Install a vSensor using the Azure portal with direct share

You can install an Arctic Wolf® Virtual Sensor (vSensor) using the Microsoft Azure® web console.

Note:
  • These steps only apply if you have a Cloud Solution Provider (CSP) plan and have received the image through direct share. If you have a different plan, see Install a vSensor using the Azure portal.
  • Some detections may not be available if sensors cannot see the relevant network traffic, including traffic flowing through different switches or unmonitored firewalls. Make sure that sensors are properly placed across all network egress points.
  • During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
  • The vSensor generates additional observations for any traffic that is not filtered or dropped by the upstream firewall. The Azure virtual network Terminal Access Point (TAP) mirrors the traffic from the source VM interface network interface controller (NIC) directly. You may want to deploy the vSensor behind a firewall.

These actions are required:

  • Make sure you have the appropriate Arctic Wolf permissions to install the appliance. Contact your Concierge Security® Team (CST) at security@arcticwolf.com to identify who in your organization has these permissions.
  • Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
    Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click Resources > Allowlist Requirements, and then view the IP addresses in the section for your product.
  • If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
  • If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
  • If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.

Create a vSensor instance

  1. Sign in to the Microsoft Azure portal.
  2. Navigate to the Virtual machines section.
  3. Click Create > Virtual machine.
  4. In the Basics section, configure these settings:
    • Subscription — Create a new resource group or assign an existing resource group.
    • Instance details — For Virtual machine name, enter the virtual machine (VM) name.
    • Security type — Select Standard.
    • Size — Select the vSensor size:
      Note:
      • Make sure to select the exact size. You cannot configure the vSensor if you do not select the correct size.
      • If your region does not support v5, select v7 if available. If v7 is not available, use v4.
      • AWNv100 — Standard_D2as_v5 - 2 vcpus, 8 GiB memory
      • AWNv200 — Standard_D4as_v5 - 4 vcpus, 16 GiB memory
      • AWNv1000 — Standard D16as_v5 - 16 vcpus, 64 GiB memory
  5. Select the image:
    1. In the Images field, click See all images.
    2. Click Direct share.
    3. In the Scope field, select your Subscription ID.
    4. Select the image.
  6. Click Next: Disks.
  7. In the Disks section, in the OS options > OS disk type section, select Standard SSD.
  8. Click Next: Networking.
  9. In the Networking section, configure these settings:
    • Virtual network — Select the virtual network.
    • Subnet — Select the subnet.
    • Public IP — Select None.
    • NIC network security group — Select Advanced.
    • Configure network security group — Leave this as the default setting.
    • Public inbound ports — Select None.
  10. Click Review + create.
  11. Click Create.
  12. In the Generate a new key pair box, click Download private key and create resource.
    Note: The private key is not used by Arctic Wolf. You can delete it.
    After the private key is downloaded, Deployment is in progress displays.
  13. Click Go to resource.

Create a network security group

  1. Sign in to the Microsoft Azure portal.
  2. Go to the Network security groups page.
  3. Click Create.
  4. Complete these fields:
    • Subscription — Select your subscription.
    • Resource group — Select your resource group.
    • Name — Give the network security group a name.
  5. Click Review + create.
  6. Click Go to resource.

Create inbound security rules

  1. In the side navigation, click Settings > Inbound security rules.
  2. Create a virtual network Terminal Access Point (TAP) rule:
    1. Click Add.
    2. Complete these fields:
      • SourceAny
      • Destination port range — 4789
      • Protocol UDP
      • Name — Enter a name for the rule.
    3. Click Add.

Attach a network interface

Create an interface to receive virtual network terminal access point (TAP) traffic.

  1. Stop the VM.
  2. In the side navigation, click Networking > Network settings.
  3. Click Attach network interface.
  4. Click Create and attach network interface.
  5. Complete these fields:
    • Resource group — Select your resource group.
    • Name — Enter a name for the network interface, such as vntap_receiver.
    • Subnet — Select your subnet.
    • NIC network security group — Select advanced.
    • Configure network security group — Select the security group that you created in Create a network security group.
  6. Click Create.

Enable accelerated networking

Enable accelerated networking on the network interface you created in Attach a network interface.

  1. On the Network settings page, next to Network interface, click the name of your network interface.
  2. Click Edit accelerated networking.
  3. In the Edit accelerated networking pane, select Enabled.
  4. Select I have validated that the operating system supports accelerated networking.
  5. Click Save.
    Note: The interface may not update the accelerated networking status immediately.
  6. Start the VM.

Connect to the serial console

  1. In the side navigation, click Virtual machines.
  2. Select your VM.
  3. In the side navigation, click Connect > Connect.
  4. Click More ways to connect > Go to serial console.

Configure the vSensor

Use the serial console to configure the vSensor. For more information on using the serial console, see Serial console.

  1. When prompted, press Enter three times to initiate the serial console session.
  2. Select Next.
  3. At the Use a proxy? prompt, do one of these actions:
    Note: Only management interface traffic is sent to the proxy server.
    • If your virtual appliance management traffic goes through a proxy server — Select Yes, and then configure these settings:
      • Server IP address — Enter the proxy server IP address for your appliance.
      • Server port — Enter the proxy server port.
    • If your virtual appliance management traffic does not go through a proxy server — Select No.
  4. Select Next.
  5. At the Do you want to verify your network connection? prompt, select one of these options:
    • Yes

      A series of connectivity tests run. If a connectivity check fails, edit your network settings as needed, and then complete the connectivity checks again.

    • No
  6. Select Next.
  7. At the Tell us about the application you are configuring prompt, configure these settings:
    1. In the Shorthand field, enter a shorthand name for the virtual appliance.
    2. Select Mirroring.
  8. Select Next.
  9. When prompted, do one of these actions to connect the virtual appliance to Arctic Wolf:
    • On a mobile device — Scan the QR code displayed in the console window, and then follow the on-screen prompts.
      Note: QR codes expire after 15 minutes. A new code appears in the console if the QR code expires.
    • In a web browser — Enter the displayed URL into the URL field, and then follow the on-screen prompts.

    After the virtual appliance successfully connects to Arctic Wolf, a prompt replaces the QR code.

Activate the vSensor

Note: Only the user who configured the vSensor can activate the vSensor.
  1. Sign in to the Arctic Wolf Unified Portal.
  2. If you are a Managed Service Provider (MSP), verify that you are viewing the correct customer organization.
  3. In the navigation menu, click Data Collection > Sensors.
  4. Find the virtual appliance that you want to activate, and then click View Sensor.
    Tip: Virtual appliances that are not activated have the Awaiting Activation status.
  5. Click Activate.
    The console displays Appliance activation in progress, please wait.
  6. If you are an MSP, select the same customer organization that you are currently viewing in the Unified Portal, and then Activate Virtual Appliance.
    Note: To activate the virtual appliance for a different customer, switch to that customer organization before completing this step.
    The serial console displays Appliance activation in progress, please wait.
  7. In the serial console, when prompted, press Enter three times to activate the console.

Configure a virtual network TAP

  1. In the Azure web portal, go to the Virtual network terminal access points page.
  2. Click Create.
  3. Complete these fields:
    • Resource Group — Select your resource group.
    • Name — Enter a name for the access point.
  4. Click Select destination resource, select the network interface that you created for the sensor in Attach a network interface, and then click Select.
  5. Click Review + create.
  6. Once the access point is created, in the Deployment succeeded modal, click Go to resource and confirm that the configuration is correct.
  7. In the side navigation, click Settings > Sources.
  8. Click Add.
  9. Select all sources that you want to associate with the sensor, then click Add.