Faddom can seamlessly integrate with your Nutanix AHV environment. To do this, you need to enable IPFIX via the Faddom UI. This guide will explain to you how to do this.
If you are using VMware on Nutanix, refer to our VMware guide.
Prerequisites
Faddom utilises IPFIX to get the traffic from Nutanix AHV. This is supported from Prism Central 2023.3 and AOS is 6.5.5.5.
If you want to enable IPFIX on older versions of Nutanix, see How to Enable IPFix on Nutanix 5.20LTS
Additionally, to receive information on the OS, MAC address and some other server properties, Nutanix Guest Tools (NGT) needs to be enabled on each machine.
Permissions
To enable IPFIX via the Faddom UI you need to provide user credentials with Prism Admin permissions. Once the discovery is complete and IPFIX is configured, you can use a read-only user.
How to Discover Nutanix
Go to Settings > Data Sources > Nutanix
Enter your Prism Central credentials
Select DISCOVER
At Step 2 select the hosts you wish to enable IPFIX for and select ENABLE IPFIX
Once this is complete you can begin creating maps with your Nutanix environment by following the guide New Application Maps
Categories and Custom Tags
Faddom automatically collects Nutanix categories (custom tags) from your Prism Central environment and displays them in the Custom Tags section of each server's properties panel.
You can use these categories to:
Create Application Maps based on category groupings
Organize and filter servers in your inventory
Generate microsegmentation policies (see below)
Search by tags across your environment
Using Nutanix Categories for Microsegmentation
Faddom's Micro-Segmentation module can leverage Nutanix categories to automatically create security policies in Nutanix Flow.
When you create application maps based on Nutanix categories, Faddom will:
Automatically generate Nutanix Flow policies using category-to-category rules
Push policies to Flow in Monitoring Mode for safe review
Maintain ongoing drift detection to keep policies current
For detailed instructions, see our guide How to Use the Microsegmentation Module.
Permissions
To push micro-segmentation policies to Nutanix Flow, create a custom role in Prism Central (IAM > Authorization Policies) with the following permissions:
Address Group (1 operation)
AHV VM (1 operation)
Category (10 operations)
Category Mapping (4 operations)
Cluster Management Task (1 operation)
Flow Policy (7 operations)
Service Group (1 operation)
Note: Once discovery and IPFIX configuration are complete, you can use a read-only user for ongoing data collection. Elevated permissions are only required when pushing policies to Flow.
