Virtual Scanner Installation in VMware vSphere

Updated Sep 15, 2023

Install a vScanner using VMware vSphere

As part of Arctic Wolf® Managed Risk, install a Virtual Scanner (vScanner) to perform continuous risk monitoring and vulnerability assessments. vScanner provides context for vulnerabilities that you may have in your environment.

Requirements

Before you begin

Steps

  1. Download the vScanner image.
  2. Deploy the vScanner.
  3. Verify that the vScanner deployed correctly.
  4. Configure the vScanner.
  5. Activate the vScanner.

Step 1: Download the vScanner image

Note: The virtual appliance image file must be downloaded on or after June 14, 2023. For appliance images downloaded prior to June 14, 2023, see Legacy vScanner Installation.

  1. Sign in to the Risk Dashboard.

    Note: The Risk Dashboard is only compatible with Google Chrome.

  2. In the navigation menu, click Downloads.

  3. In the Download a Scanner Virtual Machine image for your virtualization infrastructure list, select VMware ESXi.

  4. Click Download Scanner VM.

    A new Arctic Wolf Portal web page opens.

  5. In the Virtual Network Appliances section, click Download Virtual Network Appliance to download the OVA file.

    Tip: If your browser downloads the OVA file in .ovf format, rename the file to change the file extension to .ova.

Step 2: Deploy the vScanner

  1. Sign in to your vSphere client.

  2. Right-click your resource pool, and then click Deploy OVF Template.

  3. On the Select an OVF template page:

    1. Select Local file.
    2. Click UPLOAD FILES.
    3. Select the downloaded OVA file, and then click Open.
    4. Click Next.
  4. On the Select a name and folder page:

    1. In the Virtual machine name field, enter a name for the vScanner.
    2. Select the location for the virtual machine, and then click Next.
    3. Click Next.
  5. On the Select a compute resource page:

    1. Select a destination compute resource.
    2. Click Next.
  6. On the Review details page, click Next.

  7. On the Configuration page, select AWN Risk Scanner.

  8. On the Select storage page:

    1. (Optional) Select Encrypt this virtual machine. See the VMware vSphere product documentation for steps to encrypt an existing virtual machine or virtual disk.

      Tip: While optional, Arctic Wolf strongly recommends that you encrypt the vScanner to ensure that all data stored and flowing through the appliance has an additional layer of protection.

    2. Select the storage location for the configuration and disk files, and then click Next.

  9. On the Select networks page:

    1. Select the appropriate Destination Network.

      Log traffic is sent to the vScanner over this network.

    2. Click Next.

  10. On the Ready to complete page, click Finish.

    Note: The OVA image may take some time to upload. In the vSphere Client, you can check the progress of the upload on the Recent Tasks tab.

Step 3: Verify that the vScanner deployed correctly

  1. If the vScanner power is off, right-click your virtual machine in the vSphere Client, and then click Power > Power On.
  2. Check if the vScanner VM power is on.
  3. Verify that the VM IP address is reported in the VM summary.

Step 4: Configure and activate the vScanner

  1. In the vSphere web UI, right-click your virtual machine, and then click Power > Power On.

  2. Right-click your virtual machine, and then click Console > Open Console.

  3. When prompted, press Enter three times to initiate the serial console session.

  4. At the Select an option to configure your management interface with prompt, select DHCP or enter a static IP address for the vScanner management interface.

    Note: If you select DHCP, you must use a DHCP reservation to prevent log collection and connection errors.

  5. Click Next.

  6. At the Use a proxy? prompt, do one of these actions:

    • If your vScanner traffic needs to go through a proxy server, select Yes, and then configure these fields:
      • Server IP address — Enter the proxy server IP address for your appliance.
      • Server port — Enter the proxy server port.
    • If your vScanner traffic does not need to go through a proxy server, select No.
  7. Click Next.

  8. At the Do you want to verify your network connection? prompt, select one of these options:

    • Yes

      A series of connectivity tests run.

    • No

  9. Click Next.

  10. At the Tell us about the application you are configuring prompt, configure these settings:

    1. In the Shorthand field, enter the shorthand name for the vScanner.

    2. Select Scanner.

  11. Click Next.

  12. When prompted, do one of these actions to connect the vScanner to the Arctic Wolf Platform:

    • Using a mobile device — Scan the QR code displayed in the console window, and then follow the on-screen prompts.
    • Using a web browser — Enter the displayed URL into a web browser, and then follow the on-screen prompts.

    Note: QR codes expire after 15 minutes. A new code appears in the console if the QR code expires.

    After the vScanner successfully connects to the Arctic Wolf Platform, a prompt replaces the QR code, asking you to go to the Arctic Wolf Appliance Management.

Step 5: Activate the vScanner

Note: Only the user who performed the steps to configure the vScanner can activate the vScanner.

  1. In the Arctic Wolf Portal, click Account > Arctic Wolf Appliance Management.

  2. Locate the name or the serial number of the vScanner you want to activate.

  3. In the Actions column, click Activate virtual appliance, and then click Activate Virtual Network Appliance when prompted.

    The console displays Appliance activation in progress, please wait.

  4. When prompted, press Enter three times to activate the console.

Next steps

Reconfigure a vScanner using VMware vSphere

  1. In the vSphere web UI, right-click your virtual machine, and then click Console > Open Console.
  2. When prompted, press Enter three times to initiate the serial console session.
  3. Change the required settings.

Uninstall a vScanner using VMware vSphere

  1. Decommission the vScanner:
    1. Sign in to the Arctic Wolf Portal.

    2. Click Account > Arctic Wolf Appliance Management

      A list of deployed virtual appliances appear on the Arctic Wolf Appliance Management page.

    3. Locate the short name or serial number of the vScanner that you want to decommission.

    4. Under Actions, click Decommission Virtual Appliance, and then select Decommission Virtual Appliance when prompted.

  2. Turn off the vScanner VM power.
  3. In the vSphere Client, select the vScanner, and then click Delete from Disk.

See also