Deploy the ExtraHop Discover Appliance with VMware
The ExtraHop virtual appliance can help you to monitor the performance of your applications across internal networks, the public internet, or a virtual desktop interface (VDI), including database and storage tiers. ExtraHop can monitor application performance across geographically distributed environments such as branch offices or virtualized environments through intra-VM traffic.
Before you begin
- You must have familiarity with administrating VMware. The images in this guide are from VMware version 5.0.0, and some of the menu selections might have changed.
- We recommend that you upgrade to the latest patch for the vSphere environment, to avoid any known issues.
This guide explains how to deploy the following ExtraHop Discover virtual appliances on the VMware ESXi/ESX platform:
- EDA 1000v (Monitors up to 250 devices)
- Reveal(x) EDA 1100v (Monitors up to 250 devices)
- EDA 2000v (Monitors up to 1000 devices)
- EDA 6100v (Monitors up to 3000 devices)
Virtual machine requirements
You must have an existing installation of the VMware ESX/ESXi server version 5.5 or later, capable of hosting the Discover virtual appliance. In addition, you need a vSphere client to deploy the OVF file and to manage the virtual machine.
Appliance | CPU | RAM | Disk |
---|---|---|---|
EDA 1000v | 2 processing cores with hyper-threading support, VT-x or AMD-V technology, and 64-bit
architecture. If you want to enable SSL decryption, 3 CPUs are required. For more information, see Add a CPU Core to the EDA 1000v with VMware. |
4 GB | 46 GB or higher disk (thick-provisioned) |
Reveal(x) EDA 1100v | 4 processing cores with hyper-threading support, VT-x or AMD-V technology, and 64-bit architecture. | 8 GB | 46 GB or higher disk (thick-provisioned) |
EDA 2000v | 6 processing cores with hyper-threading support, VT-x or AMD-V technology, and 64-bit architecture. | 6 GB | 255 GB or higher disk (thick-provisioned) |
EDA 6100v | 16 processing cores with hyper-threading support, VT-x or AMD-V technology, and 64-bit architecture. | 64 GB | 1 TB or higher disk (thick-provisioned) |
- Make sure that the VMware ESX/ESXi server is configured with the correct date and time.
- Always choose thick provisioning. The ExtraHop datastore requires low-level access to the complete drive and is not able to grow dynamically with thin provisioning. Thin provisioning can cause metric loss, VM lockups, and capture issues.
- Do not change the default disk size on initial installation. The default disk size ensures correct lookback for ExtraHop metrics and proper system functionality. If your configuration requires a different disk size, contact your ExtraHop representative before you make any changes.
- Do not migrate the VM. Although it is possible to migrate when the datastore is on a remote SAN, ExtraHop does not recommend this configuration.
Important: | If you want to deploy more than one ExtraHop virtual appliance, create the new instance with the original deployment package or clone an existing instance that has never been started. |
Network requirements
Appliance | Intra-VM | External |
---|---|---|
EDA 1000v | One 1-Gbps Ethernet network port is required (for management). The management port must be accessible on port 443. | Two 1-Gbps Ethernet network ports are required. One for the physical port mirror and
one for management. The physical port mirror interface must be connected to the port mirror
of the switch. While it is possible to configure a 10-Gbps Ethernet network port for the port mirror interface, it is not recommended as the virtual appliance cannot process more than 1 Gbps of traffic. |
EDA 2000v | One 1-Gbps Ethernet network port is required (for management). The management interface must be accessible on port 443. | Two to four 1-Gbps Ethernet network ports are required for the physical port mirror
and management. The physical port mirror interface must be connected to the port mirror of
the switch. The VMware ESX server must support network interface drivers. While it is possible to configure a 10-Gbps Ethernet network port for the port mirror interface, it is not recommended as the virtual appliance cannot process more than 3 Gbps of traffic. |
EDA 6100v | One 1-Gbps Ethernet network port is required (for management). The management interface must be accessible on port 443. | A 10-Gbps Ethernet network port is recommended for the physical port mirror.
Optionally, you can configure two to four 1-Gbps Ethernet network ports for the physical
port mirror and management. The physical port mirror interface must be connected to the port mirror of the switch. The VMware ESX server must support network interface drivers. |
Note: | For registration purposes, the virtual Discover appliance requires outbound DNS connectivity on UDP port 53 unless managed by the ExtraHop Command appliance. |
Deploy the OVA file through the VMware vSphere web client
ExtraHop distributes the Discover virtual appliance package in the open virtual appliance (OVA) format.
Before you begin
If you have not already done so, download the ExtraHop Discover virtual appliance OVA file for VMware from the ExtraHop Customer Portal.Configure a static IP address through the CLI
The ExtraHop appliance is delivered with DHCP enabled. If your network does not support DHCP, no IP address is acquired, and you must configure a static address manually.
- Establish a console connection to the ExtraHop appliance.
- At the login prompt, type shell and then press ENTER.
- At the password prompt, type default, and then press ENTER.
-
To configure the static IP address, run the following commands:
Configure the Discover appliance
After you configure an IP address for the Discover appliance, open a web browser and navigate to the ExtraHop Web UI through the configured IP address. Accept the license agreement and then log in. The default login name is setup and the password is default. Enter the product key to license the appliance.
After the appliance is licensed, and you have verified that traffic is detected, complete the recommended procedures in the post-deployment checklist.
Mirror Wire Data
This section includes procedures for mirroring data to your ExtraHop virtual appliance.
Mirroring internal and external traffic
The ExtraHop Discover virtual appliance can be configured to monitor network traffic in the following network configuration examples.
- Monitoring
Intra-VM Traffic
- One virtual interface on the EDA 1000v
- Up to three virtual interfaces on the EDA 2000v or EDA 6100v
- Monitoring external mirrored traffic to the VM
- Monitoring external mirrored traffic to the VM (EDA 2000v or EDA 6100v)
- Monitoring both intra-VM and external mirrored traffic to the VM (EDA 2000v or EDA 6100v)
Note: | Monitoring external network-mirrored traffic requires an external NIC and an associated virtual switch. |
Monitoring intra-VM traffic
This scenario requires a second VM port group on the default virtual switch of the ESX host for monitoring traffic within the virtual switch as well as external traffic in and out of the switch.
Monitoring external mirrored traffic to the VM
This scenario requires a second physical network interface and the creation of a second vSwitch associated with that NIC. This NIC then connects to a mirror, tap, or aggregator that copies traffic from a switch. This setup is useful for monitoring the intranet of an office.
Monitoring external mirrored traffic to the VM (EDA 2000v or EDA 6100v)
In this scenario, you must create a third and fourth physical network interface and two more vSwitches associated with those NICs. These NICs then connect to a mirror, tap, or aggregator that copies traffic from a switch.
Thank you for your feedback. Can we contact you to ask follow up questions?