For the complete documentation index, see llms.txt. This page is also available as Markdown.

Introduction and general requirements

VMware vSensor deployment introduction, resource requirements, performance, supported VMware versions, and connectivity requirements.

Introduction

This guide is intended to help customers or partners deploy vSensors in VMware environments and pair them with a Vectra Brain. It will cover basic background information, connectivity requirements (firewall rules that may be needed in your environment), vCenter integration, deployment of the vSensor in VMware, and pairing.

vSensors behave much in the same way that physical Sensors do. One advantage is that there is no cost to deploy a vSensor other than your own costs to provide and maintain the infrastructure they run on. vSensors also allow you to capture and analyze traffic that only exists in the virtual environment. You can even use vSensors in place of physical Sensors to capture physical network traffic.

VMware vSensors can be used in both Respond UX and Quadrant UX deployments. For more detail on Respond UX vs Quadrant UX please see Vectra Analyst User Experiences (Respond vs Quadrant). One of the below guides should be the starting point for your overall Vectra deployment:

About VMware vSensor Images

The Brain makes a VMware OVA available for download and subsequent provisioning. Vectra appliances typically operate with updates enabled. Regular updates ensure that the appliances are running the very latest version. Deployed Sensors and vSensors also update regularly from the Brain. Once a vSensor has been deployed, it will update itself as needed, staying current with its Brain.

Please Note:

As your Vectra Brain is updated, the OVA for the VMware vSensor is also updated.

  • If you deploy additional VMware vSensors in the future, always download a fresh copy of the OVA from an up-to-date Brain to ensure you are working with the latest code.

  • vSensor images are retrieved from the Brain when using either the Respond UX and Quadrant UX.

    • The RUX UI is delivered from Vectra's cloud but the download link still retrieves the image from the Brain itself.

Resource Requirements and Performance

Performance1

500 / 250 Mbps

1 / .5 Gbps

2 / 1 Gbps

5 / 2.5 Gbps

20 / 10 Gbps

CPU Cores

2

4

83

163

323

Memory

8 GB

8 GB

16 GB

64 GB

114 GB

Storage

100 GB

150 GB

150 GB

600 GB4

830 GB4

Capture Interfaces

22

22

4

4

4

Footnotes:

1 1st number represents NDR/Detect only performance, 2nd number represents performance with NDR/Detect and Match and/or Suspect Protocol Activity detections enabled.

2 2-core and 4-core vSensors can use up to 4 capture ports if the RAM is updated to at least 10GB.

3 2 and 4 core vSensors throttle CPU usage while 8, 16, and 32 core versions do CPU pinning to maintain performance.

4 The 16 and 32 core vSensors will need their configuration modified after deployment due to limitations in what can be preconfigured when using one image file for multiple different deployment configurations.

  • 16 core requires 600 GB storage.

  • 32 core requires 830 GB storage and added ethernet configuration.

  • 32 core may also need NUMA parameters adjusted in advanced VM configuration options.

Supported vSwitch Types

  • VMware Virtual Standard Switch (VSS) or VMware Distributed Switch (VDS a.k.a. dvSwitch)

Supported vSphere Versions

  • 6.5 to 8

    • 5.x was supported through version v6.14 and 6.0 was supported through v6.19

Please see VMware deployment details and considerations (the next section in this guide) for addtional guidance on the following topics:

Connectivity Requirements

The Vectra Respond UX Deployment Guide or Vectra Quadrant UX Deployment Guide detail basic connectivity requirements for initial platform deployment. It also gives guidance on firewall/proxy SSL inspection, Internet access to and from the Brain, and guidance for air-gapped environments. For full detail on all possible firewall rules, please see Firewall Requirements for Vectra Appliances. VMware vSensor specific requirements are listed below:

Connectivity Requirements for VMware vSensors

Source

Destination

Protocol/Port

Description

Admin Hosts

vSensors

TCP/22 (SSH)

CLI access to vSensor

Brain

vSensors

TCP/22 (SSH)

Remote management and troubleshooting

vSensors

Brain

TCP/22 (SSH)

TCP/443 (HTTPS)

Pairing, metadata transfer, and ongoing communication

Brain

vCenter

Configured TCP Port(s)

Physical Hosts view, vCenter Host ID input, vCenter Host context, vCenter alerts

Please note:

  • vSensors do not communicate with the Vectra Cloud.

    • All communication sessions with vSensors are initiated from the vSensor to the Brain.

    • Updates for vSensors are downloaded to the Vectra Brain, and the vSensor retrieves them from the Brain.

  • Command Line (CLI) access can also be obtained via the console in your hypervisor if you wish to login to the vSensor CLI after deployment. Please SSH login process for CLI for more details.

Last updated

Was this helpful?