Skip to main content

How to Discover Nutanix AHV

Itamar Rotem avatar
Written by Itamar Rotem
Updated over 2 weeks ago

Faddom can seamlessly integrate with your Nutanix AHV environment. To do this, you need to enable IPFIX via the Faddom UI. This guide will explain to you how to do this.

If you are using VMware on Nutanix, refer to our VMware guide.

Prerequisites

Faddom utilises IPFIX to get the traffic from Nutanix AHV. This is supported from Prism Central 2023.3 and AOS is 6.5.5.5.

If you want to enable IPFIX on older versions of Nutanix, see How to Enable IPFix on Nutanix 5.20LTS

Additionally, to receive information on the OS, MAC address and some other server properties, Nutanix Guest Tools (NGT) needs to be enabled on each machine.

Permissions

To enable IPFIX via the Faddom UI you need to provide user credentials with Prism Admin permissions. Once the discovery is complete and IPFIX is configured, you can use a read-only user.

How to Discover Nutanix

  1. Go to Settings > Data Sources > Nutanix



  2. Enter your Prism Central credentials

  3. Select DISCOVER

  4. At Step 2 select the hosts you wish to enable IPFIX for and select ENABLE IPFIX

Once this is complete you can begin creating maps with your Nutanix environment by following the guide New Application Maps

Categories and Custom Tags

Faddom automatically collects Nutanix categories (custom tags) from your Prism Central environment and displays them in the Custom Tags section of each server's properties panel.

You can use these categories to:

  • Create Application Maps based on category groupings

  • Organize and filter servers in your inventory

  • Generate microsegmentation policies (see below)

  • Search by tags across your environment


Using Nutanix Categories for Microsegmentation

Faddom's Micro-Segmentation module can leverage Nutanix categories to automatically create security policies in Nutanix Flow.

When you create application maps based on Nutanix categories, Faddom will:

  • Automatically generate Nutanix Flow policies using category-to-category rules

  • Push policies to Flow in Monitoring Mode for safe review

  • Maintain ongoing drift detection to keep policies current

For detailed instructions, see our guide How to Use the Microsegmentation Module.

Permissions

To push micro-segmentation policies to Nutanix Flow, create a custom role in Prism Central (IAM > Authorization Policies) with the following permissions:

  • Address Group (1 operation)

  • AHV VM (1 operation)

  • Category (10 operations)

  • Category Mapping (4 operations)

  • Cluster Management Task (1 operation)

  • Flow Policy (7 operations)

  • Service Group (1 operation)

Note: Once discovery and IPFIX configuration are complete, you can use a read-only user for ongoing data collection. Elevated permissions are only required when pushing policies to Flow.

Did this answer your question?