Title
Create new category
Edit page index title
Edit category
Edit link
Online Installation
Prepare your host system /VM
Before starting the installation, please make sure that your target system meets the technical requirements and the installation is performed by a person with basic Linux skills.
Warning
This page only refers to product installation with a stable internet connection!
Installation
Step #1 - Download and unpack the product installer:
Download the release archive from https://my.opswat.com/portal/products and save it to a convenient location, e.g. your home folder.
The release archive is password protected and needs to be unpacked using 7-Zip:
Please use the password that you received from OPSWAT support!
Please adjust the x.y.z version numbers to match the downloaded filename.
Step #2 - Move to the installation folder:
Step #3 - Run the install shell script
Note that this operation can take up to 20-30 minutes (depending on available network bandwidth).
The first step of the installation process is accepting the product EULA, you need to type ACCEPT to start the installation.
Step #4 - Access the NDR web server
Navigate to (https://localhost:443) and setup the initial Admin user.
username: admin
password: admin123
Step #5 - Add your Activation Key
Please use the Activation Key that you received from your OPSWAT Sales Representative, and follow the instructions on the License Activation page.
Simple steps for Online activation:
Navigate to the Admin panel > Settings > Integrations > License Management tab, then click on Activate All, then enter your license key!
Manager/Sensor Installation and Adoption (v5)
MetaDefender NDR v5 is deployed using a bootable ISO that runs a First-Boot Guided Installer. The installer supports three deployment roles, allowing you to deploy a Manager and one or more Sensors independently.
Prerequisites
Resource | All-in-One | Manager Only | Sensor Only |
|---|---|---|---|
CPU | 8+ cores (4 min) | 4+ cores | 2+ cores |
RAM | 32 GB recommended (8 GB min) | 16 GB recommended (8 GB min) | 4 GB min |
Disk | 150 GB | 150 GB | 50 GB |
NICs | 2+ (1 mgmt, 1+ capture) | 1 (mgmt) | 1 mgmt + 1+ capture |
For Sensor enrollment to a remote Manager: HTTPS port 8443 must be open from sensor to Manager IP.
Obtaining and Booting the ISO
Download the NDR v5 ISO from the OPSWAT Customer Portal or your designated artifact repository.
Flash to USB (Linux/macOS:
dd, Windows: Rufus in DD Image mode) or attach as a virtual CD-ROM in your hypervisor.Boot the target server/VM from the ISO. The NDR boot menu appears — select Install NDR Platform and press Enter.
The automated Oracle Linux 9 OS installation completes (~10–20 minutes), then the system reboots automatically.
First-Boot Guided Installer
After reboot, the NDR First-Boot Guided Installer launches automatically on the console. If connecting over SSH before setup completes, run:
Step 1: Accept the EULA by typing ACCEPT.
Step 2: Select a deployment role:
1) All-in-One — Full NDR management platform with a local Suricata sensor on this host
2) Manager — Management platform only; sensors are enrolled separately
3) Sensor — Network capture sensor that connects to an existing Manager
All-in-One Role Prompts
Prompt | Example | Notes |
|---|---|---|
Management interface |
| Interface for operator UI/API access |
Capture interface(s) |
| Comma-separated interfaces |
HOME_NET |
| Internal network CIDR(s) |
Sensor name |
| Friendly display name in the UI |
Manager Only Role
Prompted only for the management network interface. All further configuration is performed via the NDR Web UI after installation.
Sensor Only Role — Enrollment Prompts
Prompt | Example | Notes |
|---|---|---|
Manager URL |
| Manager enrollment API endpoint |
Enrollment token |
| Generated from Manager UI |
Capture interface(s) |
| Interface(s) for traffic capture |
HOME_NET |
| Internal network CIDR(s) |
Sensor name |
| Friendly display name |
Generating a Sensor Enrollment Token
Before enrolling a new Sensor, generate an enrollment token from the Manager:
Log in to the Manager Web UI.
Navigate to Admin panel → Sensors → Add Sensor.
Copy the generated enrollment token (
eyJ...).Supply this token to the Sensor First-Boot Installer when prompted.
The sensor establishes a mutual TLS-authenticated channel to the Manager upon successful enrollment and appears in the Sensors list as Online.
Post-Installation Access
Service | URL / Endpoint |
|---|---|
NDR Web UI |
|
SSH |
|
Sensor status |
|
Airgapped Deployments
The NDR ISO is fully self-contained. All container images are pre-loaded — no internet access is required at install time or during normal operation. For DNS-restricted environments, configure /etc/hosts or a local DNS resolver to resolve the management hostname before enrolling sensors.
OVA Installation for MetaDefender NDR v5
MetaDefender NDR v5 is installed from a bootable ISO image — there is no pre-built OVA to import. This section covers how to create and configure a virtual machine, attach the NDR v5 ISO, and run the First-Boot Guided Installer to deploy the product inside a hypervisor.
MetaDefender NDR v5 is distributed as a bootable ISO (not a pre-packaged OVA/OVF). You create the VM yourself using the specs below, then install from the ISO exactly as you would on bare metal.
VM-based deployments are supported for 1 Gbps sensors and below only. Higher throughput tiers (10 Gb, 20 Gb, 40 Gb, 100 Gb) require dedicated bare-metal appliances with hardware-level tuning (SR-IOV, CPU pinning, hugepages, RAID NVMe). Do not attempt to run a high-throughput sensor in a VM.
CPU virtualization extensions (Intel VT-x / AMD-V) must be enabled in BIOS/UEFI. For nested virtualization (VM-inside-VM), ensure the hypervisor exposes these extensions to the guest.
Supported Hypervisors
Hypervisor | Recommended Adapter | Notes |
|---|---|---|
VMware ESXi 7.0+ | VMXNET3 | Recommended for production |
VMware Workstation / Fusion (Intel) | VMXNET3 or E1000e | Lab/demo use |
KVM / Proxmox VE | VirtIO | Best open-source option |
VirtualBox | Paravirtualized / Intel PRO/1000 | Lab use only |
VMware Fusion on Apple Silicon (ARM/M-series) is not supported. MetaDefender NDR v5 requires x86_64 architecture.
VM Sizing Requirements
Sensor VM (1 Gbps)
Resource | Minimum | Recommended |
|---|---|---|
vCPU | 24 cores | 32 cores |
RAM | 256 GB | 256 GB |
Storage | 7.68 TB | 7.68 TB NVMe |
Management NIC | 1 GbE | 1 GbE (static IP) |
Capture NIC(s) | 1 GbE+ | 1+ dedicated capture interfaces |
Configure capture NIC(s) in promiscuous mode so the VM can see all traffic on the monitored segment. In VMware, set the vSwitch/portgroup to Promiscuous Mode: Accept. In Proxmox/KVM, bring the bridge up without ARP filtering.
Manager VM
SKU | Sensors Managed | vCPU Cores | RAM | Storage |
|---|---|---|---|---|
Manager STD | Up to 25 sensors | 32–64 | 512 GB | 19.2 TB NVMe (RAID 10) |
Manager XL | 100–500 sensors | 96–192 | 1–4 TB | 76.8+ TB NVMe (RAID 10) |
Manager storage is used by Elasticsearch and ClickHouse for event retention. 19.2 TB (Manager STD) supports approximately 90 days of full event retention at typical enterprise traffic volumes. Size up or add nodes if longer retention is required.
Attaching the ISO
VMware ESXi / vCenter:
Upload the NDR v5 ISO to your datastore.
Edit VM Settings → CD/DVD Drive → Datastore ISO File → select the ISO.
Ensure Connect at Power On is checked.
VMware Workstation / Fusion:
VM Settings → CD/DVD → Use ISO Image File → browse to the NDR v5 ISO.
Proxmox VE:
Upload the ISO to local (pve) → ISO Images.
VM → Hardware → Add → CD/DVD Drive → select the ISO from storage.
Set the boot order to boot from the CD drive first.
KVM / virt-manager:
Add Hardware → Storage → Select custom storage → ISO file.
Set boot device to CD-ROM in the Boot Options tab.
Installing from the ISO
Power on the VM. The NDR boot menu appears.
Select Install NDR Platform and press Enter.
To install with FIPS 140-2 cryptographic enforcement (required for US federal or regulated environments), select Install NDR Platform (FIPS Mode) instead.
FIPS mode cannot be enabled after installation — you must re-image to switch.
The automated Oracle Linux 9 OS installation runs unattended (~10–20 minutes). The VM reboots automatically when complete.
After reboot, the NDR First-Boot Guided Installer launches on the console (tty1). Follow the prompts from the Manager/Sensor Installation and Adoption (v5) section above to complete your deployment.
Post-Install: Detach the ISO
After installation is complete, detach the ISO from the VM's CD/DVD drive to prevent re-booting from it on next restart.
After a successful install, the VM boots directly from disk and the ISO is no longer needed. Leaving it attached is harmless but unnecessary.