Configuring Private Cloud for Global Threat Intelligence integration
Previously, the communication between Network Security Platform and the Global Threat Intelligence Public or Private cloud was using the UDP protocol on port 53. Starting with this release, Network Security Platform and the Global Threat Intelligence Public or Private cloud uses TCP protocol on port 443. By default, Network Security Platform is configured to communicate with the McAfee Global Threat Intelligence server. You can configure Network Security Platform to communicate with a Private Cloud in the Manager → <Admin Domain Name> → Integration → GTI page.
The GTI page has the following tabs:
- File Reputation: Allows configuring public or private cloud for file reputation queries. You must have the file reputation server name or IP address with the user name and password for configuration.
- Endpoint/URL Reputation: Allows configuring public or private cloud for endpoint/URL reputation queries. You must need the IP address for the Private GTI Cloud server and .ZIP file that contains Network Security Platform certificate, Private key for Network Security Platform certificate, and GTI Private Cloud CA certificate files in the PEM format.
IPS CLI enhancements
The following Sensor CLI commands are updated:
| CLI Command | Description |
|---|---|
| pktcapturefile | Uploads packet capture file to the SCP server or Manager or deletes a packet capture file in the Sensor. With this release of 10.1, the command is now applicable to all NS-series Sensors. |
| pktcapture intfport | Captures incoming and outgoing packets on a single monitoring port. With this release of 10.1, the command is now applicable to all NS-series Sensors. |
| pktcapture intfport-pair | Captures incoming and outgoing packets on two different monitoring ports. With this release of 10.1, the command is now applicable to all NS-series Sensors. |
| show gti config | Displays the GTI configuration details for File reputation and IP/URL reputation. |
| CLI Command | Description |
|---|---|
| show malwareserverstats | Displays additional counters for Network Security Platform communication with the Global Threat Intelligence using REST. |