Introduction and requirements
Introductions and requirements for deploying a Vectra Brain appliance in Nutanix environments.
Introduction
This guide is intended to help customers or partners deploy a virtual Brain appliance in Nutanix environments. A Nutanix Brain appliance can be used in Vectra AI Platform deployments that use either the Respond UX or the Quadrant UX. The Respond UX is served from Vectra’s cloud and the Quadrant UX is served locally from the Brain appliance. For more detail on Respond UX vs Quadrant UX please see Vectra Analyst User Experiences (Respond vs Quadrant).
This guide will cover basic background information, connectivity requirements (firewall rules that may be needed in your environment), licensing, deployment, and next steps. One of the below guides should be the starting point for your overall Vectra deployment:
General Requirements
An open Proof of Value (Proof of Concept or Trial) that you are working with Vectra or a Vectra partner or a valid entitlement to Vectra NDR through purchase.
The licensing system cannot provide licenses for customers who are not currently entitled to a license through a trial or purchase.
Current login to a fully approved Vectra Support Portal account.
Accounts that are self-registered and not fully approved on the Vectra Support Portal will not have the license request option enabled.
IP address, subnet mask, default gateway, and hostname for the Management interface of the Brain (DHCP is also supported).
If DHCP is used, a reservation should be created to keep the IP consistent for Sensors that may pair via IP instead of Hostname.
DNS server addresses.
Nutanix Prism Central with v3 API accessible to the user who will perform the deployment. The specific permissions required are:
Cluster – View Cluster
OVA – View OVA
Subnet – View Subnet
AHV VM – Create Virtual Machine
About Nutanix Brain Images
The .zip file that contains the .ova image and deployment script used to deploy a Brain in Nutanix is made available on the Vectra Customer Portal which is part of Vectra Support. Vectra periodically updates the base image used for VMware Brain deployment.
It is a best practice to always download the latest image from the Vectra Customer Portal prior to deployment of a new Nutanix Brain.
Brains that are connected to Vectra are updated automatically according to the settings on that Brain. Offline updates are also possible for Quadrant UX deployments only. Please see Offline Updates for instructions on how to apply offline updates.
Nutanix Brain Resource Requirements and Throughput
Nutanix Versions Supported: AOS 6.8.1 and higher with Prism Central (and v3 API) available
For use in Respond UX or Quadrant UX deployments:
Performance1
Coming Soon
Coming Soon
10 Gbps
CPU
8 Cores
16 Cores
32 Cores
Memory
64 GB RAM
128 GB RAM
256 GB RAM
Drive (OS, Data) Requires 260 MB/s
128 GB, 512 GB
128 GB, 512 GB
128 GB, 512 GB
Max Paired Sensors
Coming Soon
Coming Soon
100
Max Simultaneous Tracked Hosts2
Coming Soon
Coming Soon
150,000
For use ONLY in Respond UX for Network deployments:
A Respond UX for Network deployment means using network Sensors with the Respond UX.
Performance1
Coming Soon
Coming Soon
CPU
4 Cores
6 Cores
Memory
48 GB RAM
48 GB RAM
Drive (OS, Data) Requires 260 MB/s
128 GB, 512 GB
128 GB, 512 GB
Max Paired Sensors
Coming Soon
Coming Soon
Max Simultaneous Tracked Hosts2
Coming Soon
Coming Soon
Please Note:
At the initial availability of the Nutanix Brain image, only the 32-core version is supported by Vectra. Vectra plans to make the other sizes (greyed out in the chart) available in the future.
Footnotes:
1 Performance represents the aggregate bandwidth observed on the capture interfaces of any Sensors that are paired to the Brain. Guidance is for average traffic mixes. Traffic mixes that skew toward larger flows (like file transfers) will perform better than traffic mixes that skew towards smaller flows (like DNS) as they produce more metadata.
2 Refers to how many hosts the Brain can track simultaneously (open host sessions). Brains retain and display data for larger numbers of hosts, this only refers to how many hosts the system can process metadata for simultaneously.
Please Note:
The virtual CPU MUST support the pdpe1gb cpu flag (1GB Large Pages) – More information, and a minimum SSE instruction level of 4.2, and must support the POPCNT (population count) instruction. This requires the hypervisor host to be running one of the following processors or later:
Intel Nehalem (2008) processors and newer
AMD Bulldozer (2011) processors and newer
Vectra Nutanix based Brains do not support Mixed Mode deployment. They can only be used in Brain mode.
Vectra Nutanix based Brains support running in FIPS mode. Note that the underlying hardware must also be FIPS compliant (it must support the RDRAND CPU instruction). To configure FIPS mode once deployed login to the CLI of the Brain and use the following commands to enable/disable FIPS mode.
set security-mode fipsset security-mode defaultFor full details please see FIPS mode enabling and disabling.
Vectra Nutanix based Brains do not support Direct PCI or SR-IOV passthrough.
Vectra Nutanix based Brains do support paravirtualized NICs. Vectra uses a VirtIO NIC for the Nutanix Brain.
Vectra recommends that Brains are configured to use storage local to the hypervisor and are not stored on a SAN. Vectra Brains require extremely high throughput from their disk storage and this throughput cannot normally be sustained by SAN systems without impact to other SAN users.
Live Migration is not explicity supported by Vectra.
If you do use Live Migration and encounter any issues, support from Vectra will be best effort only.
It is a best practice to set VM-Host affinity to pin the Brain to a node with adequate resources where satisfactory Brain performance test results (details in Post Deployment Guidance) are achieved.
Last updated
Was this helpful?