For the complete documentation index, see llms.txt. This page is also available as Markdown.

Licensing and Brain deployment overview

How licensing works for VMware Brains and an overview of the VMware Brain deployment process.

Licensing Overview

Appliance code has been encrypted to protect Vectra’s intellectual property and a license is required to enable successful decryption of the file system and complete deployment. The licensing for Vectra NDR (formerly Detect for Network) running on VMware Brains also governs the ability of the system to create Detections.

Licensing Enforcement

Vectra NDR (Detect for Network) supports licensing functionality regardless of the type of deployment (physical appliance, cloud IaaS, VMware). All versions will be able to see license status and enable requests for and application of licenses.

Enforcement of NDR licensing is only enabled on VMware and Nutanix Brains. Any other Brain type does NOT currently have licensing for NDR enforced. Vectra does plan to add licensing enforcement for other Brain types in the future.

It is recommended that all customers work with their account teams to ensure their licensing is up to date. Please refer to the following table for additional detail:

Product

Deployment Type

License Enforcement

NDR (Detect for Network)

VMware Brain Nutanix Brain

Algorithms stop producing Detections when expired.

NDR (Detect for Network)

Physical or Cloud Brains

Not currently enforced. Planned for future (timing TBD).

Other Vectra products are also licensed but enforcement of the license is a matter of contract compliance between sales teams and customers or partners.

VMware Brain Deployment Overview

Deployment of a Brain appliance in VMware environments can be done on both standalone ESXi servers using the embedded host client or in full vSphere environments using vCenter to manage your virtual infrastructure.

Please Note:

  • If deploying on standalone ESXi servers using their embedded host client, configuring a static IP is not possible until after the deployment is completed and you have access to the Brain CLI.

    • DHCP is the only supported IP assignment method while using the embedded host client.

  • Deployment using vCenter allows for Static or DHCP IP assignment of the Management port for the Brain appliance.

The main steps for the deployment are summarized below. For additional detail see Brain Deployment in VMware.

1

Download the .OVA

2

Deploy the .OVA

Deploy OVA in VMware and power on the appliance using one of the below methods:

  • Using the embedded host client on standalone ESXi will require that DHCP be available to the Brain appliance when booting for an IP to be assigned.

    • After the system is licensed and the CLI of the Brain is available for login, if a Static IP is required, the initial DHCP setting for the management port can be changed to a static assignment using the CLI of the Brain.

  • Using vCenter with a vSphere client to do the deployment in VMware allows for either a Static or DHCP address assignment for the initial boot of the Brain appliance.

3

License the Brain

  • Browse to the IP assigned to the Brain’s management interface to see the initial boot status messages. The status message screen will update but a manual refresh is required to display any new information.

  • When you are able to see the System Setup and Provisioning screen, enter proxy information if required for your environment and then enter the License configuration screen.

    • Copy the licensing request code from the Vectra UI.

  • Back on the Vectra customer portal, paste the license request code into the Licensing Request form in the Enter Authorization Code box available at https://support.vectra.ai/vectra/additional-resources.

    • Copy the license once generated and paste it into the Vectra UI Licensing Information box.

  • Click Save on the licensing configuration screen.

4

Complete Provisioning

  • After the license is validated, the file system will be decrypted, a performance test will be run, the Brain will reboot, and the Brain will reach out to the Vectra provisioning server and complete provisioning (if the deployment is in online mode).

    • Offline Brains follow a similar process but do not need to communicate with the provisioning server and can validate the license locally.

  • Finally, a success message will be presented with a button to redirect to the main UI login screen.

  • For QUX deployments only:

    • Initial login credentials for the UI:

      • admin / changethispassword

    • Initial login credentials for the SSH access to the CLI:

      • vectra / changethispassword

    • You will be asked to change the password after the initial login.

  • Complete your configuration using instructions available in the Vectra Respond UX Deployment Guide or Vectra Quadrant UX Deployment Guide.

Last updated

Was this helpful?