Views:

To install DSA on Microsoft Hyper-V Server:

  1. Configure external switch.

    The DSA and Deep Security Manager (DSM) should be able to communicate with each other. The virtual machines are connected to an external switch, which allows virtual machines to send or receive packets among all Hyper-V partitions and physical network interfaces on the host.

    To use the Microsoft Hyper-V feature, Microsoft requires a virtual switch so that the guest virtual machines can connect to the desired network. Refer to this Microsoft article to create virtual networks.

    Configure external switch

    ​​
     
    Microsoft Hyper-V allows third-party vendors to develop custom switch extensions. This includes an NDIS filter or WFP filter that runs inside the Hyper-V virtual switch. At present, we support the standard configuration which only includes Microsoft default switch extensions.

    Microsoft default switch extensions

  2. Install DSA on Windows 2012 Hyper-V Server.

    There is no special configuration needed in installing the DSA on Windows 2012 Hyper-V Server. After the installation is completed, the driver will automatically connect to the Hyper-V virtual adapter.

    Connect using Hyper-V Virtual Ethernet Adapter

    ​​
     
    Starting from Deep Security 9.0 SP1 Patch 2, the Hyper-V environment is supported.
    Currently, DSA does not support Windows Server 2012 Hyper-V Replica.
  3. Protect the virtual machines.

    The DSA installed on Windows 2012 Hyper-V Server provides host-level protection and does not protect the inner guest virtual machines at hypervisor level.

    Guest virtual machines without DSA receive packets without inspection. To protect the guest virtual machine, a separate DSA should be installed and activated on the virtual machine as a standalone host. No other special configuration is needed.