Virtual appliance node requirements

You can install Forcepoint NGFW on virtual appliances with these hardware requirements. Also be aware of some limitations.

Component Requirement
CPU Intel® Pentium D series 2 core or higher
Memory 4 GB RAM
Virtual disk space 8 GB
Hypervisor One of the following:
  • VMware ESXi 6.5 or 7.0
  • KVM with Red Hat Enterprise Linux 7.9 or 8.5
  • (Firewall/VPN role only) Microsoft Hyper-V on Windows Server 2012 R2 or Windows Server 2016 with an Intel 64-bit processor
Interfaces
  • At least one virtual network interface for the Firewall/VPN role
  • Three virtual network interfaces for IPS or Layer 2 Firewall roles

The following network interface card drivers are recommended:

  • VMware ESXi platform — vmxnet3.
  • KVM platform — virtio_net.

When Forcepoint NGFW is run as a virtual appliance node in the Firewall/VPN role, these limitations apply:

  • Only Packet Dispatching CVI mode is supported.
  • Only standby clustering mode is supported.
  • Heartbeat requires a dedicated non-VLAN-tagged interface.

When Forcepoint NGFW is run as a virtual appliance node in the IPS or Layer 2 Firewall role, clustering is not supported.