Jump to content

Recommended Posts

Igor Akhmetov
Posted

Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.

 

Issue

In KATA 4.1, when Central Node was used as Sensor, it was possible to access Traffic Capture and disable protocol, e.g SMTP.

CN-Sensor - https://support.kaspersky.com/help/KATA/4.1/en-US/199500.htm
Standalone Sensor - https://support.kaspersky.com/help/KATA/4.1/en-US/199500_1.htm

image.png.9584e9914e9132e5a853427af0933d2f.png

In KATA 5.0, this possibility is missing from docs and from CN and only available on Standalone Sensor:

image.png.e06ffeacc13a1911f880bff5544f034b.png

image.png.a78c63747a0810ebceeff2605fa8e05a.png

image.png.d3890f21550561bbb0801dfeb34e3517.png

image.png.a43ce2854c9fc5f1d3cf4bd8aa76fd58.png
 

Solution

Workaround is to use CLI and access predecessor configuration directly:

Settings section
#console-settings-updater get /kata/configuration/product/preprocessor_span | python3 -m json.tool | grep \"traffic\" -A 23
 "traffic": {
        "buffer_size_limit": 4096,
        "checksum_validation": false,
        "enable": true,
        "enable_dns": true,
        "enable_ftp": true,
        "enable_http": true,
        "enable_smtp": false,
        "enable_ssl": true,
        "ftp_data_expired_timeout": "PT60S",
        "ftp_data_supposed_max_size_bytes": 10485760,
        "iface_groups": [
            {
                "ifaces": [
                    "ens192"
                ],
                "core_id": null
            }
        ],
        "pcap_filter": "",
        "pcap_snaplen": 1600,
        "pcap_timeout": 10,
        "tcp_threads_number": 16
    },
Example disable SMTP, enable the rest
#console-settings-updater set --merge /kata/configuration/product/preprocessor_span '{"traffic": {"enable_dns": true, "enable_ftp": true, "enable_http": true, "enable_smtp": false}}'
Example change
#console-settings-updater get /kata/configuration/product/preprocessor_span | python3 -m json.tool  > /tmp/preprocessor_span.json
#vim /tmp/preprocessor_span.json
#console-settings-updater set /kata/configuration/product/preprocessor_span @/tmp/preprocessor_span.json

 

 

  • The title was changed to How to exclude protocol from SPAN traffic in KATA 5.x CN with Sensor role [KATA/KEDRE]

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...