8.1. List of potential actions
8.1.1. Accessing the GCap and GCenter
To perform the following task |
Choose the following procedure |
|---|---|
Connect to the GCap by a direct connection |
1 - Procedure to connect directly to the GCap via keyboard and screen |
Remote connection to iDRAC via HTTP |
|
Remote SSH connection in serial port forwarding mode |
|
Connect to the GCenter via a web browser |
|
Remote connection to GCap via an SSH tunnel |
1 - Procedure to remote connection to GCap via an SSH tunnel |
8.1.2. Configuring the GCap
To perform the following task |
Carry out the following procedures in succession |
|---|---|
Install a GCAP |
|
Display the current keyboard language |
1 - Display: use the show keymap command
|
Modify the keyboard language. |
1 - Display: use the show keymap command
2 - Modify: use the set keymap command
|
Configuring the Gcap interface: (GUI or CLI) |
1 - Display: use the show network-config command
2 - Modify: use the set network-config command
|
Display the date and time |
1 - Display: use the show datetime command
|
Modify the date and time |
1 - Display: use the show datetime command
2 - Modify: refer to Procedure to change the date and time of the GCap
|
Enable or disable colors for the current CLI session |
1 - Use the color command |
Compatibility mode with the GCenter |
1- Show: use the show compatibility-mode command
2 - Modify: use the set compatibility-mode command
|
Pairing the GCap with GCenter |
1 - Refer to Procedure to pair a GCap with the GCenter
|
8.1.3. Managing accounts
To perform the following task |
Carry out the following procedures in succession |
|---|---|
Display the list of users |
1 - Display the list: use the show passwords command
|
Modify the passwords |
1 - Display the list: use the show passwords command
2 - Change passwords: use the set passwords command
|
Change the SSH keys |
1 - Use the set ssh-keys command |
Display the password policy |
2 - Use the show password-policy command |
Unlock blocked accounts |
1 - Use the system unlock command |
Modify the password management policy |
1 - Use the set password-policy command |
Display the protection policy against brute force attacks |
1 - Use the show bruteforce-protection command |
Modify the protection policy against brute force attacks |
1 - Use the set bruteforce-protection command |
Display the duration of inactivity before disconnection |
1 - Use the show session-timeout command |
Modify the duration of inactivity before disconnection |
1 - Use the set session-timeout command |
8.1.4. Manage the network
To perform the following task |
Carry out the following procedures in succession |
|---|---|
Managing Tunnel and Management interfaces |
1 - refer to Procedure to manage the network parameters of `Tunnel` and `Management` interfaces |
Display the GCenter IP address |
1 - Use the show gcenter-ip command |
Modify the IP address of the GCenter |
1 - Use the set gcenter-ip command |
Manage the capture interfaces |
1 - refer to Procedure to manage the `monx` capture interface settings |
Manage interface aggregation of capture |
1 - refer to Procedure to manage capture interface aggregation |
Switch to the single-interface configuration |
1 - Refer to Procedure to switch the single-interface configuration |
Switching to the dual-interface configuration |
1 - Refer to Procedure to switch to the configuration dual-interface |
8.1.5. Manage the detection engine
To perform the following task |
Carry out the following procedures in succession |
|---|---|
Display advanced options of the Sigflow configuration |
1 - Use the show monitoring-engine command |
Apply a Sigflow advanced configuration |
1 - Use the set monitoring-engine command |
Start the Sigflow detection engine |
1 - Use the monitoring-engine start command |
Stop the Sigflow monitor engine |
1 - Use the monitoring-engine stop command |
Display the detection engine status |
1 - Use the monitoring-engine status command |
Replay a pcap file of traffic generation |
1 - Use the replay command |
8.1.6. Managing server
To perform the following task |
Carry out the following procedures in succession |
|---|---|
Display help on the commands |
1 - Use the help command |
Exit the current context |
1 - Use the exit command |
Leave the SSH session |
1 - Use the exit command |
Restart the GCap |
1 - Use the system restart command |
Shut down the GCap |
1 - Use the system shutdown command |
8.1.7. Monitoring the GCAP
To perform the following task |
Carry out the following procedures in succession |
|---|---|
Display the current status of the GCap |
1 - Use the show status command |
Display the statistics of the Sigflow detection engine |
1 - Use the show eve-stats command |
Display statistics and health information |
1 - Use the show health command |
Extract the information from the GCap as requested by technical support |
1 - Use the show tech-support command |