Kaspersky Anti Targeted Attack Platform

Calculations for the Central Node component deployed on the KVM and VMware ESXi virtualization platforms

This section describes the hardware and software requirements for Central Node servers that are deployed on KVM and VMware ESXi virtual platforms and have between 50 and 750 Endpoint Agent components connected. Hardware requirements for servers with more Endpoint Agents are connected are provided in the Calculations for the Central Node component section.

To deploy the application on the KVM virtual platform, you need to install the KVM hypervisor based on the Debian GNU/Linux 12 operating system using QEMU 8.0.2.

The software requirements for the VMware ESXi virtual platform are provided in the Hardware and software requirements section.

When deploying Central Node on a virtual platform, you must keep in mind the following limitations:

  • KVM:
    • The application can be installed only with Ubuntu installation files.
    • Only the non-high-availability version of the application can be installed.
    • Only Embedded Sensor can be used.
    • You can only connect a Sandbox component deployed outside the KVM virtualization platform on a physical server or on another supported virtualization platform.
    • For each Central Node server deployed in a virtual infrastructure, a separate network interface must be used for receiving mirrored SPAN traffic.
    • External systems cannot use the API to get alert information and application events.
    • Support of KVM virtualizations used in cloud solutions is not guaranteed.
    • In the virtual machine settings, the host value must be set for the type parameter in the CPU settings and the VMware vmxnet3 value for the model parameter in the network adapter settings.
  • VMware ESXi:
    • Only the non-high-availability version of the application can be installed.
    • Only Embedded Sensor can be used.
    • For each Central Node server deployed in a virtual infrastructure, a separate network interface must be used for receiving mirrored SPAN traffic.

The hardware requirements for the Central Node server depending on the functionality being used are listed in the table below.

Hardware requirements of the Central Node server when using KEDR functionality

Maximum number of hosts with the Endpoint Agent component

Maximum number of email messages per minute

Maximum volume of traffic from SPAN ports on the server with the Central Node component (Mbps)

Minimum number of logical cores at 3 GHz

Minimum RAM (GB)

50

0

0

4

31

100

0

0

4

31

150

0

0

6

31*/32

250

0

0

6

31/32

500

0

0

8

31/34

750

0

0

10

31/38

* The value before the slash represents the amount of RAM required to install the Central Node component. After installation, the amount of RAM must be brought up to the value after the slash.

Hardware requirements of the Central Node server when using KATA and KEDR functionality

Maximum number of hosts with the Endpoint Agent component

Maximum number of email messages per minute

Maximum volume of traffic from SPAN ports on the server with the Central Node component (Mbps)

Minimum number of logical cores at 3 GHz

Minimum RAM (GB)

100

1

20

6

31*/32

250

5

50

6

31/32

500

30

100

12

31/40

750

30

100

12

31/46

* The value before the slash represents the amount of RAM required to install the Central Node component. After installation, the amount of RAM must be brought up to the value after the slash.