Kaspersky Anti Targeted Attack Platform

Configuring the recording of mirrored traffic from SPAN ports using the web interface

If you are using the

and mode, use the web interface of the PCN or SCN server for which you want to configure parameters.

To enable and configure the recording of mirrored traffic from SPAN ports:

  1. Connect and configure external storage.
  2. Select the Sensor servers section in the window of the application web interface.
  3. Click the card of the relevant Sensor component.

    This opens a window with information about the component.

  4. Click Edit.
  5. Go to the External storage tab.

    This tab is not displayed if an external storage is not connected.

    In the External storage section, the Oldest packet field displays the date and time of the first saved dump in the external storage. The Newest packet field displays the date and time of the last dump saved to external storage.

  6. If you want to use the external storage, set the Record traffic toggle switch to Enabled.

    By default, the toggle switch is in the Disabled position.

  7. In the Path for saving traffic field, specify the path to the directory in which you want the application to save traffic dumps.
  8. Do the following:
    1. Under Maximum storage size, specify the maximum size of traffic dumps that will be stored in the storage.

      If the size of dumps in the storage exceeds the specified value, the earliest dumps are deleted, the total size of which is equal to the size of the new dumps.

      If you reduce the maximum dump storage size, the earliest dumps are deleted, the total size of which is equal to the change of the setting.

    2. If you want to limit the capture of data in traffic, under Traffic filtering upon capture, set the BPF filtering toggle switch to Enabled. Traffic filtering can reduce the size of dumps in dump storage and facilitate traffic analysis.

      In the BPF filtering rules, the filtering rule. The BPF filtering rule is written in the libpcap format. For more details about the syntax, please refer to the pcap-filter manual page.

      Example of a filtering expression:

      tcp port 102 or tcp port 502

    3. If you want to configure the traffic dump storage duration, in under Storage duration, set the Enable storage duration toggle switch to Enabled. In the Storage time (days) field, enter the number of days for which you want to store traffic dumps. Traffic dumps that are stored longer than the specified duration are deleted from the storage.
    4. Click Save.

The recording of mirrored traffic from SPAN ports is configured.