Online Installation

Prepare your host system /VM

Before starting the installation, please make sure that your target system meets the technical requirements and the installation is performed by a person with basic Linux skills.

Warning

This page only refers to product installation with a stable internet connection!

Installation

Step #1 - Download and unpack the product installer:

Download the release archive from https://my.opswat.com/portal/products and save it to a convenient location, e.g. your home folder.

The release archive is password protected and needs to be unpacked using 7-Zip:

Please use the password that you received from OPSWAT support!

Please adjust the x.y.z version numbers to match the downloaded filename.

7za x -aoa -p"PASSWORD" MetaDefender_NDR_vx.y.z-Standalone.zip

Step #2 - Move to the installation folder:

cd ndr-installer

Step #3 - Run the install shell script

Note that this operation can take up to 20-30 minutes (depending on available network bandwidth).

sudo ./install.sh

The first step of the installation process is accepting the product EULA, you need to type ACCEPT to start the installation.

Step #4 - Access the NDR web server

Navigate to (https://localhost:443) and setup the initial Admin user.

username: admin

password: admin123

Step #5 - Add your Activation Key

Please use the Activation Key that you received from your OPSWAT Sales Representative, and follow the instructions on the License Activation page.

Simple steps for Online activation:

Navigate to the Admin panel > Settings > Integrations > License Management tab, then click on Activate All, then enter your license key!


Manager/Sensor Installation and Adoption (v5)

MetaDefender NDR v5 is deployed using a bootable ISO that runs a First-Boot Guided Installer. The installer supports three deployment roles, allowing you to deploy a Manager and one or more Sensors independently.

Prerequisites

Resource

All-in-One

Manager Only

Sensor Only

CPU

8+ cores (4 min)

4+ cores

2+ cores

RAM

32 GB recommended (8 GB min)

16 GB recommended (8 GB min)

4 GB min

Disk

150 GB

150 GB

50 GB

NICs

2+ (1 mgmt, 1+ capture)

1 (mgmt)

1 mgmt + 1+ capture

For Sensor enrollment to a remote Manager: HTTPS port 8443 must be open from sensor to Manager IP.

Obtaining and Booting the ISO

  1. Download the NDR v5 ISO from the OPSWAT Customer Portal or your designated artifact repository.

  2. Flash to USB (Linux/macOS: dd, Windows: Rufus in DD Image mode) or attach as a virtual CD-ROM in your hypervisor.

  3. Boot the target server/VM from the ISO. The NDR boot menu appears — select Install NDR Platform and press Enter.

  4. The automated Oracle Linux 9 OS installation completes (~10–20 minutes), then the system reboots automatically.

First-Boot Guided Installer

After reboot, the NDR First-Boot Guided Installer launches automatically on the console. If connecting over SSH before setup completes, run:

sudo ndr-firstboot

Step 1: Accept the EULA by typing ACCEPT.

Step 2: Select a deployment role:

  • 1) All-in-One — Full NDR management platform with a local Suricata sensor on this host

  • 2) Manager — Management platform only; sensors are enrolled separately

  • 3) Sensor — Network capture sensor that connects to an existing Manager

All-in-One Role Prompts

Prompt

Example

Notes

Management interface

eth0

Interface for operator UI/API access

Capture interface(s)

eth1,eth2

Comma-separated interfaces

HOME_NET

192.168.0.0/16

Internal network CIDR(s)

Sensor name

aio-sensor-01

Friendly display name in the UI

Manager Only Role

Prompted only for the management network interface. All further configuration is performed via the NDR Web UI after installation.

Sensor Only Role — Enrollment Prompts

Prompt

Example

Notes

Manager URL

https://192.168.1.10:8443

Manager enrollment API endpoint

Enrollment token

eyJ...

Generated from Manager UI

Capture interface(s)

eth1

Interface(s) for traffic capture

HOME_NET

192.168.0.0/16

Internal network CIDR(s)

Sensor name

sensor-datacenter-01

Friendly display name

Generating a Sensor Enrollment Token

Before enrolling a new Sensor, generate an enrollment token from the Manager:

  1. Log in to the Manager Web UI.

  2. Navigate to Admin panel → Sensors → Add Sensor.

  3. Copy the generated enrollment token (eyJ...).

  4. Supply this token to the Sensor First-Boot Installer when prompted.

The sensor establishes a mutual TLS-authenticated channel to the Manager upon successful enrollment and appears in the Sensors list as Online.

Post-Installation Access

Service

URL / Endpoint

NDR Web UI

https://<ip>:443

SSH

ssh admin@<ip>

Sensor status

sudo systemctl status ndr-adapter.service ndr-sensord.service

Airgapped Deployments

The NDR ISO is fully self-contained. All container images are pre-loaded — no internet access is required at install time or during normal operation. For DNS-restricted environments, configure /etc/hosts or a local DNS resolver to resolve the management hostname before enrolling sensors.


OVA Installation for MetaDefender NDR v5

MetaDefender NDR v5 is installed from a bootable ISO image — there is no pre-built OVA to import. This section covers how to create and configure a virtual machine, attach the NDR v5 ISO, and run the First-Boot Guided Installer to deploy the product inside a hypervisor.

MetaDefender NDR v5 is distributed as a bootable ISO (not a pre-packaged OVA/OVF). You create the VM yourself using the specs below, then install from the ISO exactly as you would on bare metal.

VM-based deployments are supported for 1 Gbps sensors and below only. Higher throughput tiers (10 Gb, 20 Gb, 40 Gb, 100 Gb) require dedicated bare-metal appliances with hardware-level tuning (SR-IOV, CPU pinning, hugepages, RAID NVMe). Do not attempt to run a high-throughput sensor in a VM.


CPU virtualization extensions (Intel VT-x / AMD-V) must be enabled in BIOS/UEFI. For nested virtualization (VM-inside-VM), ensure the hypervisor exposes these extensions to the guest.

Supported Hypervisors

Hypervisor

Recommended Adapter

Notes

VMware ESXi 7.0+

VMXNET3

Recommended for production

VMware Workstation / Fusion (Intel)

VMXNET3 or E1000e

Lab/demo use

KVM / Proxmox VE

VirtIO

Best open-source option

VirtualBox

Paravirtualized / Intel PRO/1000

Lab use only


VMware Fusion on Apple Silicon (ARM/M-series) is not supported. MetaDefender NDR v5 requires x86_64 architecture.

VM Sizing Requirements

Sensor VM (1 Gbps)

Resource

Minimum

Recommended

vCPU

24 cores

32 cores

RAM

256 GB

256 GB

Storage

7.68 TB

7.68 TB NVMe

Management NIC

1 GbE

1 GbE (static IP)

Capture NIC(s)

1 GbE+

1+ dedicated capture interfaces

Configure capture NIC(s) in promiscuous mode so the VM can see all traffic on the monitored segment. In VMware, set the vSwitch/portgroup to Promiscuous Mode: Accept. In Proxmox/KVM, bring the bridge up without ARP filtering.

Manager VM

SKU

Sensors Managed

vCPU Cores

RAM

Storage

Manager STD

Up to 25 sensors

32–64

512 GB

19.2 TB NVMe (RAID 10)

Manager XL

100–500 sensors

96–192

1–4 TB

76.8+ TB NVMe (RAID 10)


Manager storage is used by Elasticsearch and ClickHouse for event retention. 19.2 TB (Manager STD) supports approximately 90 days of full event retention at typical enterprise traffic volumes. Size up or add nodes if longer retention is required.

Attaching the ISO

VMware ESXi / vCenter:

  1. Upload the NDR v5 ISO to your datastore.

  2. Edit VM Settings → CD/DVD Drive → Datastore ISO File → select the ISO.

  3. Ensure Connect at Power On is checked.

VMware Workstation / Fusion:

  1. VM Settings → CD/DVD → Use ISO Image File → browse to the NDR v5 ISO.

Proxmox VE:

  1. Upload the ISO to local (pve) → ISO Images.

  2. VM → Hardware → Add → CD/DVD Drive → select the ISO from storage.

  3. Set the boot order to boot from the CD drive first.

KVM / virt-manager:

  1. Add Hardware → Storage → Select custom storage → ISO file.

  2. Set boot device to CD-ROM in the Boot Options tab.


Installing from the ISO

  1. Power on the VM. The NDR boot menu appears.

  2. Select Install NDR Platform and press Enter.

  3. To install with FIPS 140-2 cryptographic enforcement (required for US federal or regulated environments), select Install NDR Platform (FIPS Mode) instead.

    FIPS mode cannot be enabled after installation — you must re-image to switch.

  4. The automated Oracle Linux 9 OS installation runs unattended (~10–20 minutes). The VM reboots automatically when complete.

  5. After reboot, the NDR First-Boot Guided Installer launches on the console (tty1). Follow the prompts from the Manager/Sensor Installation and Adoption (v5) section above to complete your deployment.


Post-Install: Detach the ISO

After installation is complete, detach the ISO from the VM's CD/DVD drive to prevent re-booting from it on next restart.

After a successful install, the VM boots directly from disk and the ISO is no longer needed. Leaving it attached is harmless but unnecessary.