Introduction and general requirements
Hyper-V vSensor deployment introduction, resource requirements, performance, and connectivity requirements.
Introduction
This guide is intended to help customers or partners deploy vSensors in Hyper-V environments and pair them to your Vectra Brain. It will cover basic background information, connectivity requirements (firewall rules that may be needed in your environment), deployment of the vSensor in Hyper-V, and pairing.
vSensors behave much in the same way that physical Sensors do. One advantage is that there is no cost to deploy a vSensor other than your own costs to provide and maintain the infrastructure they run in. vSensors also allow you to capture and analyze traffic that only exists in the virtual environment. You can even use vSensors in place of physical Sensors to capture physical network traffic.
Hyper-V vSensors can be used in both Respond UX and Quadrant UX deployments. For more detail on Respond UX vs Quadrant UX please see Vectra Analyst User Experiences (Respond vs Quadrant). One of the below guides should be the starting point for your overall Vectra deployment:
About Hyper-V vSensor Images
The Brain makes a Hyper-V VHDX image (in a .zip archive) available for download and subsequent use for provisioning vSensors. Vectra appliances typically operate with updates enabled. Regular updates ensure that the appliances are running the very latest version. Once a vSensor has been deployed and paired to a Brain, it will update itself as needed, staying current with its Brain.
Please Note:
As your Vectra Brain is updated, the image for the Hyper-V vSensor is also updated.
If you deploy additional Hyper-V vSensors in the future, always download a fresh copy of the image from an up-to-date Brain to ensure you are working with the latest code.
vSensor images are retrieved from the Brain when using either the Respond UX and Quadrant UX.
The RUX UI is delivered from Vectra's cloud but the download link still retrieves the image from the Brain itself.
Hyper-V vSensor Requirements and Throughput
Cores Required
2 (500 Mbps), 4 (1 Gbps), 8 (2 Gbps), or 16 (5 Gbps)
RAM Required
8 GB (2 and 4 core), 16 GB (8 core), 64 GB (16 core)
Must be contiguous in a single NUMA node (not spanning multiple nodes)
Disk Space Required
100 GB (2 core), 150 GB (4 and 8 core), 500 GB (16 core)
Virtual Switch Type Supported
External
Interfaces Supported
Up to 2 for capture, 1 for management (can be shared with capture)
Traffic that can be captured
Physical or Virtual
If you wish to resize the vSensor after deployment, please see: Resizing Virtual Sensors and Brains for details. Please note that you can only from a smaller configuration to a larger one. NOT from a larger configuration to a smaller one.
To add a 2nd capture interface if you originally deployed with only one, you must shut the vSensor down, add the 2nd capture interface, and restart it for this to work.
In Hyper-V, if the processor is supported but the sensor health check is reporting
[FAILED] Hypervisor CPU Supportedand not capturing traffic, try disabling the processor compatibility in the settings.
Connectivity Requirements
The Vectra Respond UX Deployment Guide or Vectra Quadrant UX Deployment Guide detail basic connectivity requirements for initial platform deployment. It also gives guidance on firewall/proxy SSL inspection, Internet access to and from the Brain, and guidance for air-gapped environments. For full detail on all possible firewall rules that might be required in your environment, please see Firewall Requirements. Hyper-V vSensor specific requirements are listed below:
Connectivity Requirements for Hyper-V vSensors
Source
Destination
Protocol/Port
Description
Admin Hosts
vSensors
TCP/22 (SSH)
CLI access to vSensor
Brain
vSensors
TCP/22 (SSH)
Remote management and troubleshooting
vSensors
Brain
TCP/22 (SSH)
TCP/443 (HTTPS)
Pairing, metadata transfer, and ongoing communication
Please Note:
vSensors do not communicate with the Vectra Cloud.
All communication sessions with vSensors are initiated from the vSensor to the Brain.
Updates for vSensors are downloaded to the Vectra Brain, and the vSensor retrieves them from the Brain.
Command Line (CLI) access can also be obtained via the console in your hypervisor if you wish to login to the vSensor CLI after deployment. Please SSH login process for CLI for more details.
Last updated
Was this helpful?