Introduction and general requirements
VMware vSensor deployment introduction, resource requirements, performance, supported VMware versions, and connectivity requirements.
Introduction
This guide is intended to help customers or partners deploy vSensors in VMware environments and pair them with a Vectra Brain. It will cover basic background information, connectivity requirements (firewall rules that may be needed in your environment), vCenter integration, deployment of the vSensor in VMware, and pairing.
vSensors behave much in the same way that physical Sensors do. One advantage is that there is no cost to deploy a vSensor other than your own costs to provide and maintain the infrastructure they run on. vSensors also allow you to capture and analyze traffic that only exists in the virtual environment. You can even use vSensors in place of physical Sensors to capture physical network traffic.
VMware vSensors can be used in both Respond UX and Quadrant UX deployments. For more detail on Respond UX vs Quadrant UX please see Vectra Analyst User Experiences (Respond vs Quadrant). One of the below guides should be the starting point for your overall Vectra deployment:
About VMware vSensor Images
The Brain makes a VMware OVA available for download and subsequent provisioning. Vectra appliances typically operate with updates enabled. Regular updates ensure that the appliances are running the very latest version. Deployed Sensors and vSensors also update regularly from the Brain. Once a vSensor has been deployed, it will update itself as needed, staying current with its Brain.
Please Note:
As your Vectra Brain is updated, the OVA for the VMware vSensor is also updated.
If you deploy additional VMware vSensors in the future, always download a fresh copy of the OVA from an up-to-date Brain to ensure you are working with the latest code.
vSensor images are retrieved from the Brain when using either the Respond UX and Quadrant UX.
The RUX UI is delivered from Vectra's cloud but the download link still retrieves the image from the Brain itself.
Resource Requirements and Performance
Performance1
500 / 250 Mbps
1 / .5 Gbps
2 / 1 Gbps
5 / 2.5 Gbps
20 / 10 Gbps
CPU Cores
2
4
83
163
323
Memory
8 GB
8 GB
16 GB
64 GB
114 GB
Storage
100 GB
150 GB
150 GB
600 GB4
830 GB4
Capture Interfaces
22
22
4
4
4
Footnotes:
1 1st number represents NDR/Detect only performance, 2nd number represents performance with NDR/Detect and Match and/or Suspect Protocol Activity detections enabled.
2 2-core and 4-core vSensors can use up to 4 capture ports if the RAM is updated to at least 10GB.
3 2 and 4 core vSensors throttle CPU usage while 8, 16, and 32 core versions do CPU pinning to maintain performance.
4 The 16 and 32 core vSensors will need their configuration modified after deployment due to limitations in what can be preconfigured when using one image file for multiple different deployment configurations.
Please see: Modifying 16 and 32 core vSensors after deployment for instructions.
16 core requires 600 GB storage.
32 core requires 830 GB storage and added ethernet configuration.
32 core may also need NUMA parameters adjusted in advanced VM configuration options.
Supported vSwitch Types
VMware Virtual Standard Switch (VSS) or VMware Distributed Switch (VDS a.k.a. dvSwitch)
Supported vSphere Versions
6.5 to 8
5.x was supported through version v6.14 and 6.0 was supported through v6.19
Special Note:
Regarding Vectra supported VMware hardware versions.
Vectra supports only versions 11 and 15 of VMware hardware.
DO NOT update the hardware version ever (during deployments, upgrades, or in any other situation).
This includes updating from v11 to v15.
Redeployment is the only supported way to change hardware between supported versions.
If you move to an unsupported hardware version, Vectra support will direct you to redeploy any VMware vSensor that is running an unsupported version. Downgrades are unsupported.
Please see VMware deployment details and considerations (the next section in this guide) for addtional guidance on the following topics:
Connectivity Requirements
The Vectra Respond UX Deployment Guide or Vectra Quadrant UX Deployment Guide detail basic connectivity requirements for initial platform deployment. It also gives guidance on firewall/proxy SSL inspection, Internet access to and from the Brain, and guidance for air-gapped environments. For full detail on all possible firewall rules, please see Firewall Requirements for Vectra Appliances. VMware vSensor specific requirements are listed below:
Connectivity Requirements for VMware vSensors
Source
Destination
Protocol/Port
Description
Admin Hosts
vSensors
TCP/22 (SSH)
CLI access to vSensor
Brain
vSensors
TCP/22 (SSH)
Remote management and troubleshooting
vSensors
Brain
TCP/22 (SSH)
TCP/443 (HTTPS)
Pairing, metadata transfer, and ongoing communication
Brain
vCenter
Configured TCP Port(s)
Physical Hosts view, vCenter Host ID input, vCenter Host context, vCenter alerts
Please note:
vSensors do not communicate with the Vectra Cloud.
All communication sessions with vSensors are initiated from the vSensor to the Brain.
Updates for vSensors are downloaded to the Vectra Brain, and the vSensor retrieves them from the Brain.
Command Line (CLI) access can also be obtained via the console in your hypervisor if you wish to login to the vSensor CLI after deployment. Please SSH login process for CLI for more details.
Last updated
Was this helpful?