Deploy Sophos NDR on Nutanix AHV
On Nutanix AHV, the NDR appliance is not imported from a single ready-made VM file. Sophos Fusion (formerly Sophos Central) generates a package containing two QCOW2 disks, a seed ISO, and the ndr-sensor.sh script. The script creates the VM and four interfaces for management, Syslog, ERSPAN, and local SPAN. Deployment is complete only when the appliance appears as Connected in Sophos Fusion and packets are visible on the selected capture path.
Scope: The Prism and
aclisteps described here apply to Nutanix AOS/AHV 6.8. Menus and behavior may differ in an earlier or later version. In particular, the CPU passthrough step below is intended for version 6.8 and later. For a different version, first check the syntax supported by that version rather than using the commands unchanged.
Before deployment
Plan the following before creating the NDR configuration:
- The Sophos Fusion tenant has the Sophos Network Detection and Response integration license pack, and the administrator account used is permitted to create integrations and appliances.
- The Nutanix administrators have approved a maintenance window, Prism access over port
9440, and SSH/SCP access asadminto a Controller VM (CVM). - The VM meets the cross-platform minimum requirement of
160 GBsystem storage. In addition, sufficient free storage is reserved in the Prism Image Service and the AHV cluster for both uploaded QCOW2 images, the seed ISO, and the VM disks created from them; the sizes of the package actually generated determine the upload and provisioning requirements. - The appliance receives DNS and gateway settings from the management network. Before deployment, the current outbound ports and domains listed in the Sophos Appliance requirements are allowed on the firewall; use the appropriate list there for firewalls with or without wildcard support instead of copying a static list from this runbook. If DHCP is used, the assigned address is reserved. For manual configuration, have the IP address, subnet mask, gateway, and DNS server details ready.
- Suitable virtual AHV subnets have been selected for management, Syslog, and tunneled ERSPAN reception. A single subnet may be used for all three paths; separation is advisable if required by security zones, routing, or areas of responsibility.
- The source of the mirrored traffic has been defined: local Nutanix SPAN, ERSPAN from another network segment, or both. Sources, direction, and expected data rate are documented so that an entire host or an overly broad uplink is not mirrored accidentally.
- CPU and RAM capacity on the AHV cluster has been checked. The installation script suggests
4CPU cores and16 GBRAM. If both SPAN interfaces are used, the VM requires8CPU cores. For higher traffic volumes, final sizing must follow the approved NDR sizing guidance; the script defaults are not evidence of sufficient capacity. - Before starting, the Nutanix team uses the CPU model and host inventory to confirm that the target host provides the CPU flags required by NDR:
pdpe1gbfor Packet Capture andavx2for Machine Learning functions. If a flag is missing or cannot be verified conclusively, do not start the VM; select a suitable target host instead. For AOS/AHV 6.8 and later, also verifycpu-passthroughbefore starting the VM.
Also record unique names, for example ndr-ahv-prod-01, ndr-ahv-prod-01-root, ndr-ahv-prod-01-data, and ndr-ahv-prod-01-seed. This makes it possible to associate the VM, images, and Sophos Fusion configuration unambiguously if a problem occurs.
Create the NDR configuration and appliance package
- In Sophos Fusion, open Threat Analysis Center > Integrations > Marketplace and select Sophos Network Detection and Response (NDR).
- Under Data Ingest (Security Alerts), click Add Configuration.
- In Step 1, enter a unique name and a description.
- In Step 2, select Create new appliance and set Virtual platform to Nutanix.
- Configure management access for the appliance:
- With DHCP, the address must be reserved in the DHCP system.
- With Manual, enter values from your own addressing plan. An example would be
10.0.252.5, mask255.255.255.0, gateway10.0.252.1, and internal DNS servers. These values are placeholders and must not be copied without verification.
- In Step 3, provide at least a name for the Exclusion List. Create Domain or Protocol Exclusions only for exceptions that are already justified. In particular, do not exclude an entire top-level protocol such as
TCPorUDPmerely to reduce data volume. - Click Save. Immediately copy the displayed Appliance Credentials to the approved password vault. They are displayed only once.
- Confirm with OK and wait for the Nutanix installer to be generated. If the configuration is missing under Configured NDR integrations, refresh the view.
- In the Actions column, open the Download image action, download the ZIP file, and extract it to a protected working directory.
The extracted package must contain at least these four related files:
ndr-root.qcow2: System diskndr-data.qcow2: Data diskseed.iso: Authorization and bootstrap datandr-sensor.sh: Creates the Nutanix VM
Treat the ZIP file, seed ISO, and credentials as secrets. Do not mix files from different Sophos Fusion configurations, and do not rename the files themselves. After extraction, check the names and file sizes for an obviously incomplete download; use authoritative checksums only if Sophos provides them for this exact package.
Upload the QCOW2 disks and seed ISO to Prism
Sign in to the Nutanix web console on port 9440 and open Home > Settings > Image Configuration. Upload the files one at a time and wait for each upload to finish completely:
- For
ndr-root.qcow2: Upload Image, unique name containingroot, Image type: DISK, Upload a file, select the file, Save. - For
ndr-data.qcow2: follow the same process with a unique name containingdataand Image type: DISK. - For
seed.iso: unique name containingseedorISOand Image type: ISO.
Before the next step, all three entries must be visible under Image Configuration with no upload in progress. Their roles are not interchangeable: the seed file is not a data disk, and the two QCOW2 files must not be swapped at the script prompts.
Create the VM on the Nutanix CVM
Run the following commands on an approved administrator workstation. Replace <CVM-IP> with the management address of the Nutanix Controller VM, not the future address of the NDR appliance.
scp ndr-sensor.sh admin@<CVM-IP>:~/
ssh admin@<CVM-IP>
Older Nutanix versions may require legacy SCP mode for the SCP transfer:
scp -O ndr-sensor.sh admin@<CVM-IP>:~/
scp only copies the script to the CVM administrator’s home directory; ssh opens the session. Then start the installation script on the CVM:
bash ndr-sensor.sh
Change affecting AHV: The script creates a VM, disks, and network interfaces. Record the selected responses and the VM UUID shown in the output. If an incorrect image or subnet is selected, stop instead of starting a second run with the same name.
Answer the prompts in this order:
- VM name; the script default is
ndr-sensor, but a unique site-specific name is better for production use. - CPU cores; default
4, or8when both SPAN interfaces are used. - Memory in GB; default
16. - Name of the uploaded seed ISO.
- Name of the root QCOW2 image.
- Name of the data QCOW2 image.
- Number of the virtual subnet for management.
- Number of the virtual subnet for Syslog.
- Number of the virtual subnet for tunneled ERSPAN traffic.
At the image prompts, L displays the available images. Compare the full name, not just a shared prefix. After successful creation, Created vm <name> UUID <UUID> appears.
Understand the four interfaces correctly
The script creates four functionally separate NICs:
- Management: Sophos Fusion connection, administration, and outbound internet access.
- Syslog: Receives appliance-based log integrations; this NIC is not automatically a packet source for NDR.
- ERSPAN: Receives encapsulated, routed mirrored traffic.
- SPAN: Local destination for Nutanix Traffic Mirroring. The script automatically creates this NIC as
type=kSpanDestinationNic; no regular virtual subnet is selected for it.
At the end, the script displays acli examples tailored to the environment and the MAC address of the SPAN destination NIC. Save this output with the change record. It contains variants for all VMs on a host and for a single VM NIC. Do not enable a session yet: first verify CPU passthrough, initial startup, and the Sophos Fusion connection.
Verify CPU passthrough on AOS/AHV 6.8 and later
This step is performed on the CVM and is required for Nutanix 6.8 and later. First identify the VM and check its current state:
acli vm.list
acli vm.get <VM-UUID>
Both commands are read-only. Replace <VM-UUID> with the UUID recorded during creation. If cpu-passthrough is already True, no change is necessary. If the value is False, enable it before the first start:
acli vm.update <VM-UUID> cpu-passthrough=true
acli vm.get <VM-UUID>
The first command changes the VM configuration; the second is the post-check. Continue only if cpu-passthrough: True is displayed for the correct VM. Do not perform this step preemptively on versions earlier than 6.8.
Initial startup and registration
- In Prism, open Settings > VM.
- Right-click the new VM and select Power on.
- Open the console with Launch Console and monitor the bootstrap process. The initial startup can take up to ten minutes. Do not interrupt it because of brief periods with no visible output.
- In Sophos Fusion, open Threat Analysis Center > Integrations > Configured > Integration Appliances.
- Wait until this specific appliance shows the status Connected.
The seed ISO authorizes the appliance created earlier; a second manual registration is not intended. Connected confirms the management path, DNS/internet path, and assignment to Sophos Fusion. The status does not yet prove that mirrored traffic is being received.
For subsequent access, use the zadmin user with the appliance password saved during creation. Open Appliance Manager in Sophos Fusion from the appliance’s three-dot menu and Open Appliance Manager. Accept a self-signed certificate warning only after verifying the destination address and appliance assignment.
Enable SPAN or ERSPAN in a controlled manner
Local Nutanix SPAN
Use the acli examples generated by the script; they contain the actual MAC address of the SPAN destination NIC. For host-wide mirroring, replace the placeholder with the correct host UUID. The following read-only command on the CVM lists the UUIDs:
acli host.list
The identifier used in the example refers to the monitored source interface. For example, br0-up can be a bridge comprising two physical interfaces, while eth0 would be a single interface. Use the identifier only after verifying it on the target host.
Whenever possible, start with a single, clearly named test VM NIC. A host-wide session multiplies both load and the privacy scope and must be approved only after a successful small-scale test. Therefore, do not copy generic mirror syntax from this article: session parameters, destination MAC, host UUID, and source identifier must come from the actual script output and the verified AHV environment.
ERSPAN from outside the AHV environment
Use ERSPAN when the source cannot be reached through local Nutanix Traffic Mirroring. Configure ERSPAN reception in Appliance Manager and configure the same parameters on the sending network device. After the settings are applied, the appliance restarts and signs you out of the Appliance Manager session; monitor the restart in Prism and wait for Connected again.
This runbook covers only deployment on the Nutanix side and initial traffic reception. Site-wide selection of mirror sources, directions, filters, and oversubscription belongs in a separate traffic-mirroring design. Do not enable broad local SPAN and ERSPAN sources at the same time before measuring each source individually.
Validate packet reception and status
Check in this order so that management and capture errors are not conflated:
- Prism: The VM is powered on; the expected disks and four NIC roles are present.
- Sophos Fusion: Under Integration Appliances, the appliance is Connected.
- Appliance Manager: The appliance is reachable and shows incoming traffic on the expected capture interface.
- Sensor log: Sign in over SSH to the management IP of the NDR appliance as
zadminand run the read-only follow command:
sudo kubectl logs -f deploy/dragonfly
Enter the zadmin password for sudo. Then generate normal test traffic only on the approved test source and verify that packets are logged for the expected SPAN interface. Stop follow mode with Ctrl+C, then end the SSH session with exit.
A log entry containing packets proves reception at the sensor, but not the complete detection chain. For acceptance, record the source, direction, time window, observed interface, and Sophos Fusion status. If packet reception cannot be proven, deployment is not complete even if Connected is green.
Troubleshooting by symptom
The VM was not created correctly
Check the final script output, the VM UUID, and the three selected image names. Common causes are an image upload that is still in progress, swapped root/data images, or an incorrect subnet. Do not blindly run the script again: first check in Prism which VM, disks, and NICs have already been created. Remove partial objects only within the approved change and only after their UUIDs have been associated unambiguously with the failed run.
Initial startup hangs or Sophos Fusion remains on Waiting for deployment
Allow up to ten minutes for the initial startup and check the Prism console. Then check the management IP or DHCP reservation, gateway, DNS, and outbound internet path. Also confirm that the seed ISO used comes from exactly the same Sophos Fusion configuration as the QCOW2 files. On AOS/AHV 6.8 or later, acli vm.get <VM-UUID> must show cpu-passthrough: True.
The appliance is Connected but receives no packets
Connected narrows the issue to the capture path. First check whether the mirror session is active and points to the MAC address of the SPAN destination NIC created by the script. Then compare the host UUID, source VM NIC or physical identifier, and the intended direction. For ERSPAN, the sender and Appliance Manager must use the same tunnel parameters, and the routed path to the ERSPAN NIC must be reachable. Test local SPAN and ERSPAN sources separately.
Packets appear on the wrong interface or on only one interface
Compare the four NIC roles with the script output. A regular subnet on the management, Syslog, or ERSPAN interface does not replace the special kSpanDestinationNic. 8 CPU cores are required only if both SPAN interfaces or SPAN ports are used; a local SPAN path together with ERSPAN does not automatically meet this condition. Do not change the NIC assignment, mirror source, and CPU count at the same time; change only one hypothesis at a time and repeat the same test traffic.
scp does not work with an older Nutanix version
Repeat only the transfer with scp -O ... if the remote endpoint does not support the modern SCP/SFTP process. -O forces the legacy SCP protocol and is not a general fix for incorrect credentials, blocked SSH access, or an incorrect CVM address.
Limited return to the initial state
The following steps are limited, reversible change-back guidance only for the deployment newly introduced by this runbook. They are not a complete rollback or decommissioning procedure documented by Sophos or Nutanix. First disable the new traffic mirror source. This stops the additional copying load without changing production routing or the original traffic. To remove or disable the session, use the inverse operation appropriate for the Nutanix mirror configuration that was actually created; do not invent a session ID or delete someone else’s session. Then confirm in the sensor log that no new packets from this test source are arriving.
The new NDR VM can then be powered off. Initially retain the Sophos Fusion configuration, VM, QCOW2 images, and seed ISO until troubleshooting and the decision about restarting are complete. A restart uses the same related configuration; a new Sophos Fusion configuration requires a new, entirely related package.
The following boundaries are important:
ndr-sensor.shis not a transactional installer with documented automatic undo. After an interruption, inventory the existing VM, disk, and NIC objects individually before deleting anything or running the script again.- Powering off or deleting the VM does not automatically remove a Nutanix mirror session. Therefore, always disable and verify the capture path separately first.
- Deleting the Sophos Fusion integration, seed ISO, or stored credentials is not a short-term troubleshooting step. These actions make restarting more difficult and are performed only after documented decommissioning approval.
- A snapshot is not a substitute for an approved rollback: the Sophos Fusion assignment, seed authorization, mirror session, and external ERSPAN configuration are outside a VM snapshot.
- Do not leave a host-wide mirror session in place as a permanent interim solution. If the small-scale test fails, remove it before adding further sources or directions.
This keeps the change-back limited to the newly introduced NDR objects. It does not change production bridges, uplinks, VLANs, routing, or firewall rules. Complete decommissioning, including the final deletion order and side effects, requires a separately validated and approved procedure.