Absent Member.
Absent Member.
1233 views

IPv6 Support?

Hello,

I'm trying to find a clear overview of the IPv6 support in ArcSight products (Logger, ESM, ...). Anybody?

/x

Labels (4)
Tags (1)
0 Likes
12 Replies
Absent Member.. Absent Member..
Absent Member..

ESM 5.0 added fields to Device Custom to accomidate IPv6 addresses, Device Custom IPv6 Address1-4. Not sure if any of the standard SmartConnectors are set up to use them however.

Don't recall logger having any fields to accomidate them yet.

0 Likes
Absent Member.
Absent Member.

A lot of "under the hood" stuff is being worked, but nothing is exposed in the UI or made part of standard content yet.

0 Likes
Commodore
Commodore

Below are the new fields from the v5.0 reference guide

GroupLabelScript AliasData TypeDescription
Device CustomIPV6 Address1 LabeldeviceCustomIPv6Address1StringFirst custom IPV6 address
Device CustomIPV6 Address1deviceCustomIPv6Address1LabelIPV6 addressFirst custom IPV6 address label
Device CustomIPV6 Address2 LabeldeviceCustomIPv6Address2StringSecond custom IPV6 address
Device CustomIPV6 Address2deviceCustomIPv6Address2LabelIPV6 addressSecond custom IPV6 address label
Device CustomIPV6 Address3 LabeldeviceCustomIPv6Address3StringThird custom IPV6 address
Device CustomIPV6 Address3deviceCustomIPv6Address3LabelIPV6 addressThird custom IPV6 address label
Device CustomIPV6 Address4 LabeldeviceCustomIPv6Address4StringFourth custom IPV6 address
Device CustomIPV6 Address4deviceCustomIPv6Address4LabelIPV6 addressFourth custom IPV6 address label
0 Likes
Absent Member.
Absent Member.

Thanks bkilroe.

I attempted to get IPv6 working via CEF today without any luck. (ESM 5.0.1.6642.2, Connector 5.1.3.5870.0)

I created a CEF file destination for a Windows Server 2008  box running IPv6, then read the file into ESM using a connector on  another box.  All address fields, including the customipv6 fields were  blank in ESM despite being able to see the IPv6 address in the raw  event.

CEF:0|Microsoft|Microsoft Windows||Microsoft-Windows-Security-Auditing:5156|The Windows Filtering Platform has allowed a connection.|Low| eventId=119 externalId=5156 categorySignificance=/Informational categoryBehavior=/Communicate/Query categoryDeviceGroup=/Operating System categoryOutcome=/Success categoryObject=/Host/Application/Service art=1309276928705 cat=Security deviceSeverity=Audit_success rt=1309276926000 spt=546 dhost=WIN2008X64 cs2=12810 cs3=Microsoft-Windows-Security-Auditing cs1Label=Accesses cs2Label=EventlogCategory cs3Label=EventSource cs4Label=Reason or Error Code cs5Label=Authentication Package Name cs6Label=Object Name cn1Label=LogonType cn2Label=New Process ID ahost=WIN2008X64 av=5.1.3.5870.0 atz=America/New_York aid=G5H41jABABCAAZsjU2aqBQ\=\= at=nt_local dvchost=WIN2008X64 dtz=America/New_York _cefVer=0.1 ad.Application_,Information=Process ID\=956 ad.Destination_,Port=547 ad.Filter_,Information=Filter Run-Time ID\=65551 ad.Layer_,Name=%%14611 ad.Application_,Name=\\device\\harddiskvolume1\\windows\\system32\\svchost.exe ad.Network_,Information=Direction\=%%14593 ad.Layer_,Run-Time_,ID=50 ad.Protocol=17 ad.Source_,Address=fe80::510e:3eef:2bbe:7ab8 ad.Destination_,Address=ff02::1:2

So far, the only way I've been able to get an IPv6 address in ESM is to use the test alert connector and manually put the address in the Device Custom IPv6 Address field using the event crafting GUI.

-Joe

0 Likes
Absent Member.
Absent Member.

I thought I'd share this too.  This is what happens if you try to put an IPv6 address in the source address field.

[ERROR] Unable to pase [fe80::510e:3eef:2bbe:7ab8] as an ip address f or field [Source Address]

-Joe

0 Likes
Absent Member.
Absent Member.

Is it possible to add IPv6 address in the definition of asset?

0 Likes
Commodore
Commodore

IPv6 is still being worked on, with improvements being added. The second part of this presentation has some details of what our products are currently doing:

0 Likes
Cadet 2nd Class Cadet 2nd Class
Cadet 2nd Class

You should join the IPv6 Support group.  V6.5 ESM is out now.  Although there is more IPv6 developments, there is certainly more to come.

scotty

0 Likes
Cadet 2nd Class Cadet 2nd Class
Cadet 2nd Class

Hey guys, any update on IPv6 support? I'm looking for more current info about IPv6 monitoring (on ESM 6.5), specifically on how I can manage assets/network zones and specify IPv6 conditions in rules, filters, queries, etc. Any more info/doc materials at all would be great, thanks!

0 Likes
Cadet 2nd Class Cadet 2nd Class
Cadet 2nd Class

Peter -

Nope, HP does not have a network/asset/zone model for IPv6.  There is no documentation on it as it does not exist. There are just a few things that HP says that works in ESM v6.5 and they do not work.  You should join the IPv6 Support group to see some of the posts there.

scotty

0 Likes
Cadet 1st Class
Cadet 1st Class

Is there any update on IPV6 support on Arcsight Products and Road map?

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.