For the complete documentation index, see llms.txt. This page is also available as Markdown.

Introduction and requirements

Introductions and requirements for deploying a Vectra Brain appliance in VMware vSphere environments.

Introduction

This guide is intended to help customers or partners deploy a virtual Brain appliance in VMware environments. A VMware Brain appliance can be used in Vectra AI Platform deployments that use either the Respond UX or the Quadrant UX. The Respond UX is served from Vectra’s cloud and the Quadrant UX is served locally from the Brain appliance. For more detail on Respond UX vs Quadrant UX please see Vectra Analyst User Experiences (Respond vs Quadrant).

This guide will cover basic background information, connectivity requirements (firewall rules that may be needed in your environment), licensing, deployment, and next steps. One of the below guides should be the starting point for your overall Vectra deployment:

Demo Deployment Video

About VMware Brain Images and Updates

The .ova image used to deploy a Brain in VMware is made available on the Vectra Customer Portal which is part of Vectra Support. Vectra periodically updates the base image used for VMware Brain deployment.

It is a best practice to always download the latest image from the Vectra Customer Portal prior to deployment of a new VMware Brain.

Brains that are connected to Vectra are updated automatically according to the settings on that Brain. Offline updates are also possible for Quadrant UX deployments only. Please see Offline Updates for instructions on how to apply offline updates.

VMware Brain Requirements and Performance

General Requirements

  • IP address and subnet mask for the Management interface of the Brain.

  • DNS server addresses.

  • Current login to a fully approved Vectra Support Portal account.

    • Accounts that are self-registered and not fully approved on the Vectra Support Portal will not have the license request option enabled.

  • An open Proof of Value (Proof of Concept or Trial) that you are working with Vectra or a Vectra partner or a valid entitlement to Vectra NDR through purchase.

    • The licensing system cannot provide licenses for customers who are not currently entitled to a license through a trial or purchase.

All VMware Brains support being deployed on VMware vSphere versions 6.5 through 8.

Performance and VMware Requirements

For use in any Respond UX or Quadrant UX deployments:

Performance
2 Gbps
4 Gbps
10 Gbps

CPU

8 Cores

16 Cores

32 Cores1

Memory

64 GB RAM

128 GB RAM

256 GB RAM

Drive (OS, Data) – Requires 260 MB/s

128 GB, 512 GB

128 GB, 512 GB

128 GB, 512 GB

Max Paired Sensors

15

25

100

Max Simultaneous Tracked Hosts²

50,000

50,000

150,000

For use ONLY in Respond UX for Network deployments:

  • A Respond UX for Network deployment means using network Sensors with the Respond UX.

Performance2

150 Mbps

500 Mbps

CPU

4 Cores

6 Cores

Memory

48 GB RAM

48 GB RAM

Drive (OS, Data) Requires 260 MB/s

128 GB, 512 GB

128 GB, 512 GB

Max Paired Sensors

5

10

Max Simultaneous Tracked Hosts3

25,000

37,500

Footnotes from above tables:

1 Please see 32 Core NUMA Configuration for details on checking and setting (if required) for 32 core Brains.

2 Performance represents the aggregate bandwidth observed on the capture interfaces of any Sensors that are paired to the Brain. Guidance is for average traffic mixes. Traffic mixes that skew toward larger flows (like file transfers) will perform better than traffic mixes that skew towards smaller flows (like DNS) as they produce more metadata.

3 Refers to how many hosts the Brain can track simultaneously (open host sessions). Brains retain and display data for larger numbers of hosts, this only refers to how many hosts the system can process metadata for simultaneously.

Please Note:

vMotion is compatible with VMware Brains but new HW or copying the VM can cause VMware to generate a new UUID which causes the Brain license to become invalid, and require relicensing.

Additional Notes:

  • Vectra VMware based Brains do NOT support Mixed Mode deployment.

    • They can only be used in Brain mode.

  • Vectra VMware based Brains support running in FIPS mode.

    • Note that the underlying hardware must also be FIPS compliant (it must support the RDRAND CPU instruction).

  • Vectra recommends that Brains are configured to use storage local to the hypervisor and are not stored on a SAN.

    • Vectra Brains require extremely high throughput from their disk storage and this throughput cannot normally be sustained by SAN systems without impact to other SAN users.

  • See VMware deployment details and considerations (the next section in this guide) for additional guidance around Storage/SANs, networking requirements, vMotion, Enhanced vMotion compatibility, and unsupported hypervisors.

Last updated

Was this helpful?