000030296 - BPF rules are not filtering traffic on RSA NetWitness Platform 10G Decoders

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support on Aug 27, 2019
Version 4Show Document
  • View in full screen mode

Article Content

Article Number000030296
Applies ToRSA Product Set: Security Analytics, RSA NetWitness Logs & Network
RSA Product/Service Type: 10G Decoder, Security Analytics UI
RSA Version/Condition: 10.4.x, 11.x
Platform: CentOS
O/S Version: EL6
IssueAfter configuring BPF rules on a Security Analytics 10G Decoder, the traffic is not being filtered as expected.
CauseThe PFRING driver used with 10G Decoders does not support the use of BPF and therefore will not filter the traffic.
ResolutionIn order to filter network traffic on a 10G Decoder, a Network Rule must be created rather than using BPF.

For example, if ports 553 and 55553 needed to be filtered, rather than using the not (port 553 or 55553) BPF syntax, a network rule similar to the rule shown below should be created.

User-added image
NotesMore information on configuring Network Rules can be found in the RSA Security Analytics 10.4 User Guide.