8.1. List of potential actions

8.1.1. Accessing the GCap and GCenter

To perform the following task

Choose the following procedure

Connect to the GCap by a direct connection

1 - Procedure to connect directly to the GCap via keyboard and screen

Remote connection to iDRAC via HTTP

1 - Procedure to connect the iDRAC in HTTP (DELL server)

Remote SSH connection in serial port forwarding mode

1 - Procedure to remote connection to the CLI using SSH via the iDRAC interface in serial port forwarding mode

Connect to the GCenter via a web browser

1 - Procedure to connect to the GCenter via a web browser

Remote connection to GCap via an SSH tunnel

1 - Procedure to remote connection to GCap via an SSH tunnel


8.1.2. Configuring the GCap

To perform the following task

Carry out the following procedures in succession

Install a GCAP

Display the current keyboard language

1 - Display: use the show keymap command

Modify the keyboard language.

1 - Display: use the show keymap command
2 - Modify: use the set keymap command

Configuring the Gcap interface: (GUI or CLI)

1 - Display: use the show network-config command
2 - Modify: use the set network-config command

Display the date and time

1 - Display: use the show datetime command

Modify the date and time

1 - Display: use the show datetime command

Enable or disable colors for the current CLI session

1 - Use the color command

Compatibility mode with the GCenter

1- Show: use the show compatibility-mode command
2 - Modify: use the set compatibility-mode command

Pairing the GCap with GCenter


8.1.3. Managing accounts

To perform the following task

Carry out the following procedures in succession

Display the list of users

1 - Display the list: use the show passwords command

Modify the passwords

1 - Display the list: use the show passwords command
2 - Change passwords: use the set passwords command

Change the SSH keys

1 - Use the set ssh-keys command

Display the password policy

2 - Use the show password-policy command

Unlock blocked accounts

1 - Use the system unlock command

Modify the password management policy

1 - Use the set password-policy command

Display the protection policy against brute force attacks

1 - Use the show bruteforce-protection command

Modify the protection policy against brute force attacks

1 - Use the set bruteforce-protection command

Display the duration of inactivity before disconnection

1 - Use the show session-timeout command

Modify the duration of inactivity before disconnection

1 - Use the set session-timeout command


8.1.4. Manage the network

To perform the following task

Carry out the following procedures in succession

Managing Tunnel and Management interfaces

1 - refer to Procedure to manage the network parameters of `Tunnel` and `Management` interfaces

Display the GCenter IP address

1 - Use the show gcenter-ip command

Modify the IP address of the GCenter

1 - Use the set gcenter-ip command

Manage the capture interfaces `monx`

1 - refer to Procedure to manage the `monx` capture interface settings

Manage interface aggregation of capture

1 - refer to Procedure to manage capture interface aggregation

Switch to the single-interface configuration

1 - Refer to Procedure to switch the single-interface configuration

Switching to the dual-interface configuration

1 - Refer to Procedure to switch to the configuration dual-interface


8.1.5. Manage the detection engine

To perform the following task

Carry out the following procedures in succession

Display advanced options of the Sigflow configuration

1 - Use the show monitoring-engine command

Apply a Sigflow advanced configuration

1 - Use the set monitoring-engine command

Start the Sigflow detection engine

1 - Use the monitoring-engine start command

Stop the Sigflow monitor engine

1 - Use the monitoring-engine stop command

Display the detection engine status

1 - Use the monitoring-engine status command

Replay a pcap file of traffic generation

1 - Use the replay command


8.1.6. Managing server

To perform the following task

Carry out the following procedures in succession

Display help on the commands

1 - Use the help command

Exit the current context

1 - Use the exit command

Leave the SSH session

1 - Use the exit command

Restart the GCap

1 - Use the system restart command

Shut down the GCap

1 - Use the system shutdown command


8.1.7. Monitoring the GCAP

To perform the following task

Carry out the following procedures in succession

Display the current status of the GCap

1 - Use the show status command

Display the statistics of the Sigflow detection engine

1 - Use the show eve-stats command

Display statistics and health information

1 - Use the show health command

Extract the information from the GCap as requested by technical support

1 - Use the show tech-support command