Deploy the ExtraHop Flow Collector with VMware
This guide explains how to deploy the ExtraHop Flow Collector virtual appliance (EFC 1290v) on the VMware ESXi/ESX platform.
The EFC 1290v is designed to connect to Reveal(x) 360 and collect flow-based traffic from your network. Features available on packet sensors, such as machine learning, rules-based detections, threat intelligence, packet analysis, and activity maps, are not available on the EFC 1290v. Triggers and Open Data Streams are supported.
The EFC 1290v supports the following flow technologies: Cisco NetFlow v5 and v9, AppFlow, IPFIX, and sFlow. For more information on collecting traffic from Netflow and sFlow devices, see Collect traffic from NetFlow and sFlow devices.
Virtual machine requirements
Your hypervisor must be able to support the following virtual machine requirements for the virtual Flow Collector appliance.
- An existing installation of VMware ESX or ESXi server version 6.5 or later capable of hosting the virtual Flow Collector appliance.
- The virtual Flow Collector appliance has the following resource
requirements:
Appliance CPU RAM Disk Reveal(x) EFC 1290v 4 processing cores with hyper-threading support, VT-x or AMD-V technology, and 64-bit architecture. Streaming SIMD Extensions 4.2 (SSE4.2) and POPCNT instruction support. 8 GB 46 GB or larger disk for data storage (thick-provisioned)
The following configuration settings are required to ensure proper functionality of the virtual appliance:
- Make sure that the VMware ESX/ESXi server is configured with the correct date and time.
- Always choose thick provisioning. The ExtraHop datastore requires low-level access to the complete drive and is not able to grow dynamically with thin provisioning. Thin provisioning can cause metric loss, VM lockups, and capture issues.
- Do not change the default disk size on initial installation. The default disk size ensures correct lookback for ExtraHop metrics and proper system functionality. If your configuration requires a different disk size, contact your ExtraHop representative before you make any changes.
- Do not migrate the VM. Although it is possible to migrate when the datastore is on a remote SAN, ExtraHop does not recommend this configuration. If you must migrate the VM to a different host, shut down the virtual appliance first and then migrate with a tool such as VMware VMotion. Live migration is not supported.
Important: | If you want to deploy more than one ExtraHop virtual appliance, create the new instance with the original deployment package or clone an existing instance that has never been started. |
Network requirements
The following table provides guidance about configuring network ports for your virtual Flow Collector appliance.
Appliance | Management | Flow Network |
---|---|---|
Reveal(x) EFC 1290v | One 1 GbE network port is required (for management). The management port must be accessible on port 443. |
One 1 GbE network port or virtual interface is required. The flow target interface must be connected to the source of the NetFlow traffic. |
Note: | For registration purposes, the Flow Collector appliance requires outbound connectivity on TCP port 443. |
Deploy the OVA file through the VMware vSphere web client
ExtraHop distributes the Flow Collector virtual appliance package in the open virtual appliance (OVA) format.
Before you begin
Download the 1100v Reveal(x) virtual Discover appliance OVA file for VMware from the ExtraHop Customer Portal. The EDA 1100v appliance is automatically converted to the EFC 1290v after you register the appliance with the 1290v product key.Configure a static IP address through the CLI
The ExtraHop system is delivered with DHCP enabled. If your network does not support DHCP, no IP address is acquired, and you must configure a static address manually.
- Access the CLI through an SSH connection to the configured IP address, vSphere web console, or VMware Remote Console.
- At the login prompt, type shell, and then press ENTER.
- At the password prompt, type default, and then press ENTER.
-
To configure the static IP address, run the following commands:
Thank you for your feedback. Can we contact you to ask follow up questions?