Packet Capture 6.3.0 Release Notes

Prev Next

New Features and changes

This section describes new features and changes in the Trellix PX release 6.3.0.

  • Support credit card data redaction

Credit Card Data Redaction identifies and redacts sensitive credit card information from raw packet data. The feature, when enabled on the appliance, scans raw packet data to identify sensitive credit card information, such as the credit card number, cardholder name, CVV, and expiration date. Upon detecting credit card details, it ensures that the information is redacted and not stored in the packet capture.

Resolved issues

The following issues were resolved in the Packet Capture 6.3.0 release.

Tracking number

Summary

NETF-6675

Addresses an issue in PX 6.2.0 (5600PX-HW) where the system frequently ran into "Out of Memory" errors, causing px-capture to restart unexpectedly.

NETF-6673

Fixes an issue where the Suricata service was not running intermittently.

NETF-6670

Fixes suricata parsing issue for tunnel packets and tacplus packets

NETF-6669

Packet Capture has been updated to extract Gmail IDs from HTTP traffic. This extracted data is then exported as a new field to IA (Information Architecture). With this enhancement, you are now able to search for Gmail IDs directly within IA.

NETF-6667

Fixes an issue where SNMP requests were unexpectedly altering the OID (Object Identifier) during queries. Previously, SNMP requests were designed to query the same OID consistently. However, in some Packet Capture devices, the OID would change unpredictably.

NETF-6666

Fixes an issue where no data was displayed in the "System" tab for filters like one hour, one day, week, and month.

NETF-6665

Fixes sysdump generation issue by closing unnecessary connections to postgres DB by ipmanager

NETF-6663

Fixes an issue where the ssl handshake was failing between HelixEndpoint Security (HX) and Packet Capture

NETF-6657

Fixes an issue where upgrades for Packet Capture were intermittently failing. This fix also resolves any potential upgrade failures occuring from RPM database corruption.

Known issues

The following issues are known in the Packet Capture 6.3.0 release.

Tracking number

Summary

NETF-6434

Storage update command fails on PX devices that have disk encryption enabled.

NETF-5907

For x6xx PX hardware models, the dropped packet count per port is not shown on the capture page where the capture speed per port is shown. The total drop count is shown in the "NIC drops" field in the footer.

NETF-5424

After upgrading an AWS PX to 6.1, the cloud-init service may issue warnings during the boot process. These are innocuous and can safely be ignored.

NETF-5371

When an appliance first sees a NIC, it determines the name of the interface and saves that information to a database for future boots. Replacing a network card or reconfiguring virtual interfaces will assign new numbers to the interfaces. The original interface numbers will remain on the appliance although they are no longer applicable.

NETF-5349

Azure deployments require two network interfaces to be created before software is installed, one for management and another for packet capture. This software version does not support changes to network interfaces after installation.

NETF-4481

Authentication using CAC/PIV requires any uploaded CRL to be in PEM format. No other formats are supported.

NETF-4255

Restoration of headers on an encrypted storage device does not restore passphrases. For security, these items are kept separate and must be installed in two steps.

Upgrade support

You can upgrade your Packet Capture appliance to release 6.3.0 from release 6.2 and later.

Important

Upgrades to Packet Capture release 6.3.0 is no longer supported for the following appliances.

  • PX 1020EXT-10

  • PX 1020EXT-20

  • PX 2004ESS-24

  • PX 2020ESS-24

  • PX 004S

  • PX 1004ESS-16

  • PX 1020ESS-16

  • PX 2000SX-24

  • PX 2000SX-48

  • PX 2004ESS-48

  • PX 2020ESS-48

  • PX 2040ESS-48

  • PX 4000SX-264 - JBOD