Create the VMware Virtual Machine

Role Availability Read-Only Investigator Analyst Manager

AT&T Cybersecurity provides a download package, which contains the VMware Open Virtualization Format (OVF) template that you can use to import and deploy the USM Anywhere Sensor on a VMware ESXi host.

Important: Use VMware ESXi 6.5, you must have build 7388607 or later. Earlier builds have an issue with the OVF tools that will cause the sensor OVF deployment to fail.

If the OVF package is invalid and can't be deployed, and you get a SHA256 Error message, see The OVF Package Is Invalid and Cannot Be Deployed - SHA256 Error for more information.

The following procedure describes the standard VMware ESXi Embedded Host Client, which is a native HTML and JavaScript application served directly from your ESXi host. Before you begin this procedure, make sure that your ESXi 6.5 host is updated to build 7388607 or later and that the web client is updated to build 7119706 or later. Refer to these VMware online resources for the latest download files and information:

If you are using VMware vCenter to manage your VMware ESXi hosts and using the VMware vSphere web client, refer to the documentation provided by VMware and extrapolate from this procedure.

To load the OVF and deploy the USM Anywhere Sensor Virtual Machine (VM)

  1. Go to the USM Anywhere Sensor Downloads page and click the icon of your specific sensor. After clicking, your browser starts to download the USM Anywhere Sensor package. Depending on your Internet connection, the download can take 30 minutes or more.

  2. Extract the USM Anywhere Sensor package to any folder on the machine where you are using the vSphere client.

  3. In your ESXi Web Client, click Create/Register VM.

    This opens the New virtual machine wizard.

  4. In the Select creation type page, choose Deploy a virtual machine from an OVF or OVA file and click Next.

  5. Enter a name for the new VM and select the template files.

  6. Browse to the location where you extracted the files from the sensor download package, select the OVF and VMDK files, and click Next.

    Select the Sensor OVF and VMDK files in the wizard

  7. For each of the wizard pages, set the parameters as needed for your network and click Next:

    • Select storage: Select the datastore you want to use for the VM.
    • Deployment options: Set the networking and deployment for the VM.

      The primary network requires internet connectivity and an IP address that is routed to provide the access to USM Anywhere. The other interfaces passively monitor network traffic in promiscuous mode.

      Warning: The VMware Sensor requires all five network interface cards (NICs) to be enabled; otherwise, the USM Anywhere update will fail. The NICs can remain disconnected.

      See Configure Network Interfaces for On-Premises Sensors for more information about these interfaces.

      Set the VM deployment options in the wizard

    • Clear the Power on automatically option. It is important to create the VM without powering it on so that you can configure the ISO file before the initial boot.
  8. In the Ready to complete panel, review the configuration and click Finish.

    An alert appears that says "A required disk image was missing". Ignore this message, because you will address the disk image in the next step.

    Review the VM settings and click Finish

    Import of the OVF and VMDK files and the creation of the virtual image can take some time. You can check the status in the Recent Tasks window.

  9. After the VM is created but not yet powered on, configure the correct ISO file, deploy_config.iso, for the datastore:

    Note: Sometimes a different ISO file is selected by default causing the deployment to fail.

    Warning: You must complete this step and ensure that the ISO is mounted before you start the sensor VM for the first time.

    If you see REPLACEME as the initial login password in the sensor welcome screen when you connect to the VM, it is most likely that the ISO was not mounted before the sensor was started. If this happens, you must shut down the VM, complete this step so that the ISO is configured for the datastore, and then begin the deployment process anew.

    • Upload the deploy_config.iso file to your datastore. You can use the datastore browser in the web client to select the ISO file and upload it.
    • Select the new sensor VM in the left pane and scroll to the Hardware Configuration section.
    • Locate CD/DVD drive 1 in the hardware list and click Select disc image.

      Locate CD/DVD drive 1 and click Select disc image

    • Navigate the datastore and select the deploy_config.iso file.

      Select the uploaded deploy_config.iso file

    • Click Select.
  10. In the toolbar, click Power on to start the USM Anywhere Sensor VM.
  11. After starting the sensor initialization process, the USM Anywhere Sensor VM thumbnail displays a green startup screen during this process, which can take a few minutes to complete.
  12. Connect to the console for the USM Anywhere Sensor using one of the following methods:

    • In the toolbar, click Console.
    • Click the thumbnail for the sensor VM.

    Open a console for the deployed USM Anywhere Sensor VM

The USM Anywhere Sensor screen provides the initial login password to use when you complete the sensor setup. It also displays the URL that you use to access USM Anywhere and complete the sensor registration and connection.