Cisco IQ Virtual Appliance Getting Started Guide

 
Updated August 20, 2026
PDF
Is this helpful? Feedback

Introduction

Cisco IQTM provides customers with features designed to improve asset visibility and deliver smarter insights across their environments. In addition, AI features such as the AI Assistant optimize operational outcomes and the Cisco IQ user experience by providing contextual understanding that empowers users to make proactive, informed decisions, and streamlines processes for customer engagement and success.

Cisco IQ On-Prem Air-Gapped is the deployment mode of Cisco IQ built for environments that cannot connect to the cloud. It is delivered as a self-contained Virtual Machine (VM), referred to as the Cisco IQ Virtual Appliance (VA), which runs entirely on the customer's premises in complete isolation from external networks, with software updates and maintenance packages obtained from Cisco IQ SaaS and transferred to the VA through an approved, manual process.

For organizations operating in regulated, high-security, and sovereign environments, VA removes the trade-off between insight and control. Customers deploy Cisco IQ Assets and Assessments capabilities inside their own network and retain complete ownership of their data, while still getting the insights and recommendations they expect from Cisco IQ. The Air-Gapped deployment mode extends the capabilities of Cisco IQ SaaS to isolated environments, enabling mission-critical teams to operate with the speed and diagnostic intelligence of cloud-connected enterprises.

This guide provides instructions for configuring and deploying the VA, including the process of setting up the required network environment.

Prerequisites

Ensure the following prerequisites are met before configuring and installing Cisco IQ VA.

Hardware and VM Resource Requirements

Cisco IQ VA is tested for multiple scale capacity and offers multiple deployment sizes to support your environment’s scaling needs. Refer to the table below to select the appropriate resource configuration based on your planned device discovery count for both Non-Graphics Processing Unit (GPU) and GPU-based deployment options.

Table 1: Hardware and VM Resource Requirements

Resource

Up to 5K Devices (Non-GPU Based)

Up to 20K Devices (Non-GPU Based)

Up to 20K Devices (GPU-Based)*

vCPU

48

64

128

RAM

96GB

128GB

256GB

Storage (SSD) (Recommended for better performance)

1.3TB

1.3TB

2.6TB

Collection Schedule

24 hours or more

24 hours or more

24 hours or more

Supported Hypervisors

●  VMware ESXi v8.0 or later with VMware vSphere Web Client v8.0 or later

●  Hyper-V on Microsoft Server 2022 and 2025

●  Kernel-based Virtual Machine (KVM) Hypervisor on RHEL v9.7 or later

Additional Recommendation

●  Cisco recommends that you use thick provisioning. While it is possible to use thin provisioning, over-provisioning can lead to a lack of storage capacity which can then result in degradation and loss of service.

●  It is highly recommended to place appliance disks on a volume backed by SSDs.

●  Disk write speed must be greater than 70 megabytes per second.

*vCPU, RAM, and Disk resources are required to be equally divided between two (2) VMs.

AI Feature Resource Requirements

Cisco IQ VA is tested and supported on the NVIDIA RTX Pro 6000 Blackwell Server Edition GPU. This GPU configuration meets the performance and latency requirements at the planned deployment scale.

Table 2: AI Feature Resource Requirements

Resource

Recommended

Validated GPU

NVIDIA RTX Pro 6000 Blackwell Server Edition

Additional GPU Options (Not validated)

NVIDIA H200 (141 GB)

Additional GPU Options (Not validated, suggested with one (1) concurrent user)

●  NVIDIA H100 (80 GB)

●  NVIDIA H100 NVL (94 GB)

●  NVIDIA A100 (80 GB)

note-icon

Note: GPUs other than NVIDIA RTX Pro 6000 Blackwell Server Edition have not been validated in Cisco labs at the supported scale. Performance and latency are not guaranteed for non-validated GPUs. Please validate all non-supported hardware against your projected workload in a pre-production environment prior to production deployment.

Network Requirements

VA supports a single network interface.

 IP Address and Hostname Requirements

The following IP address and hostname requirements must be met:

  • Domain Name System (DNS): DNS simplifies system management by replacing numeric IP addresses with consistent, human-readable hostnames. This approach facilitates easier maintenance, seamless service integration, and reliable certificate validation in secure environments. Ensure that the IPv4 address is configured in your DNS with the following:
  • A Record: Maps the hostname to the IPv4 address
  • Associated Pointer (PTR) record: Required to support reverse DNS lookups; if an IP address resolves to multiple hostnames, the first resolved hostname is used to access the UI
  •     IP Addresses: The VA requires the following three (3) IP addresses to be configured before deployment:
  • VM Access IP: A routable IPv4 address used to access the VA; no subnet restrictions apply, provided the address has network connectivity
  • System Orchestration (SysOrch) IP: An internal /32 address used for communication between pods and the VM (the default is 192.168.23.17/32); this does not need to be changed unless the address conflicts with an existing address in your network
  • Kubernetes Pod CIDR: An internal /20 subnet used for Kubernetes pod networking (the default is 100.64.0.0/20); this must not overlap with the SysOrch IP, DNS server, VM access IP, or NTP server addresses
note-icon

Note: DHCP is currently not supported.

Port Requirements

The following table outlines the network ports required for Cisco IQ VA communication.

Table 3: Port Requirements

Port(s)

Protocol

Description

22

TCP

Used for Administrator CLI and Cisco Support debugging sessions

443

TCP

Used for communication between Cisco IQ On-Prem and web browsers, as well as endpoint targets

53, 123, 161

UDP

Used to send and receive DNS, NTP, and SNMP traffic

Supported Browsers

You must use the latest stable release of the following browsers to install and launch VA:

  • Google Chrome
  • Microsoft Edge
  • Apple Safari
  • Mozilla Firefox
note-icon

Note: Support is limited to current browser versions, and older versions may not provide full functionality or may be unsupported as new updates are released.

Deployment Options

Cisco IQ VA offers two (2) flexible deployment options designed to meet your specific operational and security requirements. You can choose the deployment path that best aligns with your operational and security requirements, ensuring a scalable and future-ready solution.

Non-GPU Deployment (Non-AI Features)

The Non-GPU deployment runs on standard compute resources, with no GPU required, allowing you to access all core Cisco IQ, non-AI capabilities, including Assets and Inventory, Assessments, and day-to-day operations.

This option is ideal for environments where GPU hardware is not immediately available, allowing you to deploy the Cisco IQ VA and scale to AI features later.

The following high-level steps outline the non-GPU deployment process:

  1. System Planning: Determine the number of VMs required based on your scale and module needs. One (1) VM is required at minimum. See the table in Hardware and VM Resource Requirements for more details about Cisco IQ VA’s multi-scale capability.
  2. Resource Provisioning: Obtain the necessary IP addresses and VM resource. See Network Requirements for more details.
  3. Software Download:
    1. Download Cisco IQ VA Installer. See Downloading a VA for more details.
    2. Download required Cisco IQ Module Installer. See Modules and Rules Installation for more details.
  4. Deployment and Installation:
    1. Deploy the Cisco IQ VA.  See Deploying VA on Hypervisor and Installing VA for Air-Gapped Mode for more details.
    2. Install the downloaded modules via the Package Catalog in the UI. See Modules and Rules Installation for more details.

Once these steps are complete, Cisco IQ VA is now ready for use without AI support.

GPU-based Deployment (AI-Enabled Features)

The GPU-based deployment utilizes a supported GPU, which powers all supported Cisco IQ on-premises AI features, including an AI Assistant, Key Insights, and Full Insights, along with core features like Assets and Inventory, Assessments, and day-to-day operations. You get SaaS-grade, Cisco IQ AI-powered insights entirely within your air-gapped environment, without your data ever leaving your premises.

The GPU-based deployment requires a minimum of two (2) nodes: One (1) VM that is the same as the Non-GPU node and a second VM with a GPU to enable AI features. The following high-level steps outline the GPU deployment process.

GPU Deployment Process

  1. System Planning: Determine the number of VMs required based on scale and module needs. A minimum of two (2) VMs are required, listed below. See the table in the section Hardware and VM Resource Requirements to get more details about Cisco IQ VA multiple scale capability.
  • VM 1: Dedicated to CPU workloads
  • VM 2: Dedicated to GPU workloads
  1. Resource Provisioning: Obtain the necessary IP addresses and VM resource. See Network Requirements section for more details.
  2. Software Download:
    1. Download the Cisco IQ VA Installer.  See Downloading a VA for more details.
    2. Download the required Cisco IQ Module Installer. See Modules and Rules Installation for more details.
  3. Download the Cisco IQ AI Infra component Installer.
  4. Non-GPU Node Deployment and Installation:
    1. Deploy the Cisco IQ VA Installer. See Deploying VA on Hypervisor for more details.
    2. Install the downloaded modules via Package Catalog in the UI. See Modules and Rules Installation for more details.
  5. GPU Node Deployment and Installation:  
    1. Deploy the Cisco IQ VA Installer for GPU Node. See Deploying VA on Hypervisor for more details.
    2. Install the GPU Node as a Supplemental Node.  See Multi Node Support for detailed steps. 
  6. Once deployed, log in to the Cisco IQ VA UI.
  7. Install the downloaded modules and AI Inference Infrastructure by navigating to System Settings > Package Management. See AI-Powered Features in the Operations Guide for more details.
  8. Install any additional downloaded modules by navigating to System Settings > Package Management. See Adding Modules in Operations Guide for more details.

Once these steps are complete, Cisco IQ VA is ready for use with full AI support.

To learn more about enabling AI Inference powered features, see the Operations Guide.

Deploying VA on Hypervisor

This section outlines the deployment procedures for Cisco IQ VA. The current scope covered in the following sections includes instructions for the following hypervisors:

  • VMware ESXi
  • Microsoft Hyper-V Server
  • Red Hat KVM

Downloading a VA

VA installer files are available to be downloaded from Cisco IQ SaaS. To download VA:

  1. Log in to Cisco IQ (SaaS). For information on onboarding to the Cisco IQ SaaS portal, see the Cisco IQ Getting Started Guide.
  2. Navigate to Home > System Settings > Package Catalog. See the Cisco IQ Getting Started Guide for more information on Package Catalog.
  3. From the Cisco IQ Virtual Appliance card, choose Download options. The install package window opens.
  4. Select one of the following Hypervisor options from the drop-down list:
    • ESXi: for VMware ESXi
    • Hyper-V: for Microsoft Hyper-V
    • KVM: for Linux Kernel-based Virtual Machine (KVM)
  5. Select a Version from the drop-down list.
  6. Click Download to save the file locally.
note-icon

Note: Installation files are large (20-25 GB); ensure you have sufficient disk space before downloading.

Deploying VA on VMware ESXi

The downloaded VA installer file is ready to be installed. To install VA on VMware ESXi:

note-icon

Note: The OVA must be deployed using VMware vCenter and cannot be directly deployed on ESXi servers.

  1. Log in to VMware vSphere Web Client with administrator credentials.
  2. Right-click on the appropriate vCenter object (data center, cluster, or ESXi host) and choose Deploy OVF Template.
  3. On the Deploy OVF Template wizard, choose the template page, specify the source location, and click Next. You can specify a URL or browse to any accessible location.
  4. On the OVF Template Details page, verify the OVF template details and click Next. No input is necessary.
  5. On the Select a name and location page, add or edit the Name and Location for the VA and click Next.
  6. On the Select a resource page, choose the specific Host (ESXi host), Cluster, or Resource Pool on which you want to deploy and click Next.
    note-icon

    Note: Each VM must be assigned to a specific host on clusters that are configured with vSphere High Availability (HA) or Manual mode vSphere Distributed Resource Scheduler (DRS).

  7. On the Review details page, verify the OVA template details and click Next.
  8. On the Configuration page, choose a deployment configuration and click Next.
  9. On the Select storage page, choose the destination storage location for the VM files in the selected ESXi host and click Next.
  10. Choose the Disk Format for the VM virtual disks.
    note-icon

    Note: It is recommended to use thick provisioning. While it is possible to use thin provisioning, over-commitment of storage can lead to a lack of storage capacity resulting in degradation and loss of service.

  11. On the Select networks page, choose a source network and map it to a destination network and click Next.
  12. On the Ready to Complete page, select Power On After Deployment and click Finish.
  13. Ensure that VMs are configured with the following additional settings by right-clicking the desired VM in VMware ESXi and clicking Edit Settings.
    • CPU: Select Low from the first Shares drop-down list
    • Memory: Check the Reserve all guest memory (All locked) check box
    • Set CPU and RAM based on your scale size; see Hardware and VM Resource Requirements for more information
  14. In VMware ESXi, select the desired VM.
  15. Click the Summary tab.
  16. Click the displayed image or the Launch Console icon to launch the console.
  17. See Network Configuration for next steps.

Deploying VA on Microsoft Hyper-V Server

To install VA on Hyper-V:

  1. Log in to Hyper-V Server Manager with administrator credentials.
  2. Extract the VA package to the location defined by the Hyper-V Administrator to store all the virtual hard disks.
  3. Verify that all the disks from the original Cisco IQ .tar.gz are in the Virtual Hard Disks folder.
  4. From the Actions pane of Hyper-V Manager, choose New > Virtual Machine and click Next.
  5. Enter the Name you want to assign to the VA and click Next.
  6. Choose Generation 2 and click Next.
  7. Enter the memory value based on the recommended memory size in Hardware and VM Resource Requirements and click Next.
  8. Verify Use Dynamic Memory remains unchecked.
  9. Choose the appropriate network adapter for your VA and click Next.
  10. Add the provided VA virtual hard disk, ensuring disk one (1) is the first disk, and click Next.
note-icon

Note: The other two (2) virtual hard disks are added at a later step.

  1. Verify the selections in the Summary and click Finish. Hyper-V displays the newly created VA VM.
  2. Right click the VM and choose Settings.
  3. Under Security, uncheck the Enable Secure Boot check box.
  4. Add the other two (2) virtual hard disks to the VM by repeating the same steps used for adding the first hard disk.
  5. In the Advanced Features under the Network Adapter, verify that the Enable device naming is selected.
  6. Set the number of processors to the recommended vCPUs as listed in Hardware and VM Resource Requirements.
  7. In the Actions pane, select Start to power on the VM.
  8. In the Actions pane, select Connect to connect to the VM. The VM Connection console is displayed.
  9. See Network Configuration for more details.

Deploying VA on Red Hat KVM

Ensure that the following supported requirements are met before installing VA on KVM.

  • RHEL host OS
  • Administrative access on the Red Hat server

To install VA on a KVM Hypervisor, VM Manager is required.

  1. Log in to Red Hat host OS server with administrator credentials.
  2. Download and extract the VA package on the host.
  3. Launch the Virtual Machine Manager (VMM) client.
  4. Choose File > New Virtual Machine on the menu to install a new VA.
  5. Choose Import existing disk image and click Forward.
  6. Under Provide the existing storage path, click Browse.
  7. Create a new storage pool using the path where you extracted the VA package.
  8. Choose the first disk of the VA from the storage pool created on the previous step and click Choose Volume.
  9. Under Choose an operating system type and version, choose AlmaLinux 9, and click Forward.
  10. Under Choose Memory and CPU settings, enter details based on your scale size and click Forward. See Hardware and VM Resource Requirements for more details.
  11. In the dialog box, complete the following configuration:
    1. Under Ready to begin the installation, enter a Name for the VA instance.
    2. Click the Customize configuration before install option.
    3. Under Network selection, ensure that you select the appropriate virtual network.
  12. Click Finish to complete the addition of the first disk.
  13. Add the remaining two (2) disks:
    1. On the VMM console, click Add Hardware.
    2. Under Storage, ensure that the Select or create custom storage check box is checked and click Manage.
    3. Browse to select the second disk of the VA file that you extracted on your system.
    4. Click Choose volume.
  14. Repeat the same (Add Hardware) steps to add the third VA disk.
  15. Ensure all disk Bus Types are SCSI.
  16. Click Finish.
  17. Under the Overview section, choose UEFI for Firmware.
  18. Click Begin installation.
  19. See Network Configuration for next steps.

Network Configuration

  1. Launch VA from VM console.

Log InLog In

  1. Log in to the console using the default network credentials by entering “admin” for both the login name and password. The Configuration Settings displays.
note-icon

Note: The default credentials are provided for initial setup only as there is no data to protect at this stage of installation.

Configuration SettingsConfiguration Settings

  1. Enter “1” and press Enter to configure network settings.
  2. Provide the following network settings:
note-icon

Note: Users can press Enter to use detected values where available.

  • IP address
  • Gateway IP
  • DNS IP list
  • Search domain
  • NTP server list
note-icon

Note: Inputting multiple NTP servers using a comma-separated format is supported.

  1. Configure the NTP authentication by pressing N to proceed without an authentication method

OR

Press Y and enter the corresponding number of an option listed below:

  • Traditional key-based authentication: Uses provided credentials for secure time synchronization; after selecting this option, enter a valid algorithm and a hex key
  • Network Time Security (NTS): Uses the NTS protocol to provide secure NTP communication
note-icon

Note: NTP information can be validated in the UI after installation by navigating to System Settings.

NTP Validation in UINTP Validation in UI

  1. Enter and confirm a password after reviewing the on-screen password requirements.
  2. Review the summary and press Y to continue. Setup can take a few minutes.
  3. Once a success message is received, press Enter to return to the main menu.

Cisco IQ MenuCisco IQ Menu

Network settings are now configured, but VA has not yet been installed. It is recommended to return to hypervisor and take a Snapshot of the new VM for future reference. At this point, you can also initiate a Secure Shell connection using the newly configured IP address and credentials.

This completes manual configuration of VA.

Installing VA for Air-Gapped Mode

To install VA:

  1. Navigate to the VA installer web interface (https://<CIQ-HOST-FQDN>/installer/welcome) (received after configuring VA in VMs.). The Cisco IQ Virtual Appliance Installer page displays.Virtual Appliance Installer PageVirtual Appliance Installer Page
  2. Click Cisco IQ Virtual Appliance. The Install Cisco IQ Virtual Appliance page displays.
    Install Virtual ApplianceInstall Virtual Appliance
  3. Click Start. The Configure Internal Network tab displays.
    Configure Internal NetworkConfigure Internal Network
  4. Enter the Internal IP Range.
note-icon

Note: Ensure the internal subnet does not overlap with your VM IP, gateway, DNS, or reachable network ranges.

5. Click Next. The Installer Result page displays.

Installation ResultInstallation Result

6. Wait until all tasks displayed are complete. Upon successful completion, the browser automatically navigates to the Cisco IQ VA login page. The installation completion can take up to two (2) hours.

LoginLogin

Once successfully logged in, the system is ready to discover devices and supports the Assets application without AI support.

Modules and Rules Installation

To expand your system's capabilities, you can download additional modules and rules directly from the Cisco IQ SaaS portal and complete the installation in VA. See Installing Packages in Operations Guide for more details.

note-icon

Note: The Assets module is pre-installed in the VA installer, and available for immediate use. You can upgrade the asset module or asset rule version like any other module and rules as needed.

Multi-Node Support

The multi-node architecture allows you to expand a standalone VA for horizontal scalability and add on GPU support. The horizontal scalability helps with providing increased resource capacity for processing a higher number of supported devices and more module deployments. This configuration enables the addition of supplementary nodes to a primary management node, allowing the system to scale based on your specific workload requirements.

Enabling the multi-node capability is essential to add a GPU node. This integration allows the On-Prem environment to leverage GPU resources for AI inferencing. This section provides detailed guidance on connecting the GPU as a supplemental node for the On-Prem, which is necessary for users to utilize GPU capabilities effectively.

Network Requirements

VA supports a single network interface. 

Port Requirements

The following table outlines the network ports required for Cisco IQ VA communication in a multi-node environment.

Table 4: Port Requirements

Port(s)

Protocol

Description

Node Type

22

TCP

Used for Administrator CLI and Cisco Support debugging sessions

Management and supplementary nodes

443

TCP

Used for communication between Cisco IQ On-Prem and web browsers, as well as endpoint targets

Management and supplementary nodes

53, 123, 161

UDP

Used to send and receive DNS, NTP, and SNMP traffic

Management and supplementary nodes

10250, 10256

TCP

Used for Kubernetes communication between the node

Management and supplementary nodes

179

TCP

Used for VXLAN control plane (BGP) between nodes

Management and supplementary nodes

4789

UDP

Used for VXLAN traffic between nodes

Management and supplementary nodes

500, 4500

UDP

Used for IPSec IKE traffic between nodes

Management and supplementary nodes

All

ESP (50)

Used for IPSec ESP traffic between node

Management and supplementary nodes

6443

TCP

Used for Kubernetes API server

Management node only

note-icon

Note: Multi-node clustering is supported only for standard VA deployments.

note-icon

Note: A supplementary node must be the exact same version as the primary management node during the initial join process.

note-icon

Note: The current multi-node implementation does not provide High Availability (HA) for the management plane. If the primary management node becomes unavailable, cluster operations will be impacted.

Adding a Supplemental Node

Adding a supplementary node requires the same process as installing the VA. Once you have downloaded the VA installer from the Package Catalog in Cisco IQ (SaaS), install it on the chosen hypervisor. See Deploying VA on Hypervisor for more details. 
Before adding a supplementary node, ensure the first node is fully configured as a standard VA. To add a supplementary node:

  1. Navigate to System Configuration > Node Management.
  2. Verify that the primary node under Node column with successful status displays.
    Node ManagementNode Management
  3. Navigate to VA Installer. The following options display:
    • Cisco IQ Virtual Appliance
    • Supplemental Node
      Supplemental NodeSupplemental Node
  4. Click Supplemental Node option. The Supplemental Node Installer page displays.
    Supplemental Node PageSupplemental Node Page
  5. Enter Primary node FQDN.
  6. Enter Local admin username.
  7. Enter Password.
  8. Choose Node type from the drop-down list.
note-icon

Note: You can choose GPU worker node. When choosing GPU worker nodes, ensure your hypervisor environment (for example, VMware or Hyper-V) is configured with the necessary hardware to support GPU devices, as these are required for GPU node accessibility. See Deployment Options to learn more.

9. Click Add node. The "Supplemental node ready" message displays after successful node addition.

Supplemental Node ReadySupplemental Node Ready

10. Once “Supplemental node ready” displays, click the Visit System Management link or navigate to System Management > Node Management to trigger the add node action to complete the integration.

Add NodeAdd Node

11. Click More menu icon > Add Node. The Add GPU Node window displays.

Add GPU NodeAdd GPU Node

12. Click Add GPU Node. Once the node is successfully added, it displays in cluster.

Cluster Synchronization and Management

Upon adding a worker node, the administrative credentials of the primary management node automatically synchronize with the worker node. The access to the worker node must be performed using these synchronized credentials.

note-icon

Note: The cluster dynamically manages module distribution. When a module requires advanced processing capabilities, the system checks for the availability of GPU-enabled nodes. If a GPU worker is present and the appropriate module package is installed, the system enables these advanced features. If the cluster lacks the necessary hardware resources, the system will operate in a non-accelerated mode to maintain stability.

Support

You can create VA and module-specific support cases from Cisco IQ SaaS. The Support module is available in Cisco IQ SaaS and offers a consolidated view of your support cases. It enables you to filter, sort, and customize the case list view, providing visibility into both open and closed cases you are entitled to access. For more detailed information about the Support module in Cisco IQ SaaS, see the Cisco IQ SaaS Getting Started Guide.

note-icon

Note: Cisco IQ VA customers can access most Cisco IQ SaaS Support module features, including opening Technical Assistance Center (TAC) cases related to Cisco IQ VA and its modules, as well as creating and managing product cases.

Creating a Support Case

You can create VA and module-specific cases in Cisco IQ SaaS. To create a case:

  1. Log in to Cisco IQ (SaaS).
  2. Click the Help icon > Report an Issue. The Report an Issue window opens.

Report an IssueReport an Issue

  1. Provide the required details.
  2. Click Submit.