How to set up an NSS server
This how-to guide describes the required tasks to deploy a Nanolog Streaming Service (NSS) to stream either web logs or firewall logs to Devo Relay.Â
Contact Zscaler Support to request a share of the NSS AMI. Provide your AWS account ID and AWS region in which you want the AMI. After deployment, the NSS VM receives automatic software updates from the Zscaler cloud.
Prerequisites
You'll need the following to deploy NSS over your VM:
Prerequisite | Details |
---|---|
A subscription to either NSS for web or NSS for firewall | - |
VM specifications (See Recommended EC2 to get your recommended instance specifications) |
|
Network specs |
|
Bandwidth for log download: 11 Mbps for 10,000 users | - |
Firewall requirements | It's mandatory to deploy the NSS instance behind a VM network security group. The NSS instance requires only outbound connections to the Zscaler cloud. It doesn't require any inbound connections to your network from the Zscaler cloud. To view the firewall requirements for your specific account, refer to the Zscaler Cloud Configuration Requirements for your Zscaler cloud: https://config.zscaler.com/ Cloud Name>/nss You can find the name of your Zscaler cloud in the URL you use to log in to the Zscaler service. For example, if you log in to admin.zscaler.net, then go to config.zscaler.com/zscaler.net/nss The IP ranges are necessary to ensure that the service isn't affected by future Zscaler cloud expansion. |
Â