New Features and changes
This section describes new features and changes in the Trellix PX release 6.3.0.
Support credit card data redaction
Credit Card Data Redaction identifies and redacts sensitive credit card information from raw packet data. The feature, when enabled on the appliance, scans raw packet data to identify sensitive credit card information, such as the credit card number, cardholder name, CVV, and expiration date. Upon detecting credit card details, it ensures that the information is redacted and not stored in the packet capture.
Resolved issues
The following issues were resolved in the Packet Capture 6.3.0 release.
Tracking number | Summary |
|---|---|
NETF-6675 | Addresses an issue in PX 6.2.0 (5600PX-HW) where the system frequently ran into "Out of Memory" errors, causing px-capture to restart unexpectedly. |
NETF-6673 | Fixes an issue where the Suricata service was not running intermittently. |
NETF-6670 | Fixes suricata parsing issue for tunnel packets and tacplus packets |
NETF-6669 | Packet Capture has been updated to extract Gmail IDs from HTTP traffic. This extracted data is then exported as a new field to IA (Information Architecture). With this enhancement, you are now able to search for Gmail IDs directly within IA. |
NETF-6667 | Fixes an issue where SNMP requests were unexpectedly altering the OID (Object Identifier) during queries. Previously, SNMP requests were designed to query the same OID consistently. However, in some Packet Capture devices, the OID would change unpredictably. |
NETF-6666 | Fixes an issue where no data was displayed in the "System" tab for filters like one hour, one day, week, and month. |
NETF-6665 | Fixes sysdump generation issue by closing unnecessary connections to postgres DB by ipmanager |
NETF-6663 | Fixes an issue where the ssl handshake was failing between HelixEndpoint Security (HX) and Packet Capture |
NETF-6657 | Fixes an issue where upgrades for Packet Capture were intermittently failing. This fix also resolves any potential upgrade failures occuring from RPM database corruption. |
Known issues
The following issues are known in the Packet Capture 6.3.0 release.
Tracking number | Summary |
|---|---|
NETF-6434 | Storage update command fails on PX devices that have disk encryption enabled. |
NETF-5907 | For x6xx PX hardware models, the dropped packet count per port is not shown on the capture page where the capture speed per port is shown. The total drop count is shown in the "NIC drops" field in the footer. |
NETF-5424 | After upgrading an AWS PX to 6.1, the cloud-init service may issue warnings during the boot process. These are innocuous and can safely be ignored. |
NETF-5371 | When an appliance first sees a NIC, it determines the name of the interface and saves that information to a database for future boots. Replacing a network card or reconfiguring virtual interfaces will assign new numbers to the interfaces. The original interface numbers will remain on the appliance although they are no longer applicable. |
NETF-5349 | Azure deployments require two network interfaces to be created before software is installed, one for management and another for packet capture. This software version does not support changes to network interfaces after installation. |
NETF-4481 | Authentication using CAC/PIV requires any uploaded CRL to be in PEM format. No other formats are supported. |
NETF-4255 | Restoration of headers on an encrypted storage device does not restore passphrases. For security, these items are kept separate and must be installed in two steps. |
Upgrade support
You can upgrade your Packet Capture appliance to release 6.3.0 from release 6.2 and later.
Important
Upgrades to Packet Capture release 6.3.0 is no longer supported for the following appliances.
PX 1020EXT-10
PX 1020EXT-20
PX 2004ESS-24
PX 2020ESS-24
PX 004S
PX 1004ESS-16
PX 1020ESS-16
PX 2000SX-24
PX 2000SX-48
PX 2004ESS-48
PX 2020ESS-48
PX 2040ESS-48
PX 4000SX-264 - JBOD