The Cequence Unified API Protection (UAP) platform can integrate with the GigaVUE Fabric Manager to examine encrypted network traffic. Integrating the Cequence UAP platform with GigaVUE requires Gigamon Precryption.
Prerequisites
Before you start, confirm that you have an active Precryption license. You also need access to a Cequence UAP platform instance with Cequence Sensor.
Configuring GigaVUE Fabric Manager
Integrating the GigaVUE Fabric Manager with the Cequence UAP platform requires you to set up a monitoring domain, a policy, and an output tunnel.
- Log in to the GigaVUE Fabric Manager.
The GigaVUE management dashboard appears. - Select Containers > Universal Cloud Tap-Container (UCTC).
The New Monitoring Domain dialog box appears. - In the Monitoring Domain Name, Connection Name, and Cluster Name fields, type a name.
- Select a cluster endpoint URL from the drop-down.
- In the upper right corner, click Save.
The new Monitoring Domain is ready and the New Monitoring Domain dialog box closes. - Create a new connection to the Monitoring Domain. (TKK we never discuss how exactly this connection is made)
- Click the Monitoring Domain tab.
The Monitoring Domain tab displays all the UCTC pods on the GigaVUE instance. - Click Discovered Sources.
GigaVUE filters the list of UCTC pods to show only pods that are currently running on the cluster. - Verify that the new monitoring domain is present in the list of UCTC pods.
- Click the Traffic icon > Universal Cloud Tap-Container.
The policy wizard appears. - Type a policy name in the policy wizard.
- From the drop-down selectors, choose the Monitoring Domain created earlier in this procedure.
- From the drop-down selectors, choose the connection created earlier in this procedure.
- Select Precryption Policy, then click Next.
The wizard advances to the Source Selector. - In the Source Selector, type a name for the Source Specification.
- Specify sources and the inclusion and exclusion criteria for those sources.
Click the + or - buttons to add or remove criteria or sources. - Source Specification Name: <source selector name>
- Inclusion Criteria: You can select all sources or specific namespaces, services and pods to capture the traffic. In this example, we have chosen to capture traffic for the 'cequence' namespace only.
- Exclusion Criteria: You can exclude specific namespaces, services and pods to be ignored while capturing the traffic. In this example, we have chosen to ignore traffic to and from 'uctc' pods.
- Click Save.
The wizard advances to Rules. - In Name, type the name of the Cequence Sensor.
- In Tunnel Type, select VXLAN.
- In Destination IP, type the IPv4 address of the Cequence Sensor.
- In Destination Port, type 4789, then click Next.
The wizard advances to Deploy. - Click Deploy.
The Cequence UAP platform is now integrated with the GigaVUE Fabric Manager.