Install AutoDiscovery sensors
By default, each AutoDiscovery server installation comes pre-installed with a single sensor, used to capture data from across your network.
You may need additional sensors if you want to use direct traffic collection, full traffic capture, or if you want to separate your AutoDiscovery server and sensor machines. For more details, see Traffic collection options.
This topic describes how to install additional sensors as needed, either directly on a Windows or Linux machine, or as a VMWare OVF.
Sensor installation options
The following table describes the supported configurations for installing additional sensors, and the high-level steps required for each configuration:
ESX with port mirroring |
Do the following:
|
Physical server with port mirroring |
Do the following:
|
Local mode with direct capture |
Install a sensor on any server from which you want to capture traffic. |
For more details, see Install additional AutoDiscovery sensors.
Note: To configure statistical traffic collection with NetFlow/SFlow, we recommend using the sensor installed together with the AutoDiscovery server.
For more details, see Install AutoDiscovery.
AutoDiscovery sensor system requirements
Additional AutoDiscovery sensors must be installed on a Linux or Windows server with the following minimum specifications:
CPU |
4-core CPU, if expected traffic load has a maximum of 2 Gbps 8-core CPU if expected traffic load is more than 2 Gbps |
Memory | 8 GB |
Disk space | 1 GB free disk space |
Network adapters |
At least 2 network adapters:
|
Software (Windows only) |
When installing a Windows sensor, make sure you have the following software installed on the AutoDiscovery sensor machine:
|
When deploying on a virtual machine, network cards must be physically connected to the switch / router.
Install additional AutoDiscovery sensors
This procedure describes how to install additional AutoDiscovery sensors.
Do the following:
-
Verify that your AutoDiscovery sensor machine complies with the system requirements. For details, see AutoDiscovery sensor system requirements.
Note: If you are installing additional sensors, you must do so using different machines than the ones you are using for the AutoDiscovery server and the ASMS installation. Each additional sensor must be installed on its own machine.
- On the AlgoSec portal, navigate to Downloads > Software > AlgoSec AutoDiscovery.
-
Do one of the following:
-
Deploy the downloaded file on your sensor machine, depending on your OS type. For example:
AutoDiscovery sensor system requirements
This section describes system requirements for AutoDiscovery sensors installed in addition to the one provided by the AutoDiscovery installation. Additional sensors are most often configured for full traffic capture.
Note: The number of sensors to install and where to install them depends on your network's load and topology.
For example, if you have packet brokers or standalone sniffers already collecting traffic on your network, you can send the traffic they collect to a single sensor. This avoids the need to thoroughly cover your network with sensors.
Configure one of the following: