Overview
The Netskope DSPM (also known as Netskope One DSPM) application requires seamless connectivity to scan your data stores. However, as per common security practices, businesses tend to deny proper firewall egress between their internal networks and external applications. Such limitations impact the operational use of Netskope DSPM and reduce the full return value of your subscription.
To overcome this, Netskope DSPM provides a flexible collection architecture consisting of one or many sidecars you can deploy alongside your data stores. These sidecars collect necessary metadata and transfer it to the Netskope DSPM application. Within this central management console, you can take action on insights from across all data stores regardless of where they are hosted.
Prerequisites
Ensure you meet the following requirements:
- Netskope DSPM Tenant: You will need a Netskope DSPM-hosted tenant to receive the sidecar-collected metadata.
- Sidecar AMI: The Netskope DSPM sidecar AMI needs to be shared with your organization. Contact your CSM to request this AMI and supply:
- Your AWS account number.
- The AWS region where you will deploy the instance.
- Required Toolsets: Validate that you are running the latest versions of the following tools in your terminal:
terraform --version(Ver 1.3.2 or higher)aws --version(Ver 2.8.2 or higher)git --version(Ver 2.38.x or higher)
- DLP Appliance Connectivity: Sidecars require connectivity to a local DLP appliance to perform classification activities using your DLP Profiles and Rules. Before deploying the sidecar, ensure the following:
- A DLP appliance has been deployed and is accessible within the same network where the sidecar will be installed (or in directly connected networks, to avoid additional peering or complex routing).
- The sidecar and DLP appliance must be able to communicate via HTTPS (port 443).
- You have generated or obtained the required REST API v1 Key and License Key.
Architecture
Netskope DSPM uses a flexible architecture where you deploy one or more sidecars alongside your main application. These sidecars connect directly to your data stores to collect samples, which a local DLP appliance then scans. Afterward, the sidecars upload the classification results back to the Netskope DSPM application.
A single sidecar can efficiently scan multiple data stores within its installed environment. Although you typically deploy one sidecar per isolated network (such as a VPC or VNet), you can install multiple sidecars to achieve higher scalability and redundancy. In these highly available setups, the Netskope DSPM application automatically load-balances scan operations across all healthy sidecars within a given pool.
The following diagram illustrates the relationship between Netskope DSPM resources and your environment:

Configure Outbound Egress
Since Netskope hosts and manages the Netskope DSPM application, you must update your firewall or security group settings to allow outbound egress. Configure your allowlist on port 443 using the following group.
-
Required for Core Connectivity: Add these addresses to ensure the sidecar can communicate with the DSPM platform. Substitute
[TENANT]with your actual tenant name:Address [TENANT].goskope.comsidecar-[tenant].goskope.comnetskope-dspm-release.s3.us-west-2.amazonaws.com995750983908.dkr.ecr.us-west-2.amazonaws.com
Configure Sidecar Pool
To set up the relationship between your sidecars and Netskope DSPM-hosted tenant, you will provide the sidecars with unique authentication tokens generated within our Sidecar Administration UI.
-
Log in to the Netskope DSPM application.
-
Go to the Administration > Sidecar menu.
-
Click Add Sidecar Pool.
-
On the Details tab, complete the following field:
Field Value Name Any friendly value to describe the sidecar pool. -
Click Save.
-
Click Copy at the bottom of the Sidecar Authentication Token modal to save the generated token to your clipboard.
-
Click the X button to exit the modal.
Since you haven’t yet associated this token with a sidecar, the sidecar pool will appear only when you click the Show Inactive Sidecars icon in the upper right, with empty Version, Status, and DLP Status columns for now.
Setting up the AWS Configuration
-
At the terminal prompt or command shell type
aws configureand provide the inputs as below:AWS Access Key ID : AWS Secret Access Key : Default region name [us-west-2]: Default output format [json]:
Note that your AWS CLI should be referenced in the PATH variable.
-
Copy the following URL in your browser window to download the requisite Terraform scripts:
https://netskope-dspm-release.s3.us-west-2.amazonaws.com/aws-sidecarFromAMI-dlp.zip
-
Extract the Netskope DSPM Terraform scripts in your local system folder. This will create a new folder (e.g.,
aws-sidecarFromAMI) containing several configuration files (likemain.tf,variables.tf, etc.).
Running the Terraform Script
-
Go to the folder created from the extraction above (e.g.,
cd aws-sidecarFromAMI). -
From that directory, run the following command to initiate your Terraform environment successfully:
terraform init
If your initialization is successful, you would see a message like “Terraform has been successfully initialized!” -
To validate that you have all the pre-requisites configuration details available for the installation, run the following command:
terraform plan
-
When prompted, enter the following variables:
If any of these details are not available with you or you receive an error, revisit the Prerequisites section at the start of the document before continuing further.Parameter Value ami_id AMI ID of the Netskope DSPM sidecar image shared with your organization. This value can be found in your AMI Catalog in the My AMIs section. Clear all filters and filter by Owner = “Shared With Me”. host_security_group_ids Your own AWS security groups that you wish to associate. Use [ ]and double-quotes to surround the groups.
Please ensure the security groups belong to the same network as the subnet you will launch the Netskope DSPM sidecar, otherwise deployment will fail.host_subnet_id This is the subnet to launch the Netskope DSPM sidecar. This will determine the VPC and availability zone of the sidecar. key_name Name of the SSH key you wish to install on the sidecar.
Installing patches and security updates requires an admin to connect to the sidecar via SSH. If this is pre-configured you can select the same from the drop down list; otherwise, please configure a new key pair within the AWS EC2 Console.dasera_host Your tenant URL minus the protocol.
For example, if your tenant is accessed usinghttps://example.goskope.com, your value will beexample.goskope.com.instance_type The EC2 instance type you wish to deploy for the sidecar. Netskope's standard recommendation is to use m5.2xlargeunless advised differently by your account team.sidecar_token An existing sidecar token, or a new one generated in the Register Sidecar section above. -
To initiate the Terraform installation, run the following command from the same directory :
terraform apply
The script will begin and perform the following actions:
- Prompt you to input. Provide the same set of 6 configuration details in sequence as listed in the table above.
- Check for errors. In the event an error occurs, follow the on-screen instructions for correcting and resuming.
- Outputs a resource modification list. To learn more about the resources created by the script, please expand the section below.
- Prompt you to confirm before executing. To confirm you must type
yes.
When the script completes successfully and the AWS resources are provisioned correctly, the output will similar to the following example.Apply complete! Resources: 1 added, 0 changed, 1 destroyed. Outputs: ids = "i-0dc55679d6d318d76" ssh_ip = [ "XXX.XXX.XXX.XXX", ]
Resources Created
In the console output, the following resources are listed:
| Resource Type | Resource Name |
|---|---|
| AWS::EC2::Instance | netskope-dspm-sidecar |
When using Netskope’s recommendation instance type, each sidecar instance is deployed as a m5.2xlarge EC2 instance (equaling 8CPU/32GB).
Validate Sidecar Connection
When deploying sidecar, you’ll need to ensure that the sidecar has the ability to reach your tenant. Take the following steps to verify the connectivity from the sidecar.
- Log in to the Netskope DSPM application.
- Go to Administration > Sidecar.
- For the sidecar(s) in question, validate that:
- The Version column is populated.
- The Status indicator is green.
- The DLP Status column shows a healthy connection to your DLP appliance.
It may take a few minutes for newly-running sidecars to communicate with the Netskope DSPM application.

Rotating Sidecar Tokens
These instructions apply if your security practice requires regularly rotating security tokens, or if your sidecar is failing to communicate with the Netskope DSPM application due to an invalid token. These steps will be repeated for each individual sidecar within the sidecar pool.
Generate a New Token in Netskope DSPM
- Log in to your Netskope DSPM instance.
- Go to Administration > Sidecar to open the Sidecar Administration screen.
- For the sidecar pool registration whose token you wish to rotate, click the Generate New Token icon.
- The Generate New Token modal is displayed. Read and then click Confirm.
- Click Copy at the bottom of the Generate New Token modal to save the generated token to your clipboard.
- Close the modal.
Apply the New Token in AWS
-
Log in to the AWS EC2 Console. The EC2 dashboard is displayed.
-
In the left menu, go to the Instances > Instances screen. The Instances dashboard is displayed.
-
In the list of instances, click the Instance ID hyperlink corresponding to the Netskope One DSPM sidecar requiring the token update. The Instance Summary screen is displayed.
-
Click Connect. The Connect to instance screen is displayed.
-
Provide
ubuntuas the user name and press the Connect button to start a SSH session to the sidecar. -
The AWS CLI is displayed.
-
Enter the command
./tokenrotate.sh -
Follow the prompts to enter your new token
-
Enter the command
helm uninstall netskope -n netskopeto delete the existing Helm deployment -
Enter the command
./helm.shto redeploy Helm using the new token
Configure for an SSL Proxy Environment (Optional)
If your organization routes outbound traffic through an SSL proxy, you must perform the following steps to allow your sidecar to communicate with the Netskope DSPM platform.
-
Use an SSH client to connect to the sidecar’s IP address
-
In the Helm chart folder, open the
values.yamlfile. -
Add an entry at the bottom of the file for the
httpsProxyvalue eg.httpsProxy: https://192.168.1.17
-
Redeploy the Helm chart
When deployment is complete, your sidecar should immediately begin communicating via the designated proxy.
Next Steps: Link Sidecar to DLP Appliance
After deployment, you must link your newly deployed sidecar to a DLP appliance to enable data classification.
For detailed instructions, see Link a DLP Appliance to a Sidecar Pool.



