This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Deployment

    Deployment considerations

    Traffic source

    The NTA is a passive device. It relies on customer infrastructure to send a copy of network traffic to the NTA monitoring interface. When deploying an NTA in a virtual environment or on Amazon EC2, consider the following requirements to achieve effective traffic monitoring and minimise performance impact.

    Resource allocation

    Ensure the NTA meets the recommended specifications. In some circumstances, the allocated resources may not be sufficient. We may recommend changes after the NTA is deployed and traffic throughput has been assessed.

    Multi-NTA deployments

    If expected network throughput exceeds the capacity of one NTA, deploy multiple NTAs to maintain coverage.

    Network topology and segmentation

    Map the virtual network topology and identify the optimal deployment location for the NTA. Consider both:

    • East-west traffic between workloads on the same virtual switch, virtual network, or Amazon VPC.
    • North-south traffic between internal and external networks, such as internet-facing web traffic.

    Traffic visibility

    A copy of monitored traffic must be sent to the NTA monitoring interface.

    Recommended traffic sources include:

    • Client-to-internet traffic.
    • Client-to-client traffic.
    • Client-to-server traffic.

    Traffic that is typically not useful for NTA monitoring includes:

    • High-volume encrypted traffic where the NTA cannot inspect the payload.
    • SAN and backup traffic.

    Capture traffic by configuring network mirroring or traffic monitoring for the selected deployment platform.

    Virtual environments

    Network mirroring on a virtual switch copies traffic from one or more source ports to a destination mirror port. Connect that destination to the NTA monitoring interface. In virtualised environments, the implementation may use port mirroring, SPAN, promiscuous mode, or a platform-specific monitoring capability.

    NTA in a virtual environment

    Figure 1: The NTA in a virtual environment

    Amazon EC2

    For Amazon EC2 deployments, use VPC Traffic Mirroring to copy traffic from an Elastic Network Interface (ENI) to the NTA monitoring interface.

    NTA running on AWS

    Figure 2: The NTA running on AWS

    Create, configure and download an NTA

    1. Log in to the SamurAI Portal, select Telemetry, and then select Network Traffic Analyzer from the main menu.
    2. Select Create.
    3. Complete the fields as required.
    FieldDescription
    NTA nameA name for the NTA.
    Description (Optional)A description of the NTA.
    Location (Optional)Useful when you have NTAs in multiple locations.
    HostnameA hostname for the NTA.
    Proxy Server address (Optional)An optional HTTP proxy URL containing a hostname or IP address and port, for example https://192.168.1.254:8080.
    NTP Servers (Optional)Your NTP server IP addresses.
    SizeSelect the appropriate size based on expected monitored throughput.
    DHCP or StaticSelect DHCP, or specify a static IP address and network information.
    1. Select Create NTA after completing the relevant fields.
    2. Select the NTA by clicking the NTA Name used in step 3.
    3. Select Download.

    The files you download depend on the selected deployment platform.

    • Configuration

      • ISO — NTA-specific configuration file.
        • Required for all NTA deployments. Mount this ISO when the NTA starts for the first time so that it can configure and register with the SamurAI platform.
    • Cloud init

      • AWS — Cloud-init data for an Amazon EC2 instance.
    • Virtual machine

      • **OVA - Virtual appliance package for VMware vSphere and Proxmox VE (includes disk images)
      • VMDK — Virtual disk image for VMware vSphere manual deployment (not needed if using the OVA).
      • VHDX — Virtual hard-disk image for Microsoft Hyper-V.
      • **KVM bundle — — Virtual-machine package for KVM-based environments
    1. Download the NTA configuration ISO file and the file or files required for the selected deployment platform.

    NTA installation

    Select the section relevant to your deployment platform:

    VMware vSphere installation

    Follow the VMware documentation:

    1. Provide a meaningful virtual-machine name.
    2. Select the NTA OVA file downloaded from the SamurAI Portal. Select the appropriate E1000 or E500 variant for the target environment.
    3. Ensure the virtual machine is configured to use UEFI firmware.
    4. Configure CPU, memory, storage, and both virtual network interfaces in accordance with the recommended specifications.

    After deployment, mount the NTA configuration ISO file. Refer to VMware documentation:

    1. Select the NTA configuration ISO file downloaded from the SamurAI Portal.
    2. Ensure the CD/DVD drive is connected when the virtual machine starts.
    3. Confirm that Network Device (net0) is connected to the management network.
    4. Confirm that Network Device (net1) is connected to the network or port group that receives mirrored traffic.
    5. Start the virtual machine.
    6. Continue to Deployment status.

    Proxmox VE installation

    Follow the Proxmox documentation:

    1. Create or select storage to use as the import source.
    2. Use the OVA/OVF import workflow to import the NTA OVA file downloaded from the SamurAI Portal. Select the appropriate E1000 or E500 variant for the target environment.
    3. Ensure the imported virtual machine is configured to use UEFI firmware.
    4. Configure CPU, memory, storage, and both virtual network interfaces in accordance with the recommended specifications.

    Import the NTA configuration ISO file to Proxmox:

    1. Navigate to Datacenter and select Storage.
    2. Select the storage location where you want to store the ISO file.
    3. Select ISO Images.

    Proxmox: select ISO Images

    1. Select Upload.
    2. Select the NTA configuration ISO file and upload it using the default settings.

    Proxmox: upload the configuration ISO

    Configure the NTA virtual machine to use the configuration ISO file:

    1. Select the NTA virtual machine, select Hardware, and then select Add.

    Proxmox: open VM hardware settings

    1. Select CD/DVD Drive.

    Proxmox: add CD/DVD drive

    1. Select Use CD/DVD disk image file (ISO), locate the NTA configuration ISO file, and select Add.

    Proxmox: select the configuration ISO

    1. Confirm that Network Device (net0) is connected to the management network.
    2. Confirm that Network Device (net1) is connected to the network or bridge that receives mirrored traffic.
    3. Start the virtual machine.
    4. Continue to Deployment status.

    Microsoft Hyper-V installation

    Follow Microsoft documentation:

    1. Provide a meaningful virtual-machine name.
    2. Create the NTA as a Generation 2 virtual machine.
    3. Configure CPU, memory, storage, and two virtual network adapters in accordance with the recommended specifications.
    4. When prompted to connect a virtual hard disk, select the NTA VHDX file downloaded from the SamurAI Portal.
    5. Attach the NTA configuration ISO file to the virtual DVD drive and ensure the drive is connected at startup.
    6. Connect Eth0 to the management network.
    7. Connect Eth1 to the virtual switch or network that receives mirrored traffic.
    8. Start the virtual machine.
    9. Continue to Deployment status.

    KVM-based environments installation

    This section applies to KVM environments, including platforms that use libvirt, QEMU/KVM, Open vSwitch, or another KVM management interface. The exact workflow for creating or importing a virtual machine and configuring traffic mirroring differs by KVM management platform. Follow your platform’s documentation for these actions.

    Prerequisites:

    1. Download the NTA configuration ISO file for the NTA you created.
    2. Download the NTA KVM bundle.
    3. Extract the KVM bundle.

    Use your KVM platform documentation to create or import a virtual machine from the extracted NTA image.

    When creating or configuring the NTA virtual machine:

    1. Configure the virtual machine to use UEFI firmware.
    2. Configure CPU, memory, system disk, and data disk in accordance with the recommended specifications.
    3. Add two virtual network interfaces.
    4. Connect the first interface to the management network, which must allow the required outbound connectivity.
    5. Connect the second interface to a dedicated monitoring network, virtual switch, bridge, or port that receives mirrored traffic.
    6. Attach the NTA configuration ISO file as a virtual CD/DVD drive.
    7. Ensure the virtual CD/DVD drive is connected when the virtual machine starts for the first time.
    8. Start the virtual machine.
    9. Continue to Deployment status.

    Refer to the documentation appropriate for your KVM environment:

    Amazon EC2 installation

    Prerequisites:

    1. Download the AWS cloud-init.yaml file from Create, configure and download an NTA. You will use this file during EC2 instance deployment.

    Follow Amazon documentation to launch an EC2 instance:

    Apply the following adjustments while following the Amazon documentation:

    1. Select Ubuntu as the AMI.
    2. Select the latest supported Ubuntu 24.04 Server AMI.
    3. Select an instance type that meets the recommended specifications.
    4. Configure the key pair and network settings according to your organisation’s policies. Ensure network settings fulfil the communication requirements.
    5. Configure storage according to the system-disk and data-disk requirements for the selected NTA size.
    6. In Advanced details, paste the contents of the AWS cloud-init.yaml file into User data. Do not select User data has already been base64 encoded.
    7. Complete the remaining instance configuration according to your organisation’s requirements and the Amazon documentation.
    8. Configure VPC Traffic Mirroring so that the selected traffic is sent to the NTA monitoring interface.
    9. Continue to Deployment status.

    Deployment status

    After deploying the NTA, view deployment progress and status in the SamurAI Portal.

    1. Log in to the SamurAI Portal.
    2. Select Telemetry, and then select Network Traffic Analyzer from the main menu.
    3. Select the relevant NTA.
    4. Under General, the Status initially displays as Provisioning.
    5. Review Deployment Status, which displays deployment phases and timestamps. Each completed phase is shown in green.
    No.Deployment status messageDescription
    1Initial call to backend. Network connectivity okThe NTA has sent its first message to the SamurAI backend and enrolment has started.
    2Refreshing OS package listsRefreshing operating-system software repository information.
    3Upgrading packagesStarting operating-system updates.
    4Finished upgrading packagesOperating-system update completed.
    5Base OS update completedPost-update operating-system maintenance jobs completed.
    6Initiating CTS Build XNTA installer downloaded and started.
    7Running verification to ensure minimal requirementsInstaller is verifying minimum requirements and software settings.
    8Completed verification to ensure minimal requirementsVerification completed.
    9Request device_idRequesting device identity.
    10Request initStarting the registration process.
    11Initiator successfully contacted backendContacting the backend to retrieve basic operating information.
    12Downloading configurationDownloaded configuration.
    13Logged in to dockerhubAuthorised to Docker Hub to access private containers.
    14Downloading Docker containersContainers downloaded from Docker Hub and ready for use.
    15Storing device configuration to the backendSending device information to the backend.
    16Starting ManagerStarting NTA Manager. Additional software or containers may download in the background.
    1. When NTA deployment is complete, Status initially displays as Not Healthy while individual components start. The status changes to Healthy when startup is complete, which can take approximately five minutes.

    Configure traffic mirroring

    After deployment, determine the NTA monitoring interface before configuring traffic mirroring.

    1. Log in to the SamurAI Portal.
    2. Select Telemetry, and then select Network Traffic Analyzer from the main menu.
    3. Select the relevant NTA.
    4. Select System Information and review Network to identify the Management and Monitoring interfaces. Record each MAC address and confirm that it matches the relevant hypervisor or AWS configuration.
    5. Configure traffic mirroring to send the required traffic to the NTA monitoring interface. Refer to your deployment platform documentation because mirroring implementations differ between environments.

    Useful vendor documentation includes:

    VMware vSphere

    Microsoft Hyper-V

    The following Microsoft documentation uses Microsoft Defender for IoT examples, but its traffic-mirroring concepts also apply to NTA deployments:

    KVM-based environments

    Use the traffic-mirroring capability of the KVM platform, virtual switch, bridge, or network fabric that carries the traffic you want to monitor. Examples include Open vSwitch port mirroring and platform-specific bridge or switch mirroring.

    Amazon EC2

    Detection testing

    After deploying the NTA, validate that network traffic is monitored and analysed correctly.

    The NTA includes a built-in test detection signature that triggers on ICMP Echo Request traffic with a payload size of 333 bytes. This allows you to validate end-to-end traffic visibility and detection without affecting normal operations.

    Generate test traffic

    Generate ICMP traffic using one of the methods below.

    Windows

    From Command Prompt, run:

    ping -l 333 X.X.X.X
    

    Linux

    From a terminal, run:

    ping -s 333 X.X.X.X
    

    Cisco routers and switches

    Use Extended Ping and specify a datagram size of 361 bytes.

    The Extended Ping datagram size includes:

    • IP header: 20 bytes.
    • ICMP header: 8 bytes.
    • ICMP payload: 333 bytes.

    Total: 361 bytes.

    Expected detection

    After generating the test traffic, the NTA should generate the following alert:

    Test Alert using ICMP size 333 for NTA validation

    View this alert in the NTA Alerts panel. Refer to Alerts for more information.

    • The detection is triggered by the ICMP Echo Request. A reply from the destination host is not required.
    • The test signature does not affect traffic analysis or detection accuracy and is safe to use for validation.

    If no alert is generated

    If no alert is shown after generating the test traffic, verify the following:

    • Test traffic was generated from a network segment monitored by the NTA.
    • Traffic from the source network is mirrored to the NTA.
    • The NTA is receiving traffic on the monitoring interface.
    • The ICMP Echo Request used the correct 333-byte payload size.
    • Sufficient time has been allowed for the alert to be processed and displayed.

    If all checks pass and no alert is generated, submit a ticket through the SamurAI Portal.

    Delete an NTA

    To delete an NTA:

    1. In the SamurAI Portal, select Telemetry, and then select Network Traffic Analyzer.
    2. Select the relevant NTA.
    3. Select the More options icon and then select Delete NTA.
    4. Review the warning. To confirm the destructive action, enter DELETE and select Delete NTA.

    What’s next?

    You have now deployed and configured your NTA. Refer to NTA Details.