Views:

Learn how to deploy your own Virtual Network Sensor on VMware ESXi.

Virtual Network Sensor is a lightweight network sensor that scans your network activity and feeds network activity data to Trend Vision One and allows you to discover unmanaged assets and gain a holistic view of your attack surface. Before using the features of Network Security, you need to set up your Virtual Network Sensor and connect your sensor to Trend Vision One.
Important
Important
  • If the throughput exceeds 2000 Mbps, Trend Micro recommends configuring your Virtual Network Sensor using a PCI passthrough that is compliant with the following drivers: Broadcom tg3 and bnxt_en, and Intel i40e, igb, ixgbe, and e1000.
Note
Note
Review the Virtual Network Sensor system requirements before starting and ensure you have adequate resources for Virtual Network Sensor.

Procedure

  1. In the Trend Vision One console, go to Network SecurityNetwork InventoryVirtual Network Sensor.
  2. Click Deploy Virtual Network Sensor.
    The Virtual Network Sensor Deployment panel appears.
  3. Select VMware ESXi (OVA) for the platform.
  4. Select the Connection method.
    • Direct connection: the Virtual Network Sensor connects to Trend Vision One directly. Make sure the Virtual Network Sensor is able to connect to the internet when using this configuration.
    • Connect using a custom proxy: the Virtual Network Sensor connects to Trend Vision One through a third-party proxy. After choosing this method, configure the following fields:
      • Proxy address: Specify the IP address of the proxy.
      • Proxy port: Specify the connecting port of the proxy.
      • Proxy server requires authentication: (Optional) Select if the proxy requires authentication credentials.
      • User name: Specify the user name for the proxy credentials.
      • Password: Specify the password for the proxy credentials.
    • Connect using a Service Gateway as proxy: the Virtual Network Sensor connects to Trend Vision One through a Service Gateway. Select a Service Gateway to use for this method.
      Important
      Important
      The Virtual Network Sensor must be able to connect to a Service Gateway with the Forward Proxy Service configured and enabled. For more information, see Managing services in Service Gateway.
  5. Click Download Disk Image.
  6. In the VMware ESXi console, configure network settings to allow Virtual Network Sensor to monitor data in VMware ESXi.
  7. On the VMware ESXi console, go to Virtual MachinesCreate / Register VM.
  8. On the Select creation type screen, select Deploy a virtual machine from an OVF or OVA file from the dropdown, and click Next.
  9. On the Select OVF and VMDK files screen, provide a name for the virtual machine, and select or drag and drop the Virtual Network Sensor disk image.
  10. Click Next.
  11. On the Select storage screen, select the storage type and datastore, and click Next.
  12. Click Next.
  13. On the Deployment options screen, specify the following settings:
    • Select VM Network as the management network (NIC 1), and Data port group as the data network (NIC 2).
      Note
      Note
      The NIC you chose for the management network must be able to connect to the internet.
    • Select a deployment type from the dropdown to configure the hardware setting automatically.
    • Select Thick for disk provisioning.
    • Select Power on automatically.
  14. Click Next.
  15. On the Additional settings screen, specify the following settings:
    • Expand System Settings, select the Bandwidth specified in the deployment type on the previous screen, and enter the Administrator password.
    • Expand Network Settings and configure the settings.
      Note
      Note
      The device name or FQDN may not include underlines.
    • Expand Proxy Settings and configure the settings.
  16. Click Next.
  17. On the Ready to complete screen, review your settings and click Finish.
    Your Virtual Network Sensor deploys and automatically connects to Network Inventory.
  18. To confirm that your Virtual Network Sensor has successfully deployed, go to Network SecurityNetwork InventoryVirtual Network Sensor on the Trend Vision One console to view information about your deployed Virtual Network Sensor.
    Note
    Note
    For information about troubleshooting Virtual Network Sensor, see Virtual Network Sensor CLI commands.