Deploy the ExtraHop Discover Appliance on a Linux KVM
The following procedure guides you through the deployment process of the ExtraHop Discover EDA 1000v or EDA 2000v virtual appliance on a Linux kernel-based virtual machine (KVM). You should be familiar with basic KVM administration before proceeding.
If you have not already done so, download the ExtraHop Discover virtual appliance file for KVM from the ExtraHop Customer Portal.
Important: | If you want to deploy more than one ExtraHop virtual appliance, create the new instance with the original deployment package or clone an existing instance that has never been started. |
System requirements
Your environment must meet the following requirements to deploy a Discover appliance:
EDA 1000v | EDA 2000v |
---|---|
A KVM hypervisor environment capable of hosting a VM that includes:
|
A KVM hypervisor environment capable of hosting a VM that includes:
|
(Optional) Open vSwitch virtual switch software | (Optional) Open vSwitch virtual switch software |
An ExtraHop virtual appliance license key | An ExtraHop virtual appliance license key |
Package contents
The installation package for KVM systems is a tar.gz file that contains the following items:
Description | EDA 1000v file name | EDA 2000v file name |
---|---|---|
Domain XML configuration file | EDA 1000v_KVM.xml | EDA 2000v_KVM.xml |
Boot disk | extrahop-boot.qcow2 | extrahop-boot.qcow2 |
Datastore disk | extrahop-data.qcow2 | extrahop-data.qcow2 |
Deploy the Discover virtual appliance
To deploy the Discover virtual appliance, complete the following procedures:
Determine the best bridge configuration
Gather information about your network to determine the best virtual bridge configuration.
Create the virtual capture bridge
Before you enable packet capture by an ExtraHop virtual appliance, you must create a virtual bridge that is set to promiscuous mode. If you want to capture traffic from an external network, you must add a physical interface to the bridge, and that interface must be also be set to promiscuous mode.
The following procedure describes how to create a virtual bridge with Open vSwitch. For information on how to create a virtual bridge with the built-in Linux bridge, refer to the documentation for your KVM system.
Edit the domain XML configuration file
After you create your virtual bridge, edit the configuration file, and create the ExtraHop virtual appliance.
Configure a mirror session on the capture bridge
This procedure explains how to configure a mirror session on an Open vSwitch virtual bridge.
Start the VM
After you have created your new ExtraHop virtual appliance, you can log in to the management interface through a web browser to apply your license key, see network traffic, and customize your ExtraHop virtual appliance.
Configure a static IP address
By default, ExtraHop appliances ship with DHCP enabled. If your network does not support DHCP, you must configure a static address manually.
Register the ExtraHop appliance
Complete the following steps to apply a product key.
If you do not have a product key, contact your ExtraHop account team.
Tip: | To verify that your environment can resolve DNS entries for the
ExtraHop licensing server, open a terminal application on your Windows, Linux, or
Mac OS client and run the following
command:nslookup -type=NS d.extrahop.com If the name
resolution is successful, output similar to the following
appears:
Non-authoritative answer: d.extrahop.com nameserver = ns0.use.d.extrahop.com. d.extrahop.com nameserver = ns0.usw.d.extrahop.com. |
- In your browser, type the URL of the ExtraHop Admin UI, https://<extrahop_ip_address>/admin.
- Review the license agreement, select I Agree, and then click Submit.
- On the login screen, type setup for the username.
-
For the password, select from the following options:
- For 1U and 2U appliances, type the service tag number found on the pullout tab on the front of the appliance.
- For the EDA 1100, type the serial number displayed in the Appliance info section of the LCD menu. The serial number is also printed on the bottom of the appliance.
- For a virtual appliance, type default.
- Click Log In.
- In the Appliance Settings section, click License.
- Click Manage License.
- Click Register.
- Enter the product key and then click Register.
- Click Done.
Thank you for your feedback. Can we contact you to ask follow up questions?