Physical appliance modes and switching between them
The article describes the Brain, Sensor, and Mixed modes and how to switch between them for physical Vectra appliances.
Last updated
Was this helpful?
The article describes the Brain, Sensor, and Mixed modes and how to switch between them for physical Vectra appliances.
Vectra physical appliances operate in one of three modes:
Mode
Description
Sensor
Captures / deduplicates raw network traffic.
Houses rolling capture buffer to enable PCAP retrieval when requested from the Brain.
Forwards metadata to the Brain.
Must be paired to a Brain.
Brain
Pairs with Sensors (network data sources) and processes / deduplicates forwarded metadata.
Optionally forwards the metadata received from Sensors when licensed for Stream (RUX and QUX) or Recall (QUX only).
Communicates with the Vectra Cloud in RUX deployments.
Communicates with local integration points.
Serves the UI in QUX deployments.
Mixed
Performs both Brain and Sensor functions.
B-Series appliances can only be deployed in Brain mode.
S-Series appliances can only be deployed in Sensor mode.
X-Series appliances can be deployed in Brain, Sensor, or Mixed modes.
All NDR virtual / cloud appliances support only Brain or Sensor mode.
Virtual appliances do NOT support Mixed mode.
To display the current mode of a Vectra appliance:
Login on the appliance cli as the user vectra .
See SSH login process for CLI for more details.
Run the command show mode .
Example Below:
The method for converting a Vectra appliance from one mode to another depends on the appliance's present mode. The following table summarizes the supported mode conversion:
Brain
Sensor
Contact Vectra Support
Brain data will be lost during conversion.
Appliance will reboot and come up in Sensor mode.
Brain
Mixed
Perform set mode mixed at the CLI of your Brain.
There will be no data loss.
Sensor
Brain
Not supported
Sensor
Mixed
Not supported
Mixed
Brain
Perform set mode brain at the CLI of your Brain.
There will be no data loss.
Match must be disabled on the Mixed mode appliance before attempting conversion. See Please Note: box below for more details.
Mixed
Sensor
Contact Vectra Support
Brain data will be lost during conversion
Appliance will reboot and come up in Sensor mode
As you can see from the above table:
It is straightforward to toggle an appliance between Mixed-mode and Brain mode.
The provided commands should be entered at the CLI while logged in as the vectra user.
Vectra Support will need to be engaged to convert a Brain or Mixed-mode appliance to Sensor mode.
Please Note:
Conversion to Sensor mode is a one way process.
Once an appliance has been converted to Sensor mode, it cannot later be reverted or converted back to Brain or Mixed mode.
Conversion from Mixed to Brain mode is NOT supported when Match is enabled on the Mixed mode appliance.
Please disable Match on the Mixed mode appliance before attempting conversion.
Vectra plans to add a warning about this to the CLI command in v9.12 and above and disallow conversion attempts with Match enabled.
Last updated
Was this helpful?
Was this helpful?
vscli > show mode
Mode: mixed