Workload Security Agent Requirements
Deploy Workload Security Agents on dedicated servers that meet minimum operating system, CPU, memory, and disk space requirements to ensure optimal monitoring and threat detection performance. This guide specifies the hardware and network requirements needed before installing your Workload Security Agent, including supported Linux distributions, network connectivity rules, and system sizing guidance.
System requirements
| Component | Linux requirement |
|---|---|
Operating system |
Any 64-bit Linux distribution listed in the product, including SELinux-enabled systems. For the current list of supported distributions and versions, in Workload Security go to Collectors > Agents > +Agent and click Linux Versions Supported (i). That list is generated from the product and is always current. The installer also validates the host: on an unsupported distribution it stops with "This linux distribution is not supported. Exiting the installation". This computer should run no other application-level software. A dedicated server is recommended. |
Commands / packages |
The following are required on the Agent host:
|
CPU |
4 CPU cores |
Memory |
16 GB RAM |
Available disk space |
Allocate disk space as follows: /opt/netapp — 36 GB (minimum 35 GB free space after filesystem creation) Note: Allocate a little extra disk space to allow for filesystem creation; ensure at least 35 GB free in the filesystem. If /opt is mounted from NAS storage, ensure local users have access to the folder — the Agent or Data Collector may fail to install otherwise. |
Time synchronization |
Synchronize time on both the ONTAP system and the Agent host using NTP or SNTP. Clock skew between ONTAP and the Agent can break event correlation, health checks, and troubleshooting. |
Network |
100 Mbps to 1 Gbps Ethernet connection, static IP address, IP connectivity to all monitored devices, and a required port to the Workload Security instance (80 or 443). |
The Workload Security Agent can be installed on the same machine as a Data Infrastructure Insights Acquisition Unit and/or Agent; however, installing them on separate machines is a best practice. If installed on the same machine, allocate disk space as shown below:
| Available disk space | Allocation |
|---|---|
50–55 GB (combined install) |
For Linux, allocate as: /opt/netapp 25–30 GB; /var/log/netapp 25 GB |
Cloud network access rules
For US-based Workload Security environments:
| Protocol | Port | Source | Destination | Description |
|---|---|---|---|---|
TCP |
443 |
Workload Security Agent |
<site_name>.cs01.cloudinsights.netapp.com <site_name>.c01.cloudinsights.netapp.com <site_name>.c02.cloudinsights.netapp.com |
Access to Data Infrastructure Insights |
TCP |
443 |
Workload Security Agent |
agentlogin.cs01.cloudinsights.netapp.com |
Access to authentication services |
For Europe-based Workload Security environments:
| Protocol | Port | Source | Destination | Description |
|---|---|---|---|---|
TCP |
443 |
Workload Security Agent |
<site_name>.cs01-eu-1.cloudinsights.netapp.com <site_name>.c01-eu-1.cloudinsights.netapp.com <site_name>.c02-eu-1.cloudinsights.netapp.com |
Access to Data Infrastructure Insights |
TCP |
443 |
Workload Security Agent |
agentlogin.cs01-eu-1.cloudinsights.netapp.com |
Access to authentication services |
For APAC-based Workload Security environments:
| Protocol | Port | Source | Destination | Description |
|---|---|---|---|---|
TCP |
443 |
Workload Security Agent |
<site_name>.cs01-ap-1.cloudinsights.netapp.com <site_name>.c01-ap-1.cloudinsights.netapp.com <site_name>.c02-ap-1.cloudinsights.netapp.com |
Access to Data Infrastructure Insights |
TCP |
443 |
Workload Security Agent |
agentlogin.cs01-ap-1.cloudinsights.netapp.com |
Access to authentication services |
If the Agent is behind SSL inspection (for example, Zscaler), disable SSL inspection for *.cloudinsights.netapp.com and the regional agentlogin host. Workload Security does not work correctly when intermediary certificates re-sign the SaaS endpoints.
In-network rules
| Protocol | Port | Source | Destination | Description |
|---|---|---|---|---|
TCP |
389 (LDAP) 636 (LDAPS / start-tls) |
Workload Security Agent |
LDAP server URL |
Connect to LDAP. SSL (LDAPS/start-tls) is supported; the certificate presented by the server is accepted. |
TCP |
443 |
Workload Security Agent |
Cluster or SVM management IP address (depending on SVM collector configuration) |
API communication with ONTAP. |
TCP |
35000–55000 |
SVM data LIF IP addresses |
Workload Security Agent |
Communication from ONTAP to the Agent for FPolicy events. Open these ports toward the Agent (including any firewall on the Agent itself) so ONTAP can send file/user access events. |
TCP |
35000–55000 |
Cluster management IP |
Workload Security Agent |
Communication from the ONTAP cluster management IP to the Agent for EMS events (for example, anti-ransomware / ARP). Open these ports toward the Agent (including any firewall on the Agent itself). |
SSH |
22 |
Workload Security Agent |
Cluster management |
Needed for CIFS/SMB user blocking. |
About the FPolicy/EMS port range
You do not need to open the entire 35000–55000/tcp range. Size the reservation to the number of collectors on the Agent: each SVM uses up to 4 ports (2 per enabled protocol — NFS and CIFS/SMB). For a fully loaded Agent (50 collectors), reserve about 200 ports within this range, and increase if necessary. The two rows above use the same range for different traffic: SVM data LIF → Agent carries FPolicy file/user activity events, and Cluster management IP → Agent carries EMS events (such as ARP). Open both paths if you use the corresponding features.
When you run Test Connection before adding a collector, it verifies only a subset of live ports in this range. Keep the full reserved range open on the Agent firewall and on any network path between ONTAP and the Agent.
System sizing
An Agent supports a maximum of 50 data collectors (all types combined), within a ceiling of approximately 20,000 events per second.
Typical guidance for a dedicated Agent host:
-
4 CPU / 16 GB RAM — about 10 collectors
-
4 CPU / 32 GB RAM — about 20 collectors
-
Scale out with additional Agents when approaching the 50-collector or 20,000 events/sec limits
Use the Event Rate Checker (svm_event_rate_checker.sh) to measure peak event rates before adding collectors. See the Event Rate Checker documentation for the full sizing method.