Packet Capture¶
Packet Capture profiles are configured and associated with a Valtix Gateway and enabled in Policy Rules, Network Threat Profiles, and Web Protection Profiles. A packet capture can capture traffic flows (PCAP files), and application and network threats (HAR files).
Capture File Formats¶
Policy Rule Capture - <bucketname>/<cspaccountname>/<gatewayname>/flow-packet-captures/<year>/<month>/<day>/<instanceid>_<timestamp>_<policyname>.pcap.gz
IPS Threat Capture - <bucketname>/<cspaccountname>/<gatewayname>/network-threats-captures/<year>/<month>/<day>/<instanceid>_<timestamp>_<sessionid>.pcap.gz
WAF Threat Capture - <bucketname>/<cspaccountname>/<gatewayname>/web-protection-captures/<year>/<month>/<day>/<instanceid>_<timestamp>_<sessionid>.har.gz
API Logging - <bucketname>/<cspaccountname>/<gatewayname>/api-logging-captures/<year>/<month>/<day>/<instanceid>_<timestamp>_<sessionid>.har.gz
Create a Profile¶
- Navigate to Manage -> Profiles -> Packet Capture
- Click Create
- Specify a Profile Name and Description
- Specify a CSP Account
- Depending on the CSP, specify the parameters for the storage bucket. For AWS, specify the S3 Bucket. For Azure, specify the Storage Account Name, Blog Container and Storage Access Key. For GCP, specify the Storage Bucket.
- Click Save
- Add the desired Gateway Associations (refer to Add a Gateway Association)
Edit a Profile¶
- Navigate to Manage -> Profiles -> Packet Capture
- Check the box next to the Profile you want to Edit
- Click Edit
- Modify the parameters as desired
- Click Save
Delete a Profile¶
- Navigate to Manage -> Profiles -> Packet Capture
- View the Profile Details to view the Associated Gateways
- Remove all Gateway Associations (refer to Remove a Gateway Association)
- Navigate to Manage -> Profiles -> Packet Capture
- Check the box next to the Profile you want to Delete
- Click Delete
- Confirm the Delete operation by clicking Yes or No
View a Profile Details¶
- Navigate to Manage -> Profiles -> Packet Capture
- Select the Profile link you want to view the Details
- View the Details information
Add a Gateway Association¶
- Navigate to Manage -> Gateways -> Gateways
- Check the box next the Gateway you want to associate the Profile
- Click Edit
- For the Packet Capture Profile parameter, select the desired Profile from the menu
- Click Save
Remove a Gateway Association¶
- Navigate to Manage -> Gateways -> Gateways
- Check the box next the Gateway you want to de-associate the Profile
- Click Edit
- For the Packet Capture Profile parameter, click the 'X' next to the Profile to remove it
- Click Save