Install a vSensor in an AWS environment
You can install an Arctic Wolf® Virtual Sensor (vSensor) using the Amazon Web Services (AWS)® web console.
- Some detections may not be available if sensors cannot see the relevant network traffic, including traffic flowing through different switches or unmonitored firewalls. Make sure that sensors are properly placed across all network egress points.
- During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
- vSensor does not support auto-scaling in AWS.
- An Amazon EC2 instance supports 10 mirror sessions for each vSensor. If you require more than 10 mirror sessions for each vSensor, contact your Concierge Security® Team at security@arcticwolf.com to discuss the implementation of an AWS Network Load Balancer.
For more information, see Traffic Mirroring limitations and quotas.
- For more information about AWS best practices, see Best practices of Amazon EC2 and Security best practices for your VPC.
These actions are required:
- Make sure you have the appropriate Arctic Wolf permissions to install the appliance. Contact your Concierge Security® Team (CST) at security@arcticwolf.com to identify who in your organization has these permissions.
- Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click , and then view the IP addresses in the section for your product.
- If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
- If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
- If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.
- Configure log forwarding. For more information, see Syslog forwarding.
Provide AWS account IDs to Arctic Wolf
Create a vSensor instance
Configure network settings for the vSensor instance
Configure security group rules for the vSensor instance
Configure a second network interface for the vSensor instance
To receive mirrored traffic, you must configure your vSensor with a second network interface. Based on your network, the subnet of the second network interface can be the same or different than the primary network interface.
Launch and verify the EC2 instance
Connect to the serial console
- If you have not used the serial console before, complete these steps to configure serial console access:
- Click .
- In the Account Attributes section, select EC2 Serial Console.
- In the EC2 Serial Console section, select the Allow checkbox.
- Click Update.
- In the EC2 management console, select Instances, and then enter the vSensor instance ID.
- Click .
Configure the vSensor
Use the serial console to configure the vSensor. For more information on using the serial console, see Serial console.
Activate the vSensor
Obtain the Elastic Network Interface ID
- In the Amazon EC2 console, click the Networking tab for the interface that you created in Configure a second network interface for the vSensor instance.
- Copy the Elastic Network Interface ID (ENI), and then save it in a safe, encrypted location. You will provide it to Arctic Wolf later.
See Get started with Traffic Mirroring for more information.
Create a target group for the network load balancer
If you have more than 10 mirrored sessions, you must add a network load balancer.
Deploy a network load balancer
Create the traffic mirror target
Create the traffic mirror filter
Create the traffic mirror session
For each EC2 instance that you want to collect traffic from, complete these steps: