Requirements

What you need to get started

  • Access to the SamurAI Portal and your specific tenant.
  • A supported deployment platform for the NTA. Supported hypervisors and cloud platforms are listed below.
  • An NTA virtual machine that meets the recommended specifications for the required monitoring throughput.
  • Network changes required to meet the NTA communication requirements.
  • A static IP address for the NTA management interface and DNS server IP addresses, unless you use DHCP.
  • Access to configure traffic mirroring to the NTA monitoring interface.

Supported hypervisors

HypervisorSupported version or requirement
VMware ESXiESXi 8.x and ESXi 9.x
Microsoft Hyper-VHyper-V 2016 and later; deploy the NTA as a Generation 2 virtual machine.
Proxmox Virtual EnvironmentProxmox VE 8.4.1 and later.
KVM-based environmentsKVM environments that support UEFI virtual machines, provide two virtual network interfaces, and can import the NTA KVM bundle.

Supported cloud platforms

PlatformSupported instance types or requirements
Amazon EC2Nitro-based instances using HVM virtualization and supporting VPC Traffic Mirroring.

Amazon Web Services support

For AWS deployment, the NTA requires AWS Nitro instances that support traffic mirroring. For more information, refer to:

NTA sizing is based on the expected monitored network throughput. Select the NTA size that meets your required throughput.

MediumLarge
Throughput500 Mbit/s1000 Mbits/s
CPU8 Cores8 cores
Memory52 GB RAM
(32 GB RAM for OS and 20GB RAM for ramdisk)
104 GB RAM
(64 GB RAM for OS and 40GB RAM for ramdisk)
DisksSystem disk: 300GB
Data disk 200GB
System disk: 300GB
Data disk 200GB
Network InterfacesManagement:1 x 1 Gbit/s
Network Monitoring:1 x 1 Gbit/s
Management:1 x 1 Gbit/s
Network Monitoring:1 x 1 Gbit/s

Communication requirements

The NTA requires connectivity to the resources listed below. Update security controls, such as firewall rules, proxy settings, and DNS configuration, as needed to allow the required communications.

FunctionProtocolPortSourceDestinationDetails
Enrolment, NTA backendTCP443NTA*.*.security.ntt

nttsecurity.io
.nttsecurity.io
.*.nttsecurity.io

samurai-xdr-prod-westeurope-xgliuoit.azure-api.net
All regular backend communication
Remote ManagementTCP443NTAra.cto.nttsecurity.io

deb.releases.teleport.dev

apt.releases.teleport.dev
Remote administration of an NTA
NTPUDP123NTAClient infrastructure (NTP server(s)) if configured in SamurAI Portal

OR

0.ubuntu.pool.ntp.org

1.ubuntu.pool.ntp.org

2.ubuntu.pool.ntp.org

3.ubuntu.pool.ntp.org
Time synchronization
DNSUDP53NTAClient infrastructure (DNS server(s)) or external DNS servers (based on your NTA configuration)Domain name resolution
Ubuntu updatesTCP80, 443NTA*.ubuntu.com

api.snapcraft.io
Ubuntu software repository
Container ManagementTCP443NTAdocker.com

*.docker.com (private container registry)

docker.io (private container registry)

*.docker.io (private container registry)
Private container registry
Amazon Cloud dependenciesTCP443NTA*.cloudfront.netAmazon CDN used by NTA API

What’s next?

You now understand the supported deployment platforms, NTA sizing requirements, and required communications. Proceed to SamurAI NTA Deployment.