Packet Capture 6.1.0 Release Notes

Prev Next

Last Updated: August 1, 2024

Announcements

This document provides an overview of the new features and changes in the Trellix Packet Capture 6.1 release, including any new commands, resolved issues, and known issues.

Every update release is cumulative and includes all features and fixes from the previous release. The Trellix quality assurance process includes continuous security testing. Trellix recommends updating all products with the latest release as soon as possible.

Product compatibility

This Packet Capture release supports Investigation Analysis release 2.1 or newer.

Upgrade support

You can upgrade your Packet Capture appliance to 6.1 from release 6.0. You must upgrade your Investigation Analysis to 2.1.0 before upgrading your Packet Capture appliance to 6.1.0. For upgrade instructions, see the Packet Capture System Administration Guide.

New features and changes

This section describes new features in the Trellix Packet Capture release x.x.x.

Elasticsearch integration

You can now export Layer-7 metadata over HTTP to Elasticsearch. The filtering option enables you to filter the Layer-7 metadata that is exported to the Elasticsearch server. To configure the metadata export to Elasticsearch through the CLI, see the Packet Capture System Administration Guide.

Disk-mirroring on x600 appliances

Trellix x600 appliances ship with a secondary SSD installed, which enables you to have a more streamlined disaster-recovery plan. With the PX 6.1 release, You can perform disk mirroring to mirror files present on the primary SSD to the secondary SSD at any point of time. Disk mirroring enables you to use the secondary SSD as a fallback operating system drive. To perform disk-mirroring, see the Packet Capture System Administration Guide.

Configuration of real-time file extraction through CLI

You can now configure real-time file extraction through the CLI. To configure the real-time file extraction through the CLI, see the Packet Capture System Administration Guide.

Automatic download and update of emerging-threats rules in Suricata

This feature enables automatic download and periodic update of emerging-threat rules in Suricata. For more information, see the Packet Capture System Administration Guide.

Suricata Upgrade

Suricata has been upgraded to 6.0.8. This version supports the following:

  • HTTP 2.0 traffic parsing.

  • Two new protocols — MQTT and RFB. Metadata is generated for these protocols.

Metadata export statistics

You can now obtain the statistics of your appliance's metadata exports to SIEM tools such as Splunk and Elasticsearch. To obtain the statistics of the configured metadata exports using the CLI, see the Packet Capture System Administration Guide.

Support to monitor all the capturing interfaces using SNMP

Improved SNMP OIDs enable snmpwalk to query all the configured interfaces, thereby monitors all the capturing interfaces.

Role exceptions in SAML authentication

You can now add a "roles" filter in the SAML configuration that enables you to restrict SAML login for users with specific roles.

General Enhancements

  • You can now view the real-time file extraction stats using the CLI. For more information, see the Packet Capture System Administration Guide.

  • You can now view the charts for file extraction and export stats under the Trends page in the Web UI.

  • You can now configure the audit-logs export in the configure syslog menu in the CLI.

  • jQuery has been upgraded to 3.5.1.

Resolved issues

The following issues were resolved in the Packet Capture 6.1 release.

Tracking number

Summary

NETF-6324

Temperature trends were not displayed on the Web UI. This issue has been resolved.            

NETF-6309

The appliance could not be accessed when AAA was set up using an incorrect server IP address or if a replacement unit already had AAA setup configured. This issue has been resolved.            

NETF-6308

Login issues with LDAP authentication were observed intermittently on the Packet Capture appliance. This issue has been resolved.            

NETF-6286

The Packet Capture feature did not work properly on the resized virtual Packet Capture appliances deployed on Azure. This issue has been resolved.            

NETF-6110

When the average packet-capture active sessions crossed 1 million, Suricata failed continuously. This issue has been resolved.            

Known issues

The following issues are known in the Packet Capture 6.1 release.

Tracking number

Summary

NETF-5907

For x6xx PX hardware models, the dropped packet count per port is not shown on the capture page where the capture speed per port is shown. The total drop count is shown in the "NIC drops" field in the footer.

NETF-5424

After upgrading an AWS PX to 6.1, the cloud-init service may issue warnings during the boot process. These are innocuous and can safely be ignored.

NETF-5371

When an appliance first sees a NIC, it determines the name of the interface and saves that information to a database for future boots. Replacing a network card or reconfiguring virtual interfaces will assign new numbers to the interfaces. The original interface numbers will remain on the appliance although they are no longer applicable.

NETF-5349

Azure deployments require two network interfaces to be created before software is installed, one for management and another for packet capture. This software version does not support changes to network interfaces after installation.

NETF-4481

Authentication using CAC/PIV requires any uploaded CRL to be in PEM format. No other formats are supported.

NETF-4255

Restoration of headers on an encrypted storage device does not restore passphrases. For security, these items are kept separate and must be installed in two steps.


Technical support

For technical support, contact Trellix through the Support portal: https://www.trellix.com/en-us/support.html