Skip to content
Avanet

Install Sophos NDR on certified hardware

Sophos NDR can be installed on Dell, Intel NUC 13, and OnLogic systems tested and certified by Sophos. This does not mean that every x86 computer from these manufacturers is supported. Before making the change, compare the manufacturer, model, and configuration with the current certified hardware specifications.

The procedures share the same starting point: create a hardware appliance in Sophos Fusion and download its ISO image. After that, the installation procedures differ significantly:

  • Dell: Installation through iDRAC and a virtual ISO; the installer assigns Management, Syslog, span, or unused.
  • NUC: Installation from USB in the text-based installer; initially, only Management is configured and all other interfaces remain disabled. SPAN is configured after installation in Appliance Manager.
  • OnLogic: Installation from USB; the graphical installer offers Management, span, and unused, but no Syslog role.

Before the maintenance window

The installation formats the target system’s internal disks. Writing the ISO also completely erases the USB drive used for a NUC or OnLogic system. Therefore, schedule a maintenance window during which NDR capture can be unavailable, and confirm the following in advance:

  1. The exact device and its configuration are listed in the current Sophos specification. A separate guide explains how to select and size the NDR platform. An older NUC, a similarly configured Dell server, or a different OnLogic computer is not automatically supported.
  2. A verified, independent backup of the target system’s existing contents and of the installation USB is available if the data is still required. The NDR ISO is not a backup or migration tool.
  3. A free static IP address in CIDR notation, a default gateway, and DNS servers have been defined for Management. DHCP is possible but impractical for an appliance because the address can change after a restart.
  4. The management interface can reach all destinations that apply to the appliance in the current Sophos Appliance requirements: depending on the destination, TCP 443, TCP 22, and UDP 123. Check the current wildcard or non-wildcard allowlist provided there; it covers more than Sophos Fusion, including Sophos, AWS/S3, repository, and NTP destinations. Do not copy this long, region-dependent list into permanent firewall-rule documentation. If a proxy is required, have its URL, port, and credentials, if applicable, ready.
  5. The mirror port, cables, and switch configuration are planned. A SPAN port normally does not receive a management IP address. Configure mirroring separately and validate it in full by following Configure and validate traffic mirroring for Sophos NDR.
  6. A monitor, keyboard, and cabling are available. Dell systems also require iDRAC access and an iDRAC address.
  7. An authorised Sophos Fusion (formerly Sophos Central) account is available. Do not install an additional Sophos or antimalware agent on the appliance; Sophos manages operating system and security updates.

Before starting, document the model and, if applicable, serial number, current disk layout, switch ports used, planned interface roles, and IP settings. If port labels are ambiguous, photograph the cabling. This makes it possible to verify after installation that the correct link, rather than merely any link, is active.

Destructive go/no-go checkpoint

Do not begin writing the USB drive or performing any RAID or installation steps until the person responsible for the change has positively confirmed every item below:

  • exact, currently certified model and certified configuration;
  • unambiguously identified target USB disk and internal target media or array;
  • for Dell, the controller, member disks, and the number and purpose of existing virtual disks;
  • verified independent backup of all data that is still required;
  • working local or iDRAC console access;
  • documented mapping of physical ports to Management, Capture/SPAN, and Syslog, if applicable;
  • named person responsible for recovery, with available manufacturer recovery media and a verified recovery plan.

If any confirmation is missing or the detected hardware differs from the documentation, the decision is No-Go: do not perform any write operation.

Prepare the hardware appliance and ISO

  1. In Sophos Fusion, go to Threat Analysis Center > Integrations.
  2. Open Sophos Network Detection and Response (NDR).
  3. Under Data Ingest (Security Alerts), click Add Configuration.
  4. In Step 1, enter a unique name and description.
  5. In Step 2, click Create new appliance. Give the appliance a unique name and description as well, and select Hardware for Virtual platform.
  6. In Step 3, enter at least one name under Exclusion list name. You can add domain or protocol exclusions now or later. Do not broadly exclude a master protocol such as TCP or UDP; such an exclusion removes a large volume of traffic from inspection and is appropriate only for a justified, documented exception.
  7. Click Save. Store the displayed Sophos Appliance Manager credentials in a password manager. They are required for operations and troubleshooting.
  8. Verify that the new configuration appears under Configured NDR integrations.
  9. In the Actions column, open the three-dot menu and select Download image. Wait until the image is ready, then download the ISO to the maintenance directory.

The configuration’s presence proves only that it was saved in Fusion. It does not prove that the hardware is installed, can reach Fusion, or is receiving mirrored traffic.

Create USB media for NUC and OnLogic

Dell uses the ISO as virtual media in iDRAC. For NUC and OnLogic, it must be written to a USB drive as a bootable image. Sophos specifies balenaEtcher for this purpose; Rufus can alternatively be used for OnLogic.

  1. Insert an expendable USB drive and verify its capacity and device name.
  2. In balenaEtcher, select Flash from file, then choose the ISO downloaded from Fusion. Confirm a warning about a missing partition table with Continue.
  3. Click Select target and select only the intended USB drive.
  4. Check the target again. Flash erases all data on this disk.
  5. Click Select 1, then Flash. Confirm the operating system prompt and wait for the write operation to complete.

Install Dell

This branch follows only the current Sophos procedure Sophos NDR on Dell hardware and applies only when the exact Dell model and configuration are also approved in the current certified hardware specifications. The procedure page alone does not constitute model approval. iDRAC management, the optional RAID 5 preparation for the dual-socket R660, and the additional Syslog role are not part of the NUC or OnLogic procedures.

Prepare cabling and iDRAC

  1. Install the system using the appropriate rails and connect both power supplies.
  2. Connect a VGA monitor and USB keyboard locally.
  3. Connect the management uplink to port 1, the Syslog uplink to port 2, the separate hardware management connection to iDRAC, and the mirror links to the intended SPAN ports.
  4. Start the server and press F2 during startup to open System Setup.
  5. Open iDRAC settings > Network and configure the documented iDRAC address.
  6. Open iDRAC settings > User Configuration. The default user is root. At a minimum, change the default password, confirm with Finish, and save the change with Yes.
  7. Exit System Setup and open iDRAC in a browser at the configured address. Do not disconnect the monitor and keyboard until you can sign in successfully.

Where possible, use HTTPS for iDRAC in accordance with your management policy. The iDRAC address is separate from the NDR management address configured later.

Check RAID only on a dual-socket Dell R660

This step is intended exclusively for the certified Dell R660 2 socket system with three drives in the front bay.

  1. In iDRAC, open Storage > Summary.
  2. If Summary of Disks already shows two virtual disks, change nothing and continue with the ISO.
  3. Stop before the first storage write operation: Reconfirm the R660 2 socket system model, PERC controller, the three expected front drives, existing virtual disks, the backup, and the person responsible for recovery. Any discrepancy means No-Go; do not create an array based on assumptions.
  4. Only if the data partition is absent after this positive confirmation, open Virtual Disks > Create Virtual Disk > Basic Configuration.
  5. Select the PERC controller and choose RAID 5 under Layout.
  6. Click Add to Pending, then Apply Now, and check the job under Job Queue or Tasks > Pending Operations.
  7. Continue only when the queue is empty and Summary of Disks shows two virtual disks.

Stop if the number or purpose of the existing disks differs from this description. Do not recreate an existing array based on assumptions; an incorrect storage action can destroy data.

Mount the ISO and install

  1. On the iDRAC dashboard, open Virtual Console. Allow pop-ups for iDRAC if the window does not open.

  2. Select Virtual Media > Connect Virtual Media.

  3. Under Map CD/DVD, click Choose File, select the NDR ISO, and click Map Device.

  4. Select Boot > Virtual CD/DVD/ISO and confirm with Yes.

  5. Select Power > Reset System (warm boot) and confirm again. Wait for the installer to appear, then click Next.

  6. Under Interface Info, verify the link, speed, and detected interfaces. After changing the cabling, use Refresh interfaces to update the information.

  7. Under Interface Roles, assign roles based on the documented physical ports:

    • Management for the connection to Fusion,
    • Syslog for Syslog messages from local third-party integrations,
    • span for mirrored network traffic,
    • unused for ports that are not used.

    Management and Syslog are automatically enabled and cannot be disabled. unused remains disabled. Assigned SPAN ports can be enabled or disabled.

  8. Under Interface Addresses, disable DHCP for Management, then enter the IP address with subnet in CIDR notation, default gateway, and DNS servers. For Syslog, enter only the IP address and subnet.

  9. Under Net Proxy, enable Use Proxy if required, then enter the URL, port, username, and password.

  10. On Configuration Review, check every role and address. Click Check Settings. Continue with Apply only if the check succeeds.

  11. Click Install. The next dialog warns that the disks will be formatted and that you cannot return to the previous pages. Check the device, backup, and maintenance approval one final time, and only then click Continue.

  12. Wait for Installation Complete, click Continue, then Reboot, and confirm with Yes. Disconnect or unmap the installation media when prompted, then press Enter.

Install NUC

This branch follows only the current Sophos procedure Sophos NDR on NUC hardware. It applies to an Intel NUC 13 system only if its exact model and configuration are approved in the current certified hardware specifications; neither the generation nor this guide alone establishes support. Unlike Dell and OnLogic, capture interfaces are not yet assigned SPAN roles during this installation.

Prepare the hardware and BIOS

  1. Connect power, an HDMI monitor, and a USB keyboard. A VGA monitor requires a USB-C-to-VGA adapter, which is not included.
  2. Connect the management network to the upper network port and the capture link to the lower network port.
  3. Turn on the NUC and immediately press F2 repeatedly.
  4. Open Power, Performance and Cooling > Secondary Power Settings.
  5. Change After Power Failure from Power Off to Last State.
  6. Disable PCIE ASPM Support.
  7. Save with F10, select OK, and exit the BIOS.

Install from the USB drive

  1. Insert the prepared installation USB and start the NUC. If the device is already running, you can restart it with Ctrl+Alt+Delete.
  2. In the boot menu, select Install Sophos NDR – NUC/OnLogic Models and press Enter.
  3. Wait for Network connections. Highlight the management interface and open Edit IPv4.
  4. Set IPv4 method to Manual and enter the Subnet in CIDR notation, Address, Gateway, and Name servers. Search domains is optional. Save with Save.
  5. Open each remaining interface in turn, select Edit IPv4 > Disabled, and save. The appliance does not use the wlo1 wireless interface, which must also remain disabled.
  6. Verify again that only the connected upper management port has an address. Configure the capture interface in the SPAN settings in Appliance Manager only after the first startup.
  7. Select Continue. This confirms partitioning and installation and overwrites the internal disks.
  8. Wait for both phases to finish: Install complete! first appears after the Ubuntu installation; the process is complete only after the NDR installation has also finished and the progress indicator has stopped rotating.
  9. Select Reboot Now. Remove the USB drive when prompted and press Enter.

Install OnLogic

This branch follows only the current Sophos procedure Sophos NDR on OnLogic hardware. It applies only to the exact OnLogic model and configuration approved in the current certified hardware specifications; the manufacturer’s product family or this guide alone is insufficient. The installer offers Management, span, and unused. A Syslog role is not available in this installation procedure.

Prepare the hardware and boot settings

  1. Connect power, an HDMI monitor, and a USB keyboard. VGA requires a USB-C-to-VGA adapter, which is not included.
  2. Connect Management to the upper network port and Capture to the lower network port.
  3. Insert the prepared installation USB, start the device, and press F2 repeatedly.
  4. In the BIOS, open Boot. If multiple options are available, select the installation USB for Boot Option #1.
  5. Open Exit, select Save Changes and Exit, and confirm.
  6. Select Run live NDR ISO installer and press Enter. Wait for the installer, then click Next.

Assign roles and install

  1. Under Interface Info, check the detected interfaces, links, and speeds. Refresh Interfaces updates the view after a cabling change.

  2. Under Interface Roles, assign:

    • Management for Fusion and administration,
    • span for the mirror link,
    • unused for ports that are not used.

    Management is automatically enabled and unused is automatically disabled. SPAN ports can be enabled or disabled. Do not assign a presumed Syslog role here; it is not one of the OnLogic options in this installer.

  3. Under Interface Addresses, disable DHCP for Management. Enter the IP address and subnet in CIDR notation, default gateway, and DNS servers.

  4. Under Net Proxy, enable Use Proxy if required, then enter the URL, port, and credentials.

  5. On Configuration Review, check the roles and addresses. Click Check Settings and, if the check succeeds, Apply.

  6. Click Install. From this dialog onward, the disks are formatted and you cannot return to the previous pages. Click Continue only after the final device and backup check.

  7. Wait for Installation Complete, click Reboot, and confirm with Yes. Remove the USB drive when prompted and press Enter.

Accept the installation: focused deployment smoke test

The acceptance checks in this section are limited to an installation smoke test. They confirm neither complete mirroring nor a functional detection. Check only the following here:

  1. Local boot: After the installation media is removed, the system boots from the internal disk and does not return to the installer.
  2. Management: The documented management IP is reachable from the intended management network; the gateway, DNS, and proxy match the approved plan.
  3. Interface roles and link: Physical port labels, detected links, and roles match the advance documentation. On Dell, Syslog must not be assigned to a SPAN port; OnLogic has no Syslog role; on the NUC, wlo1 remains disabled.
  4. Appliance Manager: You can sign in using the credentials saved when the appliance was created. On a NUC, configure the intended capture port in the SPAN settings now.
  5. Fusion: The correct NDR configuration initialises. Red means the integration is not working, yellow indicates operation with errors, and green indicates a healthy state with no visible errors. A saved entry alone is not proof of installation or traffic.
  6. Capture activity: Appliance Manager shows activity on the intended capture port. This is only a smoke test, not proof of complete mirror coverage.

Perform the complete data-path and coverage acceptance by following Configure and validate traffic mirroring for Sophos NDR. Only then perform a harmless end-to-end check using Generate and verify a safe Sophos NDR test detection. Record the model, ISO creation time, interface mapping, IP configuration, installation result, and time of verification in the change log. Do not store passwords there.

Isolate installation errors methodically

Device does not boot from the installation media

  • Dell: In Virtual Media, check whether the ISO is still mapped as a CD/DVD. Then set Boot > Virtual CD/DVD/ISO again before performing Reset System (warm boot). A blocked pop-up can prevent access to Virtual Console.
  • NUC: Verify that Install Sophos NDR – NUC/OnLogic Models was actually selected and that the USB write operation completed successfully.
  • OnLogic: Check Boot Option #1 in the BIOS and start Run live NDR ISO installer. If the media remains unreadable, rewrite the USB drive or use another verified drive.

Check Settings fails

This check concerns the management path, not the quality of mirrored traffic. Check the management port’s link and VLAN, the CIDR prefix, gateway, DNS, and proxy. Then compare the outbound rules from this interface with the current wildcard or non-wildcard list in the Sophos Appliance requirements. Do not change the management and capture cabling at the same time; otherwise, the cause will no longer be clear.

Status remains unhealthy or capture activity is missing

As an installation smoke test, check only the documented physical mapping and the link:

  • Dell: Management on port 1, optional Syslog on port 2, and mirror cables on the intended SPAN ports.
  • NUC: Management on the upper port and Capture on the lower port; after installation, the capture port is configured as SPAN in Appliance Manager.
  • OnLogic: Management on the upper port and Capture on the lower port; in the installer, the capture port has the span role.

Reinstallation does not correct incorrect switch mirroring. Check the configuration and design, mirror source, and complete coverage by following Configure and validate traffic mirroring for Sophos NDR. If the sensor remains red, yellow, or without data, continue isolating the problem with “Diagnose the NDR Integration Appliance and Sensor”, collect the diagnostic data, and escalate to support if necessary. Do not perform undocumented shell repairs.

Limited local action after installation failures

This section is not a complete recovery, replacement, deletion, or decommissioning procedure published by Sophos. The Sophos installation guides do not describe such a procedure. The following points merely limit the local actions to take after a failed installation.

Until immediately before Install or Continue, you can exit the installer and correct the plan. After confirming partitioning, there is no in-place rollback: the internal disks are formatted, and the Dell installer does not allow you to return to previous pages.

After that, only separately planned approaches are permitted:

  • Repeat the NDR installation: Correct the cause and repeat the installation procedure described above for this exact certified model. The Appliance Manager credentials remain useful for access and diagnostics; this does not imply any recovery or assignment sequence.
  • Restore the previous local state according to your own recovery plan: The designated person responsible rebuilds the device using the manufacturer media verified before the change and the independent backup. The Sophos NDR ISO does not restore a previous operating system, partitions, or local data.
  • Unclear disk, RAID, or hardware state: Do not perform any further write operations. If a Dell array is unexpected, the target drive is ambiguous, or the certified model differs, consult the hardware supplier and Sophos Support before starting another attempt.

Deleting the NDR configuration in Fusion is not a storage rollback. Complete replacement, deletion from Fusion, retention, secure erasure, and decommissioning are outside the scope of this article. Do not perform these steps based on the installation guide or your own assumptions; follow only a separately approved and practically tested procedure for these tasks.