Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Data Security Posture Management (DSPM)
    Deploying DSPM Scanners (Sidecars)
    Standard Deployment (Single Appliance)
    Deploy the DSPM Single Appliance

    Deploy the DSPM Single Appliance

    Overview

    The DSPM Single Appliance bundles both the sidecar and DLP services into one virtual machine. This unified model simplifies deployment by reducing the process to a single image, a single CLI command, and a single License Key.

    This is the standard deployment path for most customers. After deployment, the appliance auto-registers with your Netskope tenant and automatically creates its sidecar pool. No manual pool creation, token management, or DLP appliance linking is required.

    For large-scale scanning scenarios that require deploying the DLP appliance and sidecars separately, see the dedicated standalone deployment instructions.

    To learn more: Deploy the DLP Appliance for DSPM.

    Prerequisites

    Before deploying the Single Appliance, ensure you meet the following requirements.

    • Network Planning: The Single Appliance must have outbound HTTPS (port 443) connectivity to the Netskope control plane. Ensure the appliance can reach:

      • Your tenant hostname (e.g., tenant.goskope.com)
      • config-tenant.goskope.com
      • callhome-tenant.goskope.com
      • The applicable gateway domains and Netskope IPs
    • Networking Considerations:

      • Ensure that Netskope IPs and Amazon S3 (e.g., *.s3-us-west-1.amazonaws.com) are allowlisted. If tenant.goskope.com is your tenant hostname, also allow IPs for config-tenant.goskope.com and callhome-tenant.goskope.com.

      • You must also allowlist the following gateway domains:

        dlpappliancegw.sv5.goskope.com
        dlpappliancegw.bom3.goskope.com
        dlpappliancegw.am2.goskope.com
        dlpappliancegw.sjc1.goskope.com
        dlpappliancegw.fr4.goskope.com
        dlpappliancegw.ruh1.goskope.com
        dlpappliancegw.mel2.goskope.com
        dlpappliancegw.sjc2.goskope.com
        dlpappliancegw.zur2.goskope.com
        dlpappliancegw.lon3.goskope.com
        dlpappliancegw.sin2.goskope.com
        dlpappliancegw.dfw3.goskope.com
        dlpappliancegw.fra2.goskope.com
        – If you use DRM with DLP, you must also allowlist Microsoft AIP endpoints.
        – All integrating services must be able to reach the appliance over HTTPS (TCP 443).
        – SSL interception of traffic from the DLP appliance isn’t recommended. If a proxy is in place, ensure you import the respective certificates.
        – Deploying multiple DLP appliances behind a network load balancer isn’t supported for asynchronous request scenarios.

        For the complete list of egress and port requirements, see Firewall Settings for DSPM-Hosted Instances.
    • Appliance Sizing: Unless recommended otherwise, deploy a Medium-sized appliance. The Small size is intended only for proof-of-concept testing.

       AWSGCPAzureVM (ESXi/Hyper-V/KVM)Concurrent RequestsMin Disk
      Smallc5ad.4xlargen2-standard-16Standard-F16s_v216 cores / 32 GB480 rps (burst 576)351 GB
      Mediumc5ad.8xlargen2-standard-32Standard-F32s_v232 cores / 64 GB1280 rps (burst 1536)351 GB
      Largec5ad.16xlargen2-standard-64Standard-F64fs_v264 cores / 128 GB2880 rps (burst 3456)351 GB

      In AWS regions where c5ad is unavailable, use c5a. To ensure optimal performance, use SSDs for all instances. ESXi does not support dynamic resizing after creation.

      If you deploy an incorrectly-sized appliance, the Single Appliance doesn’t support scaling resources up or down. You must redeploy at the correct size.

    Deployment Process

    The following steps outline the end-to-end process to retrieve the License Key, download the appliance image, and connect it to your DSPM environment.

    Step 1: Retrieve the License Key

    The appliance setup uses the License Key to validate your DLP entitlement. The Netskope console generates it automatically.

    1. Log in to the Netskope console.
    2. Navigate to DSPM > Administration > Sidecar.
    3. Copy the License Key value displayed on this screen.

    Step 2: Download the Single Appliance Image

    The download method depends on your target deployment platform. Use the wizard in the DSPM UI to assign or download the image.

    1. Go to DSPM > Administration > Sidecar.
    2. Click + ADD SINGLE APPLIANCE. The wizard opens with three steps: Platform > Assign / Download > Deployment.
      • Note: Current Single Appliance Information displays at the top of the wizard, including DLP Version, Sidecar Version, Image Size, and Release Date.
    3. Select your target platform. The wizard adapts based on your selection:

    For AWS (AMI):

    1. Select AMI.
    2. Click Assign.
    3. Enter your Account ID and select the Region.
    4. Click Submit.
    The AMI becomes available within the “Shared with me” section of your AMI Catalog within a few minutes.

    For Azure (VM Image):

    1. Select VM Image.
    2. Click Download.
    3. Copy the SHA-1 hash for verification.
    4. Download the image file.

    For ESXi:

    1. Select ESXi.
    2. Click Download.
    3. Copy the SHA-1 hash for verification.
    4. Download the .ova file.

    For GCP (Machine Image):

    1. Select Machine Image.
    2. Click Assign.
    3. Enter your Account ID and select the Region.
    4. Click Submit.
    The Machine Image becomes available within your GCP project within a few minutes.

    For Hyper-V:

    1. Select Hyper-V Image.
    2. Click Download.
    3. Copy the SHA-1 hash for verification.
    4. Download the image file.

    For KVM:

    1. Select KVM Image.
    2. Click Download.
    3. Copy the SHA-1 hash for verification.
    4. Download the QCOW2 image file.

    Step 3: Deploy the Single Appliance

    Follow the instructions below for your chosen platform to create the virtual machine instance using the image you assigned or downloaded in Step 2.

    After you deploy the appliance, an initialization process begins. The appliance takes 45 to 60 minutes to initialize, depending on network and system conditions. During this time, the appliance downloads and deploys the required components. After initialization completes, you can connect and tether the appliance.

    AWS:

    1. Go to the EC2 console and click Launch Instance.
    2. Under AMI, find the Single Appliance image in My AMIs > Shared with me.
    3. Set the Instance Type per the sizing table in Prerequisites.
    4. Set Storage to a minimum of 351 GB using gp3.
    5. No SSH key-pair is required. Configure networking and security groups as appropriate. The appliance should not be publicly accessible.
    6. Select proceed with no key-pair and launch the instance.

    Azure:

    During deployment, Azure may display an “OS Provisioning Timed Out” notification. This is expected and you can safely ignore it. Verify the instance state shows “Running” to confirm readiness.

    1. Extract the VHD from the downloaded file:
      tar -xvf {downloaded_vhd_tar_file} -C {path}
    2. Create a Storage Account under your Resource Group.
    3. Create a Container under the Storage Account.
    4. On the Storage Account page, go to Security + Networking > Shared access signature.
    5. Enable all permissions, set Start Time 24h before now and End Time 24h after now.
    6. Click Generate SAS and connection string and copy the SAS token.
    7. Install AzCopy if not already installed.
      • Note: Use AzCopy to upload. Uploading large files via the Azure Portal is unreliable and may result in file corruption.
    8. Upload the VHD:
      azcopy copy "{local_path}.vhd" "https://{account_name}.blob.core.windows.net/{container_name}/{vhd_name}.vhd?{SAS_TOKEN}" --blob-type PageBlob
    9. Go to Images in Azure.
    10. Choose your subscription > Set OS Type: Linux > Select your VHD from storage > Set Account Type: Premium SSD > Set Encryption: Platform managed.
    11. Click Review + create.
    12. Create an instance from the image. Select a minimum of 351 GB Premium SSD disk.
    13. Configure networking and create the VM.

    vSphere (ESXi):

    Download the .ova image to your local system before uploading to vSphere (vSphere does not support direct URL imports when the URL exceeds its maximum supported length).

    1. Right-click a host, cluster, or datacenter and select Deploy OVF Template.
    2. Select Local file > Upload files, choose your .ova file, click Next.
    3. Enter a VM name, select deployment location, click Next.
    4. Select compute resource, click Next.
    5. Review details and accept license agreements, click Next.
    6. Select datastore and virtual disk format (e.g., Thin Provision), click Next.
    7. Map source networks to destination network ports, click Next.
    8. Customize template settings if applicable, click Next.
    9. Review summary, optionally check Power on after deployment, click Finish.

    GCP:

    1. Go to Compute Engine > VM Instances and click Create Instance.
    2. In Machine Configuration, provide a name and select N2 under General Purpose.
    3. In Machine Type, select per the sizing table in Prerequisites.
    4. In OS and Storage, click Change, select the Single Appliance image shared to your project, and set size to 351 GB minimum.
    5. Configure networking and security groups as appropriate, then click Create.

    Hyper-V:

    1. Open Hyper-V Manager.
    2. In the Actions pane, click Import Virtual Machine.
    3. Click Next, then Browse to the top-level folder of the exported VM files. Click Select Folder > Next.
    4. Select the VM from the list, click Next.
    5. Choose Register the virtual machine in-place (use the existing unique ID).
    6. Review and click Finish.
    7. Before starting the instance, right-click the VM > Settings > Network Adapter and select the appropriate network switch.
    8. Start the VM from the Actions pane or by right-clicking > Start.

    KVM:

    1. Create a template directory and extract:
      mkdir single-appliance-template
      tar -xvf single-appliance.tar
    2. Extract the QCOW2 disk image:
      tar -xzvf netskope-single-appliance-kvm-qcow2-*.qcow2.tar.gz -C /home/ubuntu/single-appliance-template/
    3. Deploy using virt-install:
      sudo virt-install --name single-appliance --ram 65536 --vcpus 32 --os-variant ubuntu24.04 --disk path=/home/ubuntu/single-appliance-template/<image_file>.qcow2,size=452 --import --network default --check path_in_use=off
    4. When virt-install connects the console, press CTRL+C to exit. The boot process continues in the background.
    5. Verify VM status: sudo virsh list --all
    6. Check network: sudo virsh net-list
    7. Find IP address: sudo virsh net-dhcp-leases default
    8. Connect via SSH: sudo ssh nsadmin@{IP}

    Step 4: Connect and Tether the Appliance

    Once you create the instance, connect it to Netskope so it can download the required configuration and profiles.

    If you SSH into the appliance before initialization completes, the appliance displays “Initialization is in progress.” Disconnect and wait at least 15 minutes before trying again. Allow a few minutes between each subsequent attempt until the appliance displays the persona selection screen.
    1. SSH into the instance as nsadmin with the default password nsappliance:

      ssh nsadmin@<instance_ip>
    2. Select the appliance persona. On first login, the appliance displays a persona selection wizard. Select DSPM to configure the appliance as a Single Appliance (DLP + sidecar combined).

      This selection appears only once and can’t be changed after confirmation. The alternative option, DLP, configures the appliance as a standalone DLP appliance for use with separate sidecars.

      Wait for the initialization to complete. After you select DSPM, the appliance installs the sidecar components.

    3. Change the default password immediately:

      nsappliance> auth change-password
    4. Configure DNS (if DNS is not provided via DHCP):

      nsappliance> configure
      nsappliance(config)> set dns primary x.x.x.x
      nsappliance(config)> set dns secondary x.x.x.x
      nsappliance(config)> save
      nsappliance(config)> exit
      • If you need to configure the network interface manually instead of using DHCP:

        nsappliance> configure
        nsappliance(config)> set interface v4 dhcp enable false
        nsappliance(config)> set interface v4 static enable true
        nsappliance(config)> set interface v4 static ip x.x.x.x
        nsappliance(config)> set interface v4 static gw x.x.x.x
        nsappliance(config)> set interface v4 static netmask x.x.x.x
        nsappliance(config)> set dns primary x.x.x.x
        nsappliance(config)> set dns secondary x.x.x.x
        nsappliance(config)> save
        nsappliance(config)> exit
      • To revert to automatic DHCP configuration:

        nsappliance> configure
        nsappliance(config)> set interface v4 dhcp enable true
        nsappliance(config)> set dns primary x.x.x.x
        nsappliance(config)> set dns secondary x.x.x.x
        nsappliance(config)> save
        nsappliance(config)> exit

      Ensure that DNS resolution works on the appliance before proceeding.

    5. Ensure you have a REST API v1 token. If you already have one, skip to the next step. To generate a token, go to Settings > Tools > Rest API v1 and click Generate New Token.

    6. Apply the License Key you retrieved in Step 1:

      nsappliance> configure
      nsappliance(config)# set system licensekey <license-key>
      nsappliance(config)# save
      nsappliance(config)# exit
    7. Verify tethering status. The value callhome_reachable must be true, and tenant-url and serial should be populated:

      nsappliance> status tethering
      The value for callhome_reachable must be true, and tenant-url and serial should populate
    8. Return to the DSPM UI wizard (Step 3: Deployment), confirm the License Key matches the one you applied, and click Done.

    After successful tethering, the appliance completes initialization and begins processing requests. Initialization time may be shorter on on-premises platforms such as ESXi. A sidecar pool is automatically created and appears in DSPM > Administration > Sidecar. For details on managing your sidecar pool, see DSPM Sidecar Administration Overview.

    Step 5: Configure a Proxy (Optional)

    If your organization routes outbound traffic through a proxy, configure it using the appliance CLI.

    Explicit proxy
    Implicit proxy (SSL-intercepting proxy with custom CA)
    1. Configure the proxy details:

      nsappliance> configure
      nsappliance(config)# set management-plane upstream-proxy-server hostname 10.10.10.10
      nsappliance(config)# set management-plane upstream-proxy-server port 8000
      nsappliance(config)# set management-plane upstream-proxy-server username <USERNAME>
      nsappliance(config)# set management-plane upstream-proxy-server password <PASSWORD>
      nsappliance(config)# set management-plane upstream-proxy-server trusted-ca
    2. Copy and paste your single PEM-formatted server CA certificate (no keys).

    3. Press Ctrl-D when done.

    4. Save and restart:

      nsappliance(config)# save
      nsappliance(config)# exit
      nsappliance> restart dlpaas all
    1. Configure the trusted CA:

      nsappliance> configure
      nsappliance(config)# set management-plane upstream-proxy-server trusted-ca
    2. Copy and paste your single PEM-formatted server CA certificate (no keys).

      <PASTE PEM Formatted CA CHAIN>
    3. Press Ctrl-D when done.

      <Press Ctrl-D>
    4. Save and restart:

      nsappliance(config)# save
      nsappliance(config)# exit
      nsappliance> restart dlpaas all

    Step 6: Configure the Upgrade Schedule

    After deployment, configure the automatic upgrade schedule for your Single Appliance.

    1. Go to DSPM > Administration > Sidecar.
    2. Click the auto-generated pool name.
    3. In the pool details panel, click Edit Schedule.
    4. Choose when to apply upgrades after release (Within the first week after release, Within the second week after release, or Within the third week after release).
    5. Select the day of the week and start time (in the appliance’s local timezone).
    6. Click Save Schedule.
    To trigger an immediate upgrade, click Upgrade Now in the pool details panel.

    If you encounter issues during or after deployment, see Troubleshooting DSPM with DLP.

    In this Topic
    • Deploy the DSPM Single Appliance