Skip to main content
Data Infrastructure Insights

Workload Security Agent Requirements

Contributors netapp-alavoie dgracenetapp

Deploy Workload Security Agents on dedicated servers that meet minimum operating system, CPU, memory, and disk space requirements to ensure optimal monitoring and threat detection performance. This guide specifies the hardware and network requirements needed before installing your Workload Security Agent, including supported Linux distributions, network connectivity rules, and system sizing guidance.

System requirements

Component Linux requirement

Operating system

Any 64-bit Linux distribution listed in the product, including SELinux-enabled systems.

For the current list of supported distributions and versions, in Workload Security go to Collectors > Agents > +Agent and click Linux Versions Supported (i). That list is generated from the product and is always current.

The installer also validates the host: on an unsupported distribution it stops with "This linux distribution is not supported. Exiting the installation".

This computer should run no other application-level software. A dedicated server is recommended.

Commands / packages

The following are required on the Agent host:

  • unzip — Agent installation

  • zip — diagnostic bundle (cloudsecure-agent-symptom-collector.sh)

  • sshpass — Event Rate Checker (svm_event_rate_checker.sh)

  • sudo su – — installation, running scripts, and uninstall

CPU

4 CPU cores

Memory

16 GB RAM

Available disk space

Allocate disk space as follows:

/opt/netapp — 36 GB (minimum 35 GB free space after filesystem creation)

Note: Allocate a little extra disk space to allow for filesystem creation; ensure at least 35 GB free in the filesystem. If /opt is mounted from NAS storage, ensure local users have access to the folder — the Agent or Data Collector may fail to install otherwise.

Time synchronization

Synchronize time on both the ONTAP system and the Agent host using NTP or SNTP. Clock skew between ONTAP and the Agent can break event correlation, health checks, and troubleshooting.

Network

100 Mbps to 1 Gbps Ethernet connection, static IP address, IP connectivity to all monitored devices, and a required port to the Workload Security instance (80 or 443).

The Workload Security Agent can be installed on the same machine as a Data Infrastructure Insights Acquisition Unit and/or Agent; however, installing them on separate machines is a best practice. If installed on the same machine, allocate disk space as shown below:

Available disk space Allocation

50–55 GB (combined install)

For Linux, allocate as: /opt/netapp 25–30 GB; /var/log/netapp 25 GB

Cloud network access rules

For US-based Workload Security environments:

Protocol Port Source Destination Description

TCP

443

Workload Security Agent

<site_name>.cs01.cloudinsights.netapp.com

<site_name>.c01.cloudinsights.netapp.com

<site_name>.c02.cloudinsights.netapp.com

Access to Data Infrastructure Insights

TCP

443

Workload Security Agent

agentlogin.cs01.cloudinsights.netapp.com

Access to authentication services

For Europe-based Workload Security environments:

Protocol Port Source Destination Description

TCP

443

Workload Security Agent

<site_name>.cs01-eu-1.cloudinsights.netapp.com

<site_name>.c01-eu-1.cloudinsights.netapp.com

<site_name>.c02-eu-1.cloudinsights.netapp.com

Access to Data Infrastructure Insights

TCP

443

Workload Security Agent

agentlogin.cs01-eu-1.cloudinsights.netapp.com

Access to authentication services

For APAC-based Workload Security environments:

Protocol Port Source Destination Description

TCP

443

Workload Security Agent

<site_name>.cs01-ap-1.cloudinsights.netapp.com

<site_name>.c01-ap-1.cloudinsights.netapp.com

<site_name>.c02-ap-1.cloudinsights.netapp.com

Access to Data Infrastructure Insights

TCP

443

Workload Security Agent

agentlogin.cs01-ap-1.cloudinsights.netapp.com

Access to authentication services

If the Agent is behind SSL inspection (for example, Zscaler), disable SSL inspection for *.cloudinsights.netapp.com and the regional agentlogin host. Workload Security does not work correctly when intermediary certificates re-sign the SaaS endpoints.

In-network rules

Protocol Port Source Destination Description

TCP

389 (LDAP)

636 (LDAPS / start-tls)

Workload Security Agent

LDAP server URL

Connect to LDAP. SSL (LDAPS/start-tls) is supported; the certificate presented by the server is accepted.

TCP

443

Workload Security Agent

Cluster or SVM management IP address (depending on SVM collector configuration)

API communication with ONTAP.

TCP

35000–55000

SVM data LIF IP addresses

Workload Security Agent

Communication from ONTAP to the Agent for FPolicy events. Open these ports toward the Agent (including any firewall on the Agent itself) so ONTAP can send file/user access events.

TCP

35000–55000

Cluster management IP

Workload Security Agent

Communication from the ONTAP cluster management IP to the Agent for EMS events (for example, anti-ransomware / ARP). Open these ports toward the Agent (including any firewall on the Agent itself).

SSH

22

Workload Security Agent

Cluster management

Needed for CIFS/SMB user blocking.

About the FPolicy/EMS port range

You do not need to open the entire 35000–55000/tcp range. Size the reservation to the number of collectors on the Agent: each SVM uses up to 4 ports (2 per enabled protocol — NFS and CIFS/SMB). For a fully loaded Agent (50 collectors), reserve about 200 ports within this range, and increase if necessary. The two rows above use the same range for different traffic: SVM data LIF → Agent carries FPolicy file/user activity events, and Cluster management IP → Agent carries EMS events (such as ARP). Open both paths if you use the corresponding features.

When you run Test Connection before adding a collector, it verifies only a subset of live ports in this range. Keep the full reserved range open on the Agent firewall and on any network path between ONTAP and the Agent.

System sizing

An Agent supports a maximum of 50 data collectors (all types combined), within a ceiling of approximately 20,000 events per second.

Typical guidance for a dedicated Agent host:

  • 4 CPU / 16 GB RAM — about 10 collectors

  • 4 CPU / 32 GB RAM — about 20 collectors

  • Scale out with additional Agents when approaching the 50-collector or 20,000 events/sec limits

Use the Event Rate Checker (svm_event_rate_checker.sh) to measure peak event rates before adding collectors. See the Event Rate Checker documentation for the full sizing method.