You can control the incoming and outgoing network traffic that a Virtual Probe sends to the Sensors for inspection. Based on your requirement, you can configure which traffic needs to be inspected and which traffic need not be inspected.
After you install the Virtual Probe on a virtual machine, a file is available for configuring the traffic inspection. On a Linux system, the file is opt/trellix/etc/nftables_excludes.json
The file specifies configuration rules in following JSON format:
{
"table_config" : {
…
},
"input" : [
…
],
"output" : [
…
]
}
Description of sections in the configuration file:
Section | Description |
|---|---|
table_config | Defines the global parameters used for traffic inspection
|
input | Contains inspection rules for the incoming traffic |
output | Contains inspection rules for the outgoing traffic |
The following example shows the configuration to exclude the incoming iSCSI traffic from inspection.
{
"action": "bypass",
"direction": "incoming",
"network_protocol": "ipv4",
"transport_protocol": "tcp",
"src_address": "192.168.200.0",
"src_mask": 24,
"src_first_port": 3260,
"src_last_port": 3260,
"comment": "Exclude incoming iSCSI traffic from 192.168.200.0 from interception"
}
The following example shows the configuration to exclude the incoming iSCSI traffic from inspection.
Field | Description |
|---|---|
action | Action to be taken for the network traffic. Set the value to |
direction | Direction of the network traffic.
|
network_protocol | Network protocol for which the rule applies. The supported value is |
transport_protocol | Transport protocol for which the rule applies. The supported values are |
src_address (optional) | IP address of the system from which the traffic originates. This field is optional. If specified, the value should be either a host or network address specified in IPv4 dotted notation. For example, |
src_mask | Number of significant bits set in the mask. If |
src_first_port (optional) | Starting port number from the range of ports for which the network traffic should be inspected. To specify a single port, set both The value of |
src_last_port (optional) | Ending port number from the range of ports for which the network traffic should be inspected.
|
comment | A brief description of the rule.
|
Note
Both the input and output sections contain a rule that has the
actionfield set tointercept. Do not edit this rule. This rule should always be the last rule in both the input and output sections. There are several rules in the file by default. Modifying or removing the default rules may cause instability in the system. Add new rules before the default rules.
The following is a sample nftables_excludes.json file:
{
"table_config" : {
"table_type" : "inet",
"table_name" : "mcafee",
"input_type" : "filter",
"input_hook" : "input",
"input_policy" : "accept",
"output_type" : "filter",
"output_hook" : "output",
"output_policy" : "accept"
},
"input" : [
{
"action": "bypass",
"direction" : "incoming",
"transport_protocol" : "tcp",
"dest_first_port" : 10004,
"dest_last_port" : 10004,
"flags" : 16,
"comment" : "Exclude incoming Statistics requests"
},
{
"action": "bypass",
"direction" : "incoming",
"transport_protocol" : "tcp",
"dest_first_port" : 5901,
"dest_last_port" : 5901,
"flags" : 16,
"comment" : "Exclude incoming VNC traffic from interception"
},
{
"action": "intercept",
"first_queue_number" : 1,
"last_queue_number" : 1,
"direction" : "incoming",
"flags" : 16,
"comment" : "Queue everything else that's incoming"
}
],
"output" : [
{
"action": "bypass",
"direction" : "outbound",
"transport_protocol" : "tcp",
"src_first_port" : 10004,
"src_last_port" : 10004,
"flags" : 16,
"comment" : "Exclude outgoing statistics traffic from interception"
},
{
"action": "bypass",
"direction" : "outbound",
"transport_protocol" : "tcp",
"src_first_port" : 5901,
"src_last_port" : 5901,
"flags" : 16,
"comment" : "Exclude outgoing VNC traffic from interception"
},
{
"action": "bypass",
"direction" : "outbound",
"transport_protocol" : "tcp",
"dest_first_port" : 21,
"dest_last_port" : 21,
"flags" : 16,
"comment" : "Bypass outgoing ftp"
},
{
"action": "intercept",
"first_queue_number" : 1,
"last_queue_number" : 1,
"direction" : "outbound",
"flags" : 16,
"comment" : "Queue everything else that's outbound"
}
]
}