Last Updated: September 17, 2023 ........................................
Announcements
This document provides an overview of the new features and changes in the Trellix Packet Capture 6.1.1 release, including any new commands, resolved issues, and known issues.
Every update release is cumulative and includes all features and fixes from the previous release. The Trellix quality assurance process includes continuous security testing. Trellix recommends updating all products with the latest release as soon as possible.
Product compatibility
This Packet Capture release is compatible with Investigation Analysis release 2.1 or newer.
You can upgrade your Packet Capture appliance to Release 6.1.1 from Release 6.1.0. For upgrade instructions, see the Packet Capture System Administration Guide.
New features and changes
This section describes new features in the Trellix Packet Capture release 6.1.1.
Support to store PCAPs in compressed format
Presently, PX stores all the captured frames as is on the CAPTURE volume (/data/px/capture). Since CAPTURE volume stores all the received frames, its size is directly proportional to the amount of data received. This limits the amount of data stored on the disk.
The PCAP Compression feature enables you to configure PX to store PCAPs in a compressed format. This reduces the storage cost, allows you to store large amounts of data, and improves the performance of the PX appliance.
Support to expand storage for vPX
Support has been provided for expanding the storage on virtual PX. New disks can be added without losing any data present on the PX appliance.
Important
For more information on configuring these features, see the Packet Capture System Administration Guide.
Resolved issues
The following issues were resolved in the Packet Capture 6.1.1 release.
Tracking number | Summary |
|---|---|
NETF-6414 | PX capture failed with the message "range end index 518 out of range for slice of length 517". This issue is resolved. |
Known issues
The following issues are known in the Packet Capture 6.1.1 release.
Tracking number | Summary |
|---|---|
NETF-5907 | For x6xx PX hardware models, the dropped packet count per port is not shown on the capture page where the capture speed per port is shown. The total drop count is shown in the "NIC drops" field in the footer. |
NETF-5424 | After upgrading an AWS PX to 6.1, the cloud-init service may issue warnings during the boot process. These are innocuous and can safely be ignored. |
NETF-5371 | When an appliance first sees a NIC, it determines the name of the interface and saves that information to a database for future boots. Replacing a network card or reconfiguring virtual interfaces will assign new numbers to the interfaces. The original interface numbers will remain on the appliance although they are no longer applicable. |
NETF-5349 | Azure deployments require two network interfaces to be created before software is installed, one for management and another for packet capture. This software version does not support changes to network interfaces after installation. |
NETF-4481 | Authentication using CAC/PIV requires any uploaded CRL to be in PEM format. No other formats are supported. |
NETF-4255 | Restoration of headers on an encrypted storage device does not restore passphrases. For security, these items are kept separate and must be installed in two steps. |
NETF-6434 | Storage update command fails on PX devices that have disk encryption enabled. |