Enable and configure packet capture rules.
ImportantThe packet capture feature in Network Security only supports Deep Discovery Inspector version 6.7 or later.
Packet capture increases processor and disk space usage on enabled
appliances.
Enabling packet capture requires the appliance to restart. Disabling packet
capture does not require a restart.
|
Procedure
- In the Trend Vision One console, go to .
- Enable packet capture.
- Select one or more appliances.
- Click the Configure Packet Capture drop down and click Enable.
- Click Save.
Important
The request to enable or disable packet capture is not sent until you click Save on the main Packet Capture screen.
- Click the name of an appliance to configure packet capture settings.The packet capture rule list for the appliance appears.
- To import the packet capture settings from another appliance, click
Replace with Existing List.
Important
Using this method replaces any currently configured packet capture rules on the target appliance.- Select the source appliance to import settings.
- Click Replace.
- Click Save.The console returns to the main Packet Capture screen. You may need to click Save again to ensure your changes are kept.
- Click Add to add a new packet capture rule.
- Configure the settings in the Capture Settings
window.SettingDescriptionStatusThe status of the packet capture rulePriorityThe priority order in which the rule is appliedPacket capture rules are applied in order of priority, with 1 having the highest priority.DescriptionA description of the rule which appears on the packet capture rule listHost IP address / rangeThe IP address or range the rule applies toDetection criteriaWhich kinds of detections the rule applies toSelect Add specific criteria if you want to limit the detection types the rule applies to.ActionWhether the packet is captured for the rule or not
- Click Save.
- In the packet capture list, click Save.The console returns to the main Packet Capture screen. You may need to click Save again to ensure your changes are kept.
- Configure the settings in the Capture Settings
window.