Virtual Sensor Deployment on a Standalone ESXi Server

Updated Sep 13, 2023

Deploy a virtual sensor on a standalone ESXi server

The Arctic Wolf® Virtual Sensor (vSensor) is a virtual appliance that performs passive network inspection and collects security-relevant data for analysis. Arctic Wolf Managed Detection and Response (MDR) uses one or more sensor deployments to monitor events in your network and identify potential threats. Arctic Wolf supports vSensor installation in a standalone ESXi server environment.

Requirements

Before you begin

Steps

  1. Download the virtual appliance image.
  2. Deploy the virtual appliance.
  3. Configure the virtual appliance.
  4. Activate the vSensor.

Step 1: Download the virtual appliance image

Tip: If your browser downloads the OVA file in .ovf format, rename the file to change the file extension to .ova.

  1. Sign in to the Arctic Wolf Portal.
  2. Click Account > Downloads.
  3. In the Virtual Network Appliances section, click Download Virtual Network Appliance to start the .ova file download.

Note: Managed Risk customers can also download the OVA file using the Risk Dashboard.

Step 2: Deploy the virtual appliance

  1. Log in to your ESXi web UI.

  2. Click Create / Register VM.

  3. On the Select creation type page, select Deploy a virtual machine from an OVF or OVA file, and then click Next.

  4. On the Select OVF and VMDK files page, in the Enter a name for the virtual machine field, enter a name for the virtual machine.

    Note: You must provide a unique name for the virtual machine. Re-using a current or past name may prevent activation in the management portal.

  5. Click Click to select files or drag/drop.

  6. Select the .ova file you downloaded, and then click Open.

  7. Click Next.

  8. On the Deployment options page, in Deployment type, select one of the following:

    • AWNv100 Virtual Sensor
    • AWNv200 Virtual Sensor
    • AWNv1000 Virtual Sensor
  9. Click Next.

  10. On the Additional setting page, click Next.

  11. On the Ready to complete page, click Finish.

Step 3: Configure the virtual appliance

  1. In the ESXi web UI, right-click your virtual machine, and then click Power > Power On.

  2. Right-click your virtual machine, and then click Console > Open Console.

  3. When prompted, press Enter three times to initiate the serial console session.

  4. At the Select an option to configure your management interface with prompt, select DHCP or enter a static IP address for the vSensor management interface.

    Note: If you select DHCP, you must use a DHCP reservation to prevent log collection and connection errors.

  5. Click Next.

  6. At the Use a proxy? prompt, do one of these actions:

    • If your vSensor traffic needs to go through a proxy server, select Yes, and then configure these fields:
      • Server IP address — Enter the proxy server IP address for your appliance.
      • Server port — Enter the proxy server port.
    • If your vSensor traffic does not need to go through a proxy server, select No.
  7. Click Next.

  8. At the Do you want to verify your network connection? prompt, select one of these options:

    • Yes

      A series of connectivity tests run.

    • No

  9. Click Next.

  10. At the Tell us about the application you are configuring prompt, configure these settings:

    1. In the Shorthand field, enter the shorthand name for the vSensor.

    2. Select Mirroring.

  11. Click Next.

  12. When prompted, do one of these actions to connect the vSensor to the Arctic Wolf Platform:

    • Using a mobile device — Scan the QR code displayed in the console window, and then follow the on-screen prompts.
    • Using a web browser — Enter the displayed URL into a web browser, and then follow the on-screen prompts.

    Note: QR codes expire after 15 minutes. A new code appears in the console if the QR code expires.

    After the vSensor successfully connects to the Arctic Wolf Platform, a prompt replaces the QR code, asking you to go to the Arctic Wolf Appliance Management.

Step 4: Activate the virtual appliance

  1. In the Arctic Wolf Portal, click Account > Arctic Wolf Appliance Management.

  2. Locate the name or the serial number of the vSensor you want to activate.

  3. In the Actions column, click Activate virtual appliance, and then click Activate Virtual Network Appliance when prompted.

    The console displays Appliance activation in progress, please wait.

  4. When prompted, press Enter three times to activate the console.

Remove a virtual appliance

  1. Decommission the virtual appliance:
    1. In the Arctic Wolf Portal, click Account > Arctic Wolf Appliance Management.

      A list of deployed virtual appliances appear on this page.

    2. Locate the name or serial number of the virtual appliance that you want to decommission.

    3. Under Actions, select the Trash icon, and then click Decommission Virtual Appliance when prompted.

  2. In the ESXi web UI, shutdown the virtual appliance.
  3. Delete the virtual appliance:
    1. In the ESXi web UI, select the virtual appliance.
    2. Click Actions, and then select Delete.
    3. Click Delete.

Reconfigure a virtual appliance

  1. In the ESXi web UI, select the virtual appliance.
  2. Open the virtual console.
  3. When prompted, press Enter three times to initiate the serial console session.
  4. Change the required settings.