1.3. Presentation of the GCap

GCap is a probe-type component.
It enables:
  • Capturing and analyzing network traffic from TAPs

  • Reconstructing the files present in the analyzed flow (according to type and size parameters)

  • Carrying out an initial analysis

  • Generating alerts an/or metadata type events

  • Transmitting files / codes / events to the GCenter


1.3.1. Different server models

For more information, please refer to the section Mechanical characteristics of GCap.


1.3.2. Description of the GCap inputs / outputs

1.3.2.1. Example of a DELL R340 GCenter server

../_images/gcap_r340_1000.en.png

1.3.2.2. Example of a DELL R360 GCenter server

../_images/gcap_r360_2000.en.png

1.3.2.3. Example of a DELL R640 GCenter server

../_images/gcap-r640-2000.en.png

1.3.2.4. Example of a DELL R660 GCenter server

../_images/gcap-r660-2000.en.png

1.3.2.5. Example of a DELL R840 GCenter server

../_images/gcap_r840_5000.en.png

1.3.2.6. Description

Inputs/outputs

Use cases

USB and VGA connectors

Directly access a keyboard and a monitor
This connection mode is deprecated in favor of KVM/IDRAC/XCC and should only be used as a last resort

USB connector

Connection of the USB key allowing the decryption of disks (standard Linux Unified Key Setup)

RJ-45 connector `KVM/IDRAC`

Access to the server's management and configuration interface

RJ-45 connector

In the double interface configuration: used for the Management and tunnel roles
In the single interface configuration: used for the Management role only

RJ-45 connector

In the double interface configuration: used for the Dedicated VPN interface for the tunnel role
In the single interface configuration: not used

Two power supplies

Redundant server power supplies

Connectors SFP, SFP+, RJ-45 (`MON1`, `MON0`, `MON3`, `MON2`)
capture interfaces receive the flows from the TAPs

The GCap detection probe features:

  • Two RJ-45 connectors `management` and `tunnel`

  • RJ-45 and/or fiber connectors for monitoring `mon0` (`capture` role)

  • two power supplies.


1.3.2.7. Use of USB and VGA connectors

Connecting a keyboard and monitor enables direct access to the server's console interface.

Important

This mode is deprecated.
it should only be used during initial installation and for advanced diagnosis.

1.3.2.8. Access to the server's management and configuration interface

Access to this management interface is via HTTPS:

  • On a Dell server, this connector is called iDRAC. It is noted on the KVM/IDRAC GCap diagram

  • On a Lenovo server, this connector is called TSM. This connector can be identified by a wrench symbol on the bottom of it


1.3.2.9. Management and tunnel (`gcp0`) network interfaces

Important

Concept of role is introduced in the release 2.5.4.0.

These interfaces perform the following roles:

  • Role 1: called `tunnel`, is the secure communication between the probe and GCenter through an IPSEC tunnel in order to:

    • Escalate information such as files, alerts,metadata, and so on, derived from analyzing the monitored flows

    • Report information on the health of the probe to the GCenter

    • Control the probe - analysis rules, signatures, etc

  • Role 2 : called `management`, is the remote administration through the SSH protocol with access :

    • To the probe's command line interface (CLI)

    • To the graphical setup/configuration menu (deprecated)

In single-interface configuration, these roles are supported by one of these interfaces.
In dual-interface configuration, these roles is allocated over to interface (preferably, the two embedded gigabit ethernet network interfaces).

1.3.2.9.1. Configuration of the `management` and `tunnel` network interfaces

For more information on these interfaces and their configuration, refer to Management overview of `Management` and `Tunnel` interfaces.


1.3.2.10. Capture interfaces

These interfaces receive:

  • The flows from the TAPs on the indicated interfaces (`mon0` and `monx`) called `capture`

  • The flow from previously recorded files (pcap files) on a dedicated `monvirt` interface

Note

The number of capture interfaces varies depending on the specifications of each model.


1.3.2.10.1. Activating the capture `monx` interfaces

For more information, please refer to the paragraph Overview of managing the capture interfaces.


1.3.2.10.2. Aggregation of capture interfaces `monx`

For more information, please refer to Capture and capture interfaces `monx` between TAP and GCap: aggregation possibility.


1.3.3. Electrical connection

The probe has two power supplies, each of which has the necessary power to operate the equipment.
It is strongly recommended that each power supply should be connected to a separate power supply.

1.3.4. USB connector and LUKS key

During installation, the contents of the disks (excluding /boot) are encrypted using the LUKS standard.
During this process, a unique encryption key is created and placed on the USB stick connected to the probe.
It is strongly recommended to make a copy of this key because, in the event of failure, the data on the disks will no longer be accessible.
Once the system is up and running, the USB stick should be removed and placed in a secure place (e.g. in a safe).