Sophos NDR: Choose a platform and size the sensor correctly
Sophos NDR can run as a virtual appliance on VMware ESXi, Microsoft Hyper-V, AWS, or Nutanix, or on certified hardware from Dell, NUC, and OnLogic. Choose the platform before deployment: Size virtual and cloud sensors based on bandwidth, packets, and flows. For hardware, use only certified models and their corresponding capacity tiers.
Quick decision: For a dedicated virtual NDR sensor handling up to 500 Mbps, 70'000 packets per second, and 1'200 flows per second, the standard configuration is sufficient. For up to 1 Gbps, 300'000 packets per second, and 4'500 flows per second, use 8 vCPUs. If even one metric exceeds these limits, you need multiple virtual appliances distributed across the network. For higher bandwidth or a physical sensor, select certified hardware based on the actual measured sustained and peak load.
Licensing and planning fundamentals
The Sophos Network Detection and Response integration license pack is required for the integration. Sophos bases the NDR license on the organization’s total number of users and servers. Software for virtual appliances is included, and you can deploy as many NDR sensors as needed under the license. This is important when a larger environment must be distributed across multiple sensors because of the documented VM limits.
Collect the following values before choosing a platform:
- maximum and sustained bandwidth of the traffic that will actually be mirrored,
- packets per second and flows per second over the same period,
- capacity of the switch or mirror port from which the sensor receives traffic,
- planned number and placement of sensors,
- additional Log Collector integrations that will run on the same appliance,
- available CPU microarchitecture, CPU flags, memory, and storage,
- supported virtualization platform or exact certified hardware model.
An internet uplink alone is not a sufficient basis for sizing. The sensor processes the traffic mirrored to it. You must therefore collect the metrics at the intended mirror point and document both sustained and peak load.
Choose a platform
Virtual appliance or cloud
A virtual appliance is suitable if one of the tested platforms is already available and the load is within the VM limits or can be distributed effectively across multiple sensors. The following platforms are supported:
- VMware ESXi,
- Microsoft Hyper-V,
- Amazon Web Services (AWS),
- Nutanix.
For AWS, the Sophos NDR technical specification lists the c5n.2xlarge instance type. The relevant deployment guide describes the specific deployment mechanisms, network interfaces, and traffic-mirroring settings; these are not determined by the sizing decision.
VMware Cloud is not supported. ESXi and Hyper-V are also subject to the version and CPU prerequisites described below. However, the available requirements do not provide a common version matrix for AWS and Nutanix. Check their deployment prerequisites in the instructions for the relevant platform.
Certified hardware
Hardware is an option if you need a dedicated physical sensor or a certified capacity tier matches the measured load. Sophos supports NDR on hardware only when it runs on certified systems. Do not infer support for general-purpose x86 servers, similar model variants, or custom-built systems.
Systems from the following families are certified:
- Dell,
- NUC,
- OnLogic.
The manufacturer’s name alone is not sufficient. Before procurement, check the exact model against the current Certified hardware specifications for NDR. Installation, disk imaging, and manufacturer-specific steps come only after this model decision.
Size virtual and cloud sensors
Minimum resources
The following minimum resources apply to ESXi and Hyper-V:
- 4 CPUs,
- 16 GB RAM,
- 160 GB storage.
The VMware OVA is preconfigured with these minimum values for Sophos NDR and Log Collector integrations. AWS uses the instance type specified above. The requirements source used here does not specify separate minimum resources for Nutanix. However, minimum resources are not a capacity guarantee. Consider all three traffic metrics when choosing between the standard configuration, 8 vCPUs, and multiple appliances.
| Load class | Bandwidth | Packets/s | Flows/s | Sizing |
|---|---|---|---|---|
| Medium | up to 500 Mbps | up to 70'000 | up to 1'200 | Standard values; no VM adjustment required |
| High | up to 1 Gbps | up to 300'000 | up to 4'500 | Increase the VM to 8 vCPUs |
The limits collectively define a load class. A sensor handling 400 Mbps but 100'000 packets per second no longer falls entirely within Medium. If the values exceed the High limits, Sophos specifies multiple virtual appliances distributed across the network. The sources do not support using a larger single VM above this limit.
The technical specification limits a virtual NDR sensor to a maximum of 1 Gbps. This value does not override the lower packet and flow limits.
Check the CPU and hypervisor
The following microarchitecture and flag requirements apply to the system hosting the VM. On ESXi, Hyper-V, and other self-managed VM hosts, the CPU flags pdpe1gb and avx2 must be available to the VM. pdpe1gb is required for packet capture and avx2 for machine-learning functions. Additional vCPUs do not compensate for missing flags.
For AWS, check the supported instance type and AWS deployment requirements instead. Validate physical appliances using the exact certified model and its approved configuration. Therefore, no additional manual verification of these flags can be inferred for either AWS or certified hardware.
Sophos documents the following CPU microarchitectures:
- Intel: Skylake Generation 6, Kaby Lake Generation 7, Coffee Lake Generation 8, Coffee Lake Refresh and Cascade Lake Generation 9, Comet Lake Generation 10, Cannon Lake/Palm Cove Generation 10, Ice Lake/Sunny Cove Generation 10, Rocket Lake/Cypress Cove Generation 11, Alder Lake/Golden Cove Generation 12, and Raptor Lake/Raptor Cove Generation 13.
- AMD: Naples and Great Horned Owl with Zen 1, Rome with Zen 2, Milan with Zen 3, and Genoa with Zen 4.
You can also use more recent CPUs if both required flags are available. Sophos states that CPUs introduced since the first quarter of 2015 should work. Approval nevertheless depends on verifying both flags on the intended VM.
The following minimum versions and limitations apply to the hypervisors:
- VMware ESXi: Version 6.7 Update 3 or later and VM Hardware Version 11 or later. In an EVC cluster, Skylake generation or later must be selected. VMware Cloud is not supported.
- Microsoft Hyper-V: Version 6.0.6001.18016 on Windows Server 2016 or later. Processor Compatibility Mode is not supported.
Shared appliance with Log Collectors
The VM values for Medium and High apply to an appliance running only Sophos NDR. If Log Collector integrations are hosted on the same appliance, start with the NDR size and then add their load. The following limits and effects are documented:
- All Log Collector integrations on a VM can accept a combined maximum of 8'000 events per second.
- A Log Collector integration requires approximately 400 MB RAM under high load.
- With 4 CPUs, NDR uses 2 CPUs; with 8 CPUs, it uses 3 CPUs. Other integrations can still use these CPUs and thereby affect the amount of traffic NDR can process.
- With 16 GB RAM, Log Collector integrations may use no more than 2 GB in total so that NDR retains sufficient memory.
- At the maximum event rate, a Log Collector on a VM with the standard 4 CPUs requires approximately the same computing capacity as NDR under medium load.
There is no single universally applicable size for mixed workloads. If the NDR limits or available resources are likely to be exceeded, plan additional appliances. Use multiple VMs when several Log Collector integrations exceed a combined total of 8'000 events per second. If a single integration exceeds this limit, first try to reduce the event volume through the source system’s syslog settings. The documented approximations do not justify arbitrary overprovisioning.
Size certified hardware
Sophos derives the hardware tier from the capacity of the mirroring switch and the sustained and peak load. The NDR sensor should have the same capacity as the switch supplying the mirrored traffic. The following recommendations are based on a typical organization with 20 percent power users, 60 percent typical users, and 20 percent light users. They also assume VoIP, some video streaming, large uploads and downloads, and application and web servers.
These names and performance tiers are intended only for preliminary selection. Procurement is approved only when the exact model and exact configuration are listed in the current Certified hardware specifications for NDR.
| Hardware recommendation in the Size Guide (not proof of certification) | Capacity tier | Users | Typical load |
|---|---|---|---|
| NUC/OnLogic class; check the exact model in the certification specification | 2.5 Gbps | up to 2'500 | approximately 0.7 Gbps |
| OnLogic MC510-55 | 2.5 Gbps | up to 2'500 | approximately 0.7 Gbps |
| Dell R350 | 4 Gbps | up to 5'000 | approximately 1.4 Gbps |
| Dell R360 | 4 Gbps | up to 5'000 | approximately 1.4 Gbps |
| Dell R450 | 10 Gbps | up to 12'500 | approximately 3.4 Gbps |
| Dell R650 | 20 Gbps | up to 25'000 | approximately 6.8 Gbps |
| Dell R660xs | 20 Gbps | up to 25'000 | approximately 6.8 Gbps |
| Dell R660 | 40 Gbps | up to 50'000 | approximately 13.7 Gbps |
For each row, Sophos documents a possible peak load of two to three times the typical load. This peak figure is not a substitute for measurement and must not be confused with the capacity tier. Heavy additional video and music streaming may require the next higher tier. Base the decision on measured sustained and peak load and the current certified limits. A smaller tier may be suitable when usage consists primarily of email, provided the measured sustained and peak load and the user count remain within its limits.
Bandwidth and user count alone are not sufficient for hardware selection. In the current certification specification, also check the maximum connections per second and the approved CPU, RAM, and, where applicable, socket configuration. This is particularly important for connection-intensive traffic. For example, the Sophos NDR data sheet dated December 19, 2024 lists the same nominal throughput for two R660 configurations, but different connection and resource limits:
The data sheet configurations as of 19.12.2024 are detailed below:
Dell R660, 2 sockets
- Max. throughput: 40 Gbps
- Max. connections/s: 120'000
- CPUs: 64
- RAM: 128 GB
Dell R660, 1 socket
- Max. throughput: 40 Gbps
- Max. connections/s: 80'000
- CPUs: 32
- RAM: 64 GB
Dell R650
- Max. throughput: 20 Gbps
- Max. connections/s: 40'000
- CPUs: 24
- RAM: 64 GB
Dell R450
- Max. throughput: 10 Gbps
- Max. connections/s: 20'000
- CPUs: 16
- RAM: 32 GB
Dell R350
- Max. throughput: 4 Gbps
- Max. connections/s: 8'000
- CPUs: 8
- RAM: 32 GB
Intel NUC 13th Gen
- Max. throughput: 2.5 Gbps
- Max. connections/s: 4'000
- CPUs: 12
- RAM: 32 GB
These dated values show all technical sizing dimensions and the importance of the exact configuration, but they are not a current procurement or certification matrix. For R360, R660xs, OnLogic, and every variant with a different configuration, do not infer missing values from similar models. Use only the current certified specification.
The hardware recommendations are a load model, not a guarantee for every traffic distribution. Streaming and large backup flows generate high volumes. Sophos NDR is optimized for streaming and “elephant flow” traffic, while many threats are detected in normal browsing and application traffic. Evaluate both the user profile and actual network metrics.
Network prerequisites before deployment
The appliance requires outbound connections for startup and updates. If the firewall supports wildcards, Sophos documents the following allowances:
| Destination | Ports | Protocol |
|---|---|---|
*.sophos.com | TCP 443, TCP 22 | HTTPS, SSH |
*.amazonaws.com | TCP 443 | HTTPS |
*.ntp.org | UDP 123 | NTP |
sophossecops.jfrog.io | TCP 443 | HTTPS |
yum.oracle.com | TCP 443 | HTTPS |
yum.oracle.com is optional. Without access, the appliance uses the Sophos JFrog repository mirror. If the firewall does not support wildcards, do not convert this short table into a list of assumed individual hosts. Instead, use the current region-specific list on the Sophos Appliance requirements page.
Do not install a Sophos Agent or any other anti-malware agent on the Integration Appliance. Do not install operating system or security updates manually either; Sophos manages these updates.
Validate and hand over the decision
Before deployment, a planning record should include at least the following information:
- Platform: ESXi, Hyper-V, AWS, Nutanix, or the exact certified hardware model.
- Measurement window: Date, time, and duration of the measurement, plus sustained and peak values for bandwidth, packets, and flows at the intended mirror point.
- Sizing: Selected load class or hardware tier and the tightest applicable limit; for hardware, also compare the measured maximum connections per second against the current certified limit.
- Resources by platform:
- ESXi, Hyper-V, and other self-managed VM hosts: vCPUs, RAM, storage, CPU model, and the
pdpe1gbandavx2flags visible to the VM. - AWS: Supported
c5n.2xlargeinstance type and the requirements of the AWS deployment instructions. - Certified hardware: Exact certified model and approved CPU, RAM, and socket configuration.
- ESXi, Hyper-V, and other self-managed VM hosts: vCPUs, RAM, storage, CPU model, and the
- Additional load: Names and expected events per second for all Log Collector integrations hosted on the same appliance.
- Network: Planned management and mirror connections, plus confirmed outbound port and domain allowances.
- Scaling: Number and placement of additional sensors if a virtual sensor would exceed the High limits.
The decision is sound when every measured value is within the selected tier and the platform-specific prerequisites are met. For self-managed VM hosts, these include the hypervisor, CPU, and the flags visible to the VM. For AWS, the supported instance type and deployment requirements apply. For hardware, the exact model, CPU/RAM/socket configuration, throughput, and maximum connections per second must match the current certification specification. On a shared appliance, also account for the event rate, RAM usage, and CPU impact of the Log Collectors.
Image creation, installation, registration, traffic mirroring, and the first detection are part of the subsequent deployment and validation steps. A later Connected status or green appliance status confirms only the state of the integration. It proves neither complete mirror coverage nor functional end-to-end detection.
Limits of the documented planning guidance
The sources do not provide a formula for calculating an arbitrary custom CPU and RAM size above the specified VM tiers based on user count, bandwidth, or events. Above the High limits, the documented decision is therefore multiple virtual appliances, not a speculatively larger single VM.
Likewise, the hardware tables do not replace the current certification specification. They provide preliminary-selection or dated data sheet values, but do not approve similarly named servers, different components, or custom x86 systems. If the exact hardware model and approved configuration are unavailable, or if reliable traffic and connection metrics have not been collected, the platform is not yet approved for deployment. The same applies to a self-managed VM host if the required CPU flags are not available to the VM.