Announcements
This document provides an overview of the new features and changes in the Trellix Packet Capture 6.0 release, including any new commands, resolved issues, and known issues.
Product Compatibility
Packet Capture Version Requirements
Your Packet Capture appliance must be running software version 5.2.0 to upgrade to version 6.0. See the Packet Capture System Administration Guide for upgrade instructions.
Investigation Analysis Compatibility
This release of the Packet Capture is compatible with Investigation Analysis release 2.0 or newer. If you have an Investigation Analysis that is version 1.6.0 or earlier, you must upgrade your IA to 2.0 before updating your PX to this release. See the Investigation Analysis System Administration Guide.
New features and changes
This section describes new features in the Trellix Packet Capture release 6.0.
SAML Authentication
You can now enable SAML authentication for the Web UI users of the Packet Capture appliance. To know more about SAML authentication, see the "Configuring SAML Authentication" section in the Packet Capture System Administration Guide.
Layer-7 Metadata Export to Splunk
You can now export Layer-7 metadata over HTTP to Splunk. You can filter the Layer 7 metadata that is exported to the Splunk server. To configure the metadata export to Splunk through the CLI and the API, see the Packet Capture System Administration Guide.
Real-Time File Extraction Using Suricata
The Packet Capture appliance can now selectively extract files from live traffic in real time using Suricata. The extracted files saved to the Packet Capture appliance disk are then submitted to configured third-party tools such as VirusTotal and ReversingLabs.
General Enhancements
The system dump file generated through the CLI can be located at
home/npscp/transfer/{sysdump-filename}and is now owned by the npscp user instead of the root user.You can now export syslogs to a Splunk server.
The logs corresponding to the searches executed on a Packet Capture appliance are logged in the syslog server, if one is configured.
You can use the links in the metadata of any selected event to download the PCAP data and to view the connection details of your Packet Capture appliance. To include these links in the metadata, you need to enable PCAP streaming url and PCAP view url options in the
px-eve-routeconfiguration menu in the CLI.You can now configure the Layer-7 metadata settings to filter out the streaming videos from the capture data generated on your Packet Capture appliance.
The Enable mode is added in the CLI. After you enter the enable mode, you can run any number of configuration commands without entering the password.
You can now configure login banner and motd through the CLI and API. For more information, see the Packet Capture System Administration Guide.
The newly added endpoint https://localhost/api/4.0/system/filesystem?filter=/var/dev returns the details of file system information such as total disk size and available storage for partitions on your Packet Capture appliance.
The SMCLI command output is added to the system dump file. This data helps you to identify any issues with the SAN storage connected to your Packet Capture appliance.
You can now add Suricata rules that use file hash values to generate metadata that matches the specified hash values. You can enable or disable the added file hashes in the Configure Suricata menu.
You can now configure metadata settings on the Packet Capture appliance to exclude metadata corresponding to the DNS events of whitelisted hostnames. For more information, see the Packet Capture System Administration Guide.
You can now reset the IPMI password through the following API endpoint: https://<PX_IP_address>:8666/api/4.0/config/ipmi-password.
You can now enable Community Flow ID generation in Suricata through the Packet Capture CLI and API.
You can now configure CLI inactivity timeout for the Packet Capture appliance in the ACM menu to terminate the SSH session after the specified duration.
Fixed Packet Capture Issues
The following issues were resolved in the Packet Capture 6.0 Release.
The relevant issue tracking numbers for each item are included in parentheses.
DTI did not work on the Packet Capture appliances enabled with proxy authentication. This issue has been fixed. (NETF-6255)
The Weak SSL/TLS Ciphers vulnerability CWE-326 has been fixed. (NETF-6244)
The default SNMP trap threshold values for system load were set to low values that resulted in traps triggered at the following loads: 15.6%, 14.06% and 12.5%. This issue has been fixed. (NETF-6235)
The SSH weak algorithm vulnerability CVE-2008-5161 has been fixed. (NETF-6229)
The vulnerabilities CVE-2020-11022 & CVE-2020-11023 have been fixed. (NETF-6201)
The NGINX version is upgraded to 1.20.1 and therefore CVE-2019-20372 vulnerability has been fixed. (NETF-6214)
The capture process did not start on instances deployed on Azure D8s v3 and D16s v3 models. This issue has been fixed. (NETF-6192)
An SNMP trap was not generated when a power supply unit (PSU) was removed from the Packet Capture appliance. This issue has been fixed. (NETF-6178)
The expiry of the Managed Defense VPN provisioning certificate, included in the Packet Capture appliance, disconnected Managed Defense from your Packet Capture appliance. This issue has been fixed. (NETF-6129)
The syslog configuration on a Packet Capture appliance did not log events in the timezone set for the Packet Capture appliance. This issue has been fixed. (NETF-6116)
For every successful login to a Packet Capture appliance configured with RADIUS authentication, the log messages captured an error message followed by success messages. This issue has been fixed. (NETF-6099)
The snmpget command showed "Wrong Type" output for the NPULSE-PX-MIB::captureDropsTotal and NPULSE-PX-MIB::captureSpeed.1 parameters. This issue has been fixed. (NETF-5953)
An "unknown file system" output was seen during the initial configuration of the Packet Capture appliance. This issue has been fixed. (NETF-5942)
The connection to the Investigation Analysis appliance dropped when the Packet Capture appliance's disk space was fully consumed because of a malformed TCP packet parsed by the OS fingerprinting module that is enabled by default. This issue has been fixed. (NETF-5937)
Fiberblaze enabled with 40G port now shows two ports on the Capture page on the Web UI. (NETF-5886)
The Intelligent Capture feature works as intended with the new Suricata implementation. (NETF-5709)
Thee Samba version has been upgraded to 4.9.1-10 to handle the vulnerabilities noticed in the earlier versions. (NETF-5694)
Known Packet Capture Issues
The following issues are known in Packet Capture release 6.0.
Note: The relevant issue tracking numbers for each item are included in parentheses.
The PX-capture process does not start on resized virtual Packet Capture appliances deployed on Azure. (NETF-6286)
For x6xx PX hardware models, the dropped packet count per port is not shown on the capture page where the capture speed per port is shown. The total drop count is shown in the "NIC drops" field in the footer. (NETF-5907)
After upgrading an AWS PX to 6.0, the cloud-init service may issue warnings during the boot process. These are innocuous and can safely be ignored. (NETF-5424)
Azure deployments assign SSH key access to the npadmin user. Assigning a password to the npadmin user is not supported. Additional users can be created with administrative privileges and password-based access if required. (NETF-5405)
When an appliance first sees a NIC, it determines the name of the interface and saves that information to a database for future boots. Replacing a network card or reconfiguring virtual interfaces will assign new numbers to the interfaces. The original interface numbers will remain on the appliance although they are no longer applicable. (NETF-5371)
Azure deployments require two network interfaces to be created before software is installed, one for management and another for packet capture. This software version does not support changes to network interfaces after installation. (NETF-5349)
Authentication using CAC/PIV requires any uploaded CRL to be in PEM format. No other formats are supported. (NETF-4481)
Restoration of headers on an encrypted storage device does not restore passphrases. For security, these items are kept separate and must be installed in two steps. (NETF-4255)
Technical Support
For technical support, contact Trellix through the Support portal: