This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Requirements

    What you need to get started

    • Access to the Samurai MDR portal and your specific tenant.

    • A hypervisor to run the virtual machine, for example VMware ESXi, Microsoft Hyper-V or relevant access to AWS for deployment to an Amazon EC2 instance.

    • Make any necessary updates to comply with the NTA Communications Requirements.

    • A static IP address for the NTA management interface and DNS server IP addresses unless you decide to use DHCP.

    • Necessary access to configure traffic mirroring to the NTA.

    Supported Hypervisors

    The NTA supports the follows hypervisors and versions:

    HypervisorVersion
    VMware ESXi7.x and above
    Microsoft Hyper-V2016 and above
    Proxmox Virtual Environment8.4.1 and above

    Amazon Web Services Support

    For AWS deployment, the NTA requires use of AWS Nitro instances that support traffic mirroring, more information can be found at:

    There are two NTA sizes which are based on network throughput, therefore note the specifications based on your requirements.

    MediumLarge
    Throughput500 Mbit/s1000 Mbits/s
    CPU8 Cores8 cores
    Memory52 GB RAM
    (32 GB RAM for OS and 20GB RAM for ramdisk)
    104 GB RAM
    (64 GB RAM for OS and 40GB RAM for ramdisk)
    DisksSystem disk: 300GB
    Data disk 200GB
    System disk: 300GB
    Data disk 200GB
    Network InterfacesManagement:1 x 1 Gbit/s
    Network Monitoring:1 x 1 Gbit/s
    Management:1 x 1 Gbit/s
    Network Monitoring:1 x 1 Gbit/s

    Communication Requirements

    The NTA requires connectivity to resources outlined within the table below, you may need to update your security controls e.g firewall to allow this connectivity.

    FunctionProtocolPortSourceDestinationDetails
    Enrolment, NTA backendTCP443NTA*.*.security.ntt

    nttsecurity.io
    .nttsecurity.io
    .*.nttsecurity.io

    samurai-xdr-prod-westeurope-xgliuoit.azure-api.net
    All regular backend communication
    Remote ManagementTCP443NTAra.cto.nttsecurity.io

    deb.releases.teleport.dev

    apt.releases.teleport.dev
    Remote administration of an NTA
    NTPUDP123NTAClient infrastructure (NTP server(s)) if configured in Samurai app

    OR

    0.ubuntu.pool.ntp.org

    1.ubuntu.pool.ntp.org

    2.ubuntu.pool.ntp.org

    3.ubuntu.pool.ntp.org
    Time synchronization
    DNSUDP53NTAClient infrastructure (DNS server(s)) or external DNS servers (based on your NTA configuration)Domain name resolution
    Ubuntu updatesTCP80, 443NTA*.ubuntu.com

    api.snapcraft.io
    Ubuntu software repository
    Container ManagementTCP443NTAdocker.com

    *.docker.com (private container registry)

    docker.io (private container registry)

    *.docker.io (private container registry)
    Private container registry
    Amazon Cloud dependenciesTCP443NTA*.cloudfront.netAmazon CDN used by NTA API

    What’s Next?

    Now you have an understanding of the recommended specifications and communication requirements we recommend you proceed to Samurai NTA Deployment