000030296 - BPF rules are not filtering traffic on RSA Security Analytics 10G Decoders

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 3Show Document
  • View in full screen mode

Article Content

Article Number000030296
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: 10G Decoder, Security Analytics UI
RSA Version/Condition: 10.4.x
Platform: CentOS
O/S Version: EL6
IssueAfter configuring BPF rules on a Security Analytics 10G Decoder, the traffic is not being filtered as expected.
CauseThe PFRING driver used with 10G Decoders does not support the use of BPF and therefore will not filter the traffic.
ResolutionIn order to filter network traffic on a 10G Decoder, a Network Rule must be created rather than using BPF.
For example, if ports 553 and 55553 needed to be filtered, rather than using the not (port 553 or 55553) BPF syntax, a network rule similar to the rule shown below should be created.
User-added image
NotesMore information on configuring Network Rules can be found in the RSA Security Analytics 10.4 User Guide.

Attachments

    Outcomes