Install a vSensor in a VMware vSphere environment
You can install an Arctic Wolf® Virtual Sensor (vSensor) in a VMware vSphere® environment.
- Each virtual appliance virtual machine (VM) supports one network interface. If more network interfaces are necessary, deploy more virtual appliance VMs.
- If you are deploying multiple virtual appliance instances, Arctic Wolf recommends that you use the same OVA file, and then complete the installation and activation process again for each virtual appliance.
- Cloning a virtual appliance instance is not supported because it creates operational errors in the original virtual appliance and in the cloned instance.
- Some detections may not be available if sensors cannot see the relevant network traffic, including traffic flowing through different switches or unmonitored firewalls. Make sure that sensors are properly placed across all network egress points.
- During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
These resources are required:
- These system resources:
Model
Number of vCPUs
RAM
Storage
AWNv100
2
8 GB
40 GB
AWNv200
8
16 GB
40 GB
AWNv1000
24
48 GB
40 GB
Note: Reducing or limiting resource allocations below the specified requirements affects virtual appliance performance. If the appliance's CPU is throttled, security observations can be lost. Do not configure the Reservation, Limit, or Shares settings to throttle the appliance's CPU. - vSphere with vCenter 6.5 or newer
These actions are required:
- Make sure you have the appropriate Arctic Wolf permissions to install the appliance. Contact your Concierge Security® Team (CST) at security@arcticwolf.com to identify who in your organization has these permissions.
- Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click , and then view the IP addresses in the section for your product.
- If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
- If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
- If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.
- Configure log forwarding. For more information, see Syslog forwarding.
Download the vSensor image
Deploy the vSensor
Verify that the vSensor deployed correctly
- If the virtual appliance power is off, right-click your VM in the vSphere Client, and then click .
- Verify that the virtual appliance VM power is on.
- Verify that the VM IP address appears in the VM summary.
Connect to the serial console
- In the vSphere web UI, right-click your VM, and then click .
- Right-click your VM, and then click .
Configure the vSensor
Use the serial console to configure the vSensor. For more information on using the serial console, see Serial console.
Activate the vSensor
Configure optional layer 3 mirroring
You can configure optional layer 3 mirroring on the sensor to receive network traffic from a remote IP address to the AWN Sensor through LAN 1. This configuration allows a sensor to be deployed anywhere that supports Encapsulated Remote Switched Port Analyzer (ERSPAN).
For physical sensors, the management port IP address and lanID IP address cannot be on the same subnet.
This optional configuration requires assigning a static IP address to lanID for a physical sensor or lan0 for a virtual sensor. The sensor does not support DHCP or DHCP reservation for the LAN IP address. Contact your CST at security@arcticwolf.com to configure this option.