Can communicate with HCI management IP; can communicate with SCP management IP (if no SCP ignore that).
EDR manage IP
Can communicate with HCI management IP; can communicate with SCP management IP (if no SCP ignore that).
EDR edge IP
Can connect to the internet (for updating Virus database and Vulnerability patch- optional).
For the ransomware recovery use VM storage-based snapshot it’s required the HCI cluster has at least 3 nodes and VM must located in aSAN, if the VM has disk-based snapshot must delete it first otherwise the VM can’t take storage-based snapshot