pairing with your Brain. You do NOT need to continue further with the steps below.

2

License the Virtual Brain Appliance

In FedRAMP high deployments, licensing the Brain appliance before it is connected to a RUX tenant enables the Brain to connect to Vectra AI Updater system for FedRAMP high deployments instead of the default commercial environment Updater. Once licensed, all communications between the Brain and the Vectra cloud are to FedRAMP High endpoints.

During deployment for virtual Brains, before the system serves the full QUX UI, there is a System Setup and Provisioning UI that must be accessed to license the virtual Brain. This licensing process is already documented in the Initial startup and licensing section for the NDR virtual Brain you are deploying.

Please follow the instructions for licensing at the link above but bear in mind that:

  • You will email the authorization code to the Vectra team member you are working with for the FedRAMP High deployment. If they are not authorized themselves, they will work with team members who are authorized to access the FedRAMP High licensing system.

  • After licensing is completed, your Brain will then only communicate with Vectra's FedRAMP High environment and you can proceed with the rest of your RUX deployment.

Please Note:

You do NOT need to login to the locally served QUX UI that becomes available after the licensing has been completed unless Vectra personnel ask you to during the time before your Brain is connected to a RUX tenant.

If you login to the QUX UI of the virtual Brain that is served locally before it is connected to your RUX deployment, please see the guidance for what to do on any screens you see above in the License the Physical Brain Appliance section that talks about the screens you see before licensing a physical Brain appliance.

You should NOT perform any configuration outside of the licensing steps before Vectra connects your Brain to a RUX tenant.

Cloud Appliances

Please Note:

Cloud Brain appliances are NOT supported for FedRAMP High deployments during the initial availability of Vectra's FedRAMP High environment. Vectra plans to add support for Cloud deployed Brain appliances in the future.

Once cloud Brains are supported, a different template will be provided for the FedRAMP High deployment. These templates are setup similarly to the Vectra commercial environment templates, but point to the FedRAMP High environment updater instead of the commercial updater. Once deployed, Brains deployed with the FedRAMP High deployment template will then only communicate with Vectra's FedRAMP High environment and you can proceed with the rest of your RUX deployment.

FedRAMP High Vectra AI Platform Capabilities

Not all capabilities of the Vectra AI Platform are available when doing a FedRAMP High deployment. The table below will be updated over time as new capabilties are added to the Vectra AI Platform and as the availability of those capabilities changes for FedRAMP High deployments.

Table Column Definitions and Nomenclature

Capability - the Vectra AI Platform capability

Commercial - Whether the capability is supported in Vectra AI's commercial environment.

FedRAMP High - Whether the capability is supported in Vectra AI's FedRAMP High environment.

Notes - Any applicable notes

Nomenclature

  • Yes - capability exists today

  • No - not supported

  • Planned - not supported today but is planned for a future update

    • Any dates given should not be considered a promise and only represent Vectra's current plan at the time this article was last updated.

Capability
Commercial
FedRAMP High
Notes

Appliances / Provisioning

---

---

---

Physical Appliances (All)

Yes

Yes

Virtual Appliances (All)

Yes

Yes

Cloud Brains

Yes

Planned

Cloud Sensors/Stream

Yes

Yes

QUX to RUX Migration

Yes

Planned

Targeted for FYQ3 (Aug-Oct) availability

Cloud Data Sources

---

---

---

AWS Commercial Data Source (CloudTrail)

Yes

No

A FedRAMP High RUX deployment can only monitor GovCloud regions in AWS.

AWS GovCloud Data Source (CloudTrail)

No

Yes

A commercial environment RUX deployment can only monitor commerical AWS regions.

Microsoft Azure Commercial

Yes

Yes

Microsoft Azure GCC

No

No

Microsoft Azure GCC High

No

No

Entra ID (Azure AD)/M365 Commercial

Yes

Yes

Entra ID (Azure AD)/M365 GCC

Yes

Yes

Entra ID (Azure AD)/M365 GCC High

Yes

Yes

Integrations

---

---

---

API-based SIEM/SOAR

Yes

Yes

External App Alerts (Webhook)

Yes

Yes

EDR Integrations

Yes

Yes

Support & Managed Services

---

---

---

Remote Support (UI)

Yes

Yes

Customers can choose to allow Vectra to connect to their UI for assistance. Please see Vectra remote support for details

Remote Support (CLI)

Yes

No

FedRAMP High deployments cannot utilize the VPN connection required for CLI assistance that is available for commercial environments.

Proactive Support

Yes

No

MDR/MXDR

Yes

No

api.vectranetworks.com

Yes

Planned

See Firewall requirements for more details. This is used for lightweight health monitoring, retrieving added context for some detections, and proxying external queries for data.

In-App Support

Yes

No

See In-App support for details.

Product Features (RUX)

---

---

---

Entra ID (Azure AD) Account Lockdown

Yes

No

Host Lockdown (EDR)

Yes

Yes

Asset Inventory

Yes (Preview)

Planned

Exposure Management (Findings)

Yes (Preview)

Planned

Cloud Flow Logs / DNS

Yes (via Fusion)

Planned

Investigation

Yes

Yes

Includes Instant Investigation and all Investigate functionality

AI Summary and Agentic Investigations

Yes

Yes

Licensing Enforcement

For FedRAMP High deployments, licensing is required for physical and virtual Brain appliances so that they know they MUST connect to the FedRAMP High environment. The licensing enforcement details as described below do not change.

Vectra NDR (Detect for Network) supports licensing functionality regardless of the type of deployment (physical appliance, cloud IaaS, VMware). All versions will be able to see license status and enable requests for and application of licenses.

Enforcement of NDR licensing is only enabled on VMware and Nutanix Brains. Any other Brain type does NOT currently have licensing for NDR enforced. Vectra does plan to add licensing enforcement for other Brain types in the future.

It is recommended that all customers work with their account teams to ensure their licensing is up to date. Please refer to the following table for additional detail:

Product

Deployment Type

License Enforcement

NDR (Detect for Network)

VMware Brain Nutanix Brain

Algorithms stop producing Detections when expired.

NDR (Detect for Network)

Physical or Cloud Brains

Not currently enforced. Planned for future (timing TBD).

Other Vectra products are also licensed but enforcement of the license is a matter of contract compliance between sales teams and customers or partners.

Last updated

Was this helpful?