Arctic Wolf Appliances

vScanner Installation in a VMware vSphere Environment

Updated Feb 20, 2024

Install a vScanner in a VMware vSphere Environment

You can install an Arctic Wolf® Virtual Scanner (vScanner) in a VMware vSphere® environment.


Before you begin


  1. Download the vScanner image.
  2. Deploy the vScanner.
  3. Verify that the vScanner deployed correctly.
  4. Configure the vScanner.
  5. Activate the vScanner.

Step 1: Download the vScanner image

Note: The virtual appliance image file must be downloaded on or after June 14, 2023. For appliance images downloaded before June 14, 2023, see Legacy vScanner Installation.

  1. Sign in to the Risk Dashboard.

    Note: The Risk Dashboard is only compatible with Google Chrome.

  2. In the navigation menu, click Downloads.

  3. In the Download a Scanner Virtual Machine image for your virtualization infrastructure list, select VMware ESXi.

  4. Click Download Scanner VM.

    The MDR Dashboard opens in a new browser window.

  5. In the Virtual Network Appliances section, click Download Virtual Network Appliance to download the OVA file.

    Tip: If your browser downloads the OVA file in .ovf format, rename the file to change the file extension to .ova.

Step 2: Deploy the vScanner

  1. Sign in to your vSphere client.

  2. Right-click your resource pool, and then select Deploy OVF Template.

  3. On the Select an OVF template page:

    1. Select Local file.
    2. Click UPLOAD FILES.
    3. Select the downloaded OVA file, and then click Open.
    4. Click Next.
  4. On the Select a name and folder page:

    1. In the Virtual machine name field, enter a name for the vScanner.
    2. Select the location for the virtual machine, and then click Next.
    3. Click Next.
  5. On the Select a compute resource page:

    1. Select a destination compute resource.
    2. Click Next.
  6. On the Review details page, click Next.

  7. On the Configuration page, select AWN Risk Scanner.

  8. On the Select storage page:

    1. (Optional) Select Encrypt this virtual machine. See the VMware vSphere product documentation for steps to encrypt an existing virtual machine or virtual disk.

      Tip: While optional, Arctic Wolf recommends that you encrypt the vScanner to make sure all data stored and flowing through the appliance has an added layer of protection.

    2. Select the storage location for the configuration and disk files.

    3. Click Next.

  9. On the Select networks page:

    1. Select the appropriate Destination Network.

      Log traffic is sent to the vScanner across this network.

    2. Click Next.

  10. On the Ready to complete page, click Finish.

    Note: The OVA image can take some time to upload. In the vSphere Client, on the Recent Tasks tab, you can view the progress of the upload.

Step 3: Verify that the vScanner deployed correctly

  1. If the vScanner power is off, right-click your VM in the vSphere Client, and then click Power > Power On.
  2. Verify that the vScanner VM power is on.
  3. Verify that the VM IP address appears in the VM summary.

Step 4: Configure and activate the vScanner

  1. In the vSphere web UI, right-click your VM, and then click Power > Power On.

  2. Right-click your VM, and then click Console > Open Console.

  3. When prompted, press Enter three times to initiate the serial console session.

  4. At the Select an option to configure your management interface with prompt, select DHCP or enter a static IP address for the vScanner management interface.

    Note: If you select DHCP, you must use a DHCP reservation to prevent log collection and connection errors.

  5. Click Next.

  6. At the Use a proxy? prompt, do one of these actions:

    • If your vScanner traffic goes through a proxy server, select Yes, and then configure these settings:
      • Server IP address — Enter the proxy server IP address for your appliance.
      • Server port — Enter the proxy server port.
    • If your vScanner traffic does not go through a proxy server, select No.
  7. Click Next.

  8. At the Do you want to verify your network connection? prompt, select one of these options:

    • Yes

      A series of connectivity tests run.

    • No

  9. Click Next.

  10. At the Tell us about the application you are configuring prompt, configure these settings:

    • In the Shorthand field, enter the shorthand name for the vScanner.

    • Select Scanner.

  11. Click Next.

  12. When prompted, do one of these actions to connect the vScanner to the Arctic Wolf Platform:

    • On a mobile device — Scan the QR code displayed in the console window, and then follow the on-screen prompts.

      Note: QR codes expire after 15 minutes. A new code appears in the console if the QR code expires.

    • In a web browser — Enter the displayed URL into the URL field, and then follow the on-screen prompts.

    After the vScanner successfully connects to the Arctic Wolf Platform, a prompt replaces the QR code, asking you to sign in to the MDR Dashboard, and then click Accounts > Arctic Wolf Appliance Management.

Step 5: Activate the vScanner

Note: Only the user who completed Configure the vScanner can activate the vScanner.

  1. Sign in to the MDR Dashboard.

  2. Click Account > Arctic Wolf Appliance Management.

  3. Find the appliance that you want to activate.

  4. In the Actions column, click Activate <appliance>, and then click Activate <appliance> when prompted.

    The console displays Appliance activation in progress, please wait.

  5. When prompted, press Enter three times to activate the console.

Next steps

See also