Sangfor HCI and aSV provide a unified infrastructure combining compute, storage, networking, and built-in security to simplify deployment, operations, and services.
Sangfor Cyber Command (CC) supports calling the HCI platform and obtains the traffic in the HCI cluster in real-time through mirroring, conducts traffic monitoring and analysis, and realizes risk prediction and prevention before failure, and timely detection and processing of failure. Supports functions such as automatic isolation of infected virtual machines, automatic storage snapshots for risky virtual machines, and automatic shutdown/suspension of risky virtual machines.
Precautions
After HCI is connected to CC, the virtual machine list can be automatically synchronized to the CC. You do not need to manually enter the IP.
The storage snapshot scenario requires that the HCI cluster supports the aSAN storage snapshot function. Otherwise, the CC does not support using the correlated snapshotting function.
CC takes snapshots of the virtual machines in the consistent snapshot group and snapshots of the entire consistent snapshot group.
Support connecting NFV devices on HCI to CC.
Prerequisites
This function requires CC and HCI to activate corresponding authorization at the same time.
Steps
The partner service is not enabled by default in HCI. It is necessary to ensure that the HCI has authorization. Enter the System > Correlated Security Service interface, and click Enable Correlated Security Service to enable the function.
Click Add New Account to add an account that can call the corresponding API interface.
Enter information such as the Account Name, Password, Correlated Platform, and Permissions: Third-party security service, PAAS, CC, etc. Select Cyber Command here, and the correlated service modules of CC will be automatically identified below. Multiple modules can be selected by yourself.
Add HCI in the Authentication Account position, write the service account created on the HCI above, and wait for the assets to be synchronized.
Create a linkage policy in the CC platform's Response Toolbox > Linkage Response.