Sangfor NDR supports calling the HCI platform interface to obtain real-time traffic in the HCI cluster via mirroring. It performs traffic monitoring and analysis to achieve pre-fault risk prediction and prevention, as well as timely fault detection and handling. Additionally, it supports functions such as automatic isolation of infected VMs, automatic storage snapshot creation for high-risk VMs, and automatic shutdown/suspension of high-risk VMs.
Precautions
After the HCI platform is connected to NDR, the VM list will be automatically synchronized to NDR without manual IP input.
The storage snapshot scenario requires the HCI cluster to support the aSAN storage snapshot function; otherwise, NDR cannot use the linked snapshot function.
When NDR creates snapshots for VMs in a consistent snapshot group, it will take snapshots of the entire consistent snapshot group.
NFV devices on the HCI platform can be connected to NDR.
Versions 6.3.0 and later support NDR linkage. Required NDR version: SIS3.0.67.0.
Prerequisites
This function requires both NDR and the HCI platform to activate the corresponding licenses.
Operation Steps:
The partner service is not enabled by default on the HCI platform. It is required to ensure the HCI platform has a valid license. AccessSystem > Correlated Security Service, then clickEnable Correlated Security Serviceto activate the function.
Click Add New Account to create an account that can call the corresponding API interface.
Enter information for the new account, including account name, password, linked product, and activated services:The linked product options include third-party products, PAAS, and NDR. Select NDR here. The system will automatically identify the linkable service modules for NDR; additional modules can be selected manually if needed.
AccessSystem > Sensor Devicesin the NDR product, add the HCI platform, enter the service account created on the HCI platform as mentioned above, and wait for asset synchronization.
In the NDR platform, navigate to Response > Auto Response to create a linkage policy. Select HCI for the VM ID - Snapshot. For detailed operations, refer to the NDR User Manual.