Packet Capture 6.1.1 Release Notes

Prev Next

Last Updated: September 17, 2023     ........................................

Announcements

This document provides an overview of the new features and changes in the Trellix Packet Capture 6.1.1 release, including any new commands, resolved issues, and known issues.

Every update release is cumulative and includes all features and fixes from the previous release. The Trellix quality assurance process includes continuous security testing. Trellix recommends updating all products with the latest release as soon as possible.

Product compatibility

This Packet Capture release is compatible with Investigation Analysis release 2.1 or newer.

You can upgrade your Packet Capture appliance to Release 6.1.1 from Release 6.1.0. For upgrade instructions, see the Packet Capture System Administration Guide.

New features and changes

This section describes new features in the Trellix Packet Capture release 6.1.1.

Support to store PCAPs in compressed format

Presently, PX stores all the captured frames as is on the CAPTURE volume (/data/px/capture). Since CAPTURE volume stores all the received frames, its size is directly proportional to the amount of data received. This limits the amount of data stored on the disk.

The PCAP Compression feature enables you to configure PX to store PCAPs in a compressed format. This reduces the storage cost, allows you to store large amounts of data, and improves the performance of the PX appliance.

Support to expand storage for vPX

Support has been provided for expanding the storage on virtual PX. New disks can be added without losing any data present on the PX appliance.

Important

For more information on configuring these features, see the Packet Capture System Administration Guide.

Resolved issues

The following issues were resolved in the Packet Capture 6.1.1 release.

Tracking number

Summary

NETF-6414

PX capture failed with the message "range end index 518 out of range for slice of length 517". This issue is resolved.


Known issues

The following issues are known in the Packet Capture 6.1.1 release.

Tracking number

Summary

NETF-5907

For x6xx PX hardware models, the dropped packet count per port is not shown on the capture page where the capture speed per port is shown. The total drop count is shown in the "NIC drops" field in the footer.

NETF-5424

After upgrading an AWS PX to 6.1, the cloud-init service may issue warnings during the boot process. These are innocuous and can safely be ignored.

NETF-5371

When an appliance first sees a NIC, it determines the name of the interface and saves that information to a database for future boots. Replacing a network card or reconfiguring virtual interfaces will assign new numbers to the interfaces. The original interface numbers will remain on the appliance although they are no longer applicable.

NETF-5349

Azure deployments require two network interfaces to be created before software is installed, one for management and another for packet capture. This software version does not support changes to network interfaces after installation.

NETF-4481

Authentication using CAC/PIV requires any uploaded CRL to be in PEM format. No other formats are supported.

NETF-4255

Restoration of headers on an encrypted storage device does not restore passphrases. For security, these items are kept separate and must be installed in two steps.

NETF-6434

Storage update command fails on PX devices that have disk encryption enabled.