You can control the incoming and outgoing network traffic that a Virtual Probe sends to the Sensors for inspection. Based on your requirement, you can configure which traffic needs to be inspected and which traffic need not be inspected.
After you install the Virtual Probe on a virtual machine, a file is available for configuring the traffic inspection.
- On a Linux system, the file is opt/trellix/etc/nftables_excludes.json
- On a Windows system, the file is C:\Program Files (x86)\TrellixVIPS\winpkfilter_excludes.json
The file specifies configuration rules in following JSON format:
{
"table_config" : {
…
},
"input" : [
…
],
"output" : [
…
]
}
Description of sections in the configuration file:
| Section | Description |
|---|---|
| table_config | Defines the global parameters used for traffic inspection
|
| input | Contains inspection rules for the incoming traffic |
| output | Contains inspection rules for the outgoing traffic |
The following example shows the configuration to exclude the incoming iSCSI traffic from inspection.
{
"action": "bypass",
"direction": "incoming",
"network_protocol": "ipv4",
"transport_protocol": "tcp",
"src_address": "192.168.200.0",
"src_mask": 24,
"src_first_port": 3260,
"src_last_port": 3260,
"comment": "Exclude incoming iSCSI traffic from 192.168.200.0 from interception"
}
The following example shows the configuration to exclude the incoming iSCSI traffic from inspection.
| Field | Description |
|---|---|
| action | Action to be taken for the network traffic.
Set the value to bypass to exclude the traffic from being sent to the Sensor for inspection. |
| direction | Direction of the network traffic.
|
| network_protocol | Network protocol for which the rule applies. The supported value is ipv4. |
| transport_protocol | Transport protocol for which the rule applies. The supported values are udp and tcp. |
| src_address (optional) | IP address of the system from which the traffic originates.
This field is optional. If specified, the value should be either a host or network address specified in IPv4 dotted notation. For example, 10.1.1.0 for 192.168.232.19. |
| src_mask | Number of significant bits set in the mask.
If src_address is a host address, set the value to 32. |
| src_first_port (optional) | Starting port number from the range of ports for which the network traffic should be inspected.
To specify a single port, set both src_first_port and src_last_port to the same value. Neither value can be 0. The value of src_first_port should be less than the value of src_last_port. |
| src_last_port (optional) | Ending port number from the range of ports for which the network traffic should be inspected.
|
| comment | A brief description of the rule.
|
Note
Both the input and output sections contain a rule that has the action field set to intercept. Do not edit this rule. This rule should always be the last rule in both the input and output sections. There are several rules in the file by default. Modifying or removing the default rules may cause instability in the system. Add new rules before the default rules.
The following is a sample nftables_excludes.json file:
{
"table_config" : {
"table_type" : "inet",
"table_name" : "mcafee",
"input_type" : "filter",
"input_hook" : "input",
"input_policy" : "accept",
"output_type" : "filter",
"output_hook" : "output",
"output_policy" : "accept"
},
"input" : [
{
"action": "bypass",
"direction" : "incoming",
"transport_protocol" : "tcp",
"dest_first_port" : 10004,
"dest_last_port" : 10004,
"flags" : 16,
"comment" : "Exclude incoming Statistics requests"
},
{
"action": "bypass",
"direction" : "incoming",
"transport_protocol" : "tcp",
"dest_first_port" : 5901,
"dest_last_port" : 5901,
"flags" : 16,
"comment" : "Exclude incoming VNC traffic from interception"
},
{
"action": "intercept",
"first_queue_number" : 1,
"last_queue_number" : 1,
"direction" : "incoming",
"flags" : 16,
"comment" : "Queue everything else that's incoming"
}
],
"output" : [
{
"action": "bypass",
"direction" : "outbound",
"transport_protocol" : "tcp",
"src_first_port" : 10004,
"src_last_port" : 10004,
"flags" : 16,
"comment" : "Exclude outgoing statistics traffic from interception"
},
{
"action": "bypass",
"direction" : "outbound",
"transport_protocol" : "tcp",
"src_first_port" : 5901,
"src_last_port" : 5901,
"flags" : 16,
"comment" : "Exclude outgoing VNC traffic from interception"
},
{
"action": "bypass",
"direction" : "outbound",
"transport_protocol" : "tcp",
"dest_first_port" : 21,
"dest_last_port" : 21,
"flags" : 16,
"comment" : "Bypass outgoing ftp"
},
{
"action": "intercept",
"first_queue_number" : 1,
"last_queue_number" : 1,
"direction" : "outbound",
"flags" : 16,
"comment" : "Queue everything else that's outbound"
}
]
}