IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Sun July 23, 2023 04:18 AM

    Hello Seniors, Good Day!

    I am looking for details of P-CAP vs K-TAP collection mechanism. As during the installation process, K-TAP fails to load properly, possibly caused by hardware or software incompatibility, P-CAP is installed as the default collection mechanism.

    So, Can (P-CAP) collect the traffic from the server where we do not have any compatible K-TAP module. Is there any limitation of P-CAP on RHEL 8.8..

    FYI - New kernel is 4.18.0-477.13.1.el8_8. Thanks Much! 



    ------------------------------
    Sincerely,
    Akash Parmar
    ------------------------------


  • 2.  RE: Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Mon July 24, 2023 10:06 AM

    Hey Akash,

    PCAP won't help you with the shared memory traffic capture like ktap does.

    ====
    PCAPPCAP is a packet-capturing mechanism that listens to network traffic from and to a database server. In a UNIX environment, since the K-TAP captures all network traffic, PCAP is rarely used. PCAP is used to capture local TCP/IP traffic on the device.

    Restriction:
    • PCAP only works on ports (no shared memory, and so on).

    The PCAP uses the client IP/mask values for all local inspection engines to determine what to monitor and report. A PCAP that is installed with an S-TAP with multiple inspection engines that have different client IP/mask values, captures traffic from all clients that are defined in all inspection engines. The PCAP might be processing and sending more information to the Guardium system than you intend.
    ====

    Doc Reference- https://www.ibm.com/docs/en/guardium/11.5?topic=functionality-linux-unix-s-tap-monitoring-mechanisms



    ------------------------------
    Sachin Marawar
    ------------------------------



  • 3.  RE: Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Tue August 15, 2023 09:04 AM

    Thank you Sachin for the clarification. So, PCAP will be default and only one monitoring mechanism for windows platform is that correct...?



    ------------------------------
    Akash Parmar
    ------------------------------



  • 4.  RE: Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Tue August 15, 2023 12:00 PM

    No Akash,
    Windows & Unix operating systems are very different hence some parameters in guard_tap.ini won't be necessarily applicable to both OS staps.
    Coming over to the actual question- WINSTAP does not utilize pcap parameters in the guard_tap.ini and is a completely different and relies on libraries and drivers from Windows OS.



    ------------------------------
    Sachin Marawar
    ------------------------------



  • 5.  RE: Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Tue August 22, 2023 04:32 AM

    Thank you Sachin for the clarifications. Grateful for this...



    ------------------------------
    Akash Parmar
    ------------------------------



  • 6.  RE: Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Fri September 08, 2023 02:27 AM

    Hi Akash,
    What version of Guardium you are on?

    Because, I can see 4.18.0-477.13.1.el8_8.x86_64 is supported by Guardium v11.4. There is an exact match for the Kernel. Did you try the latest v11.4 STAP? 



    ------------------------------
    GIRISH RAMESH BABU
    ------------------------------



  • 7.  RE: Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Mon November 06, 2023 10:25 AM

    Hi Sachin/GIRISH,

    I have 11.3 collector and installed v11.3.4 S-TAP on RHEL8.8 where K-TAP failed to find a compatibility with Kernel.

    can i upgrade this agent to 11.4 without upgrading collector? will a failed K-TAP become an issue?

    Please suggest!

    Thanks!



    ------------------------------
    Rizwan Ali
    ------------------------------



  • 8.  RE: Looking Info for P-CAP vs K-TAP collection mechanism

    Posted Mon November 06, 2023 04:32 PM

    Rizwan,

    You really should only use GIMs and STAPs that match the collector version.

    You will want to find the correct KTAP for your OS - 'uname -a' on the database server or shown on the Setup by Client screen.

    This link will help you find the correct KTAP.

    https://login.ibm.com/oidc/sps/auth?client_id=NzJiOTdhOTUtNDBmZi00&Target=https%3A%2F%2Flogin.ibm.com%2Foidc%2Fendpoint%2Fdefault%2Fauthorize%3FqsId%3D06a76c87-644f-416e-88ac-6ffe6a7a5764%26client_id%3DNzJiOTdhOTUtNDBmZi00

    Ibm remove preview
    View this on Ibm >

    Good luck.

    Jennifer



    ------------------------------
    Jennifer Dodson
    Brand Technical Specialist
    Global Sales, Financial Services
    1 469 796 8337 Mobile
    jennifer.dodson@ibm.com

    IBM
    ------------------------------