Page 1
X3-SERIES X3-440G-ID X3-880G-ID IN-LINE SSL/TLS DECRYPTION USER MANUAL...
Page 2
If you have any questions, you can contact us through our website: www.profitap.com or by email: support@profitap.com For the latest documentation and software, visit our Resource Center: https://resources.profitap.com/...
TABLE OF CONTENTS 1. Overview 2. Hardware Guide 2.1 Included Accessories 2.2 Physical Description 2.3 Ports Description 2.3.1 Console Port 2.3.2 Management Port 2.3.3 USB Port 2.4 Unpacking and Installing the Device 2.5 Troubleshooting and Maintenance 2.5.1 Replacing FAN Module 2.5.2 Replacing PSU 3.
1. Overview This document provides information about the configuration and operation of X3-Series In-Line SSL/TLS Decryption Tools. 2. Hardware Guide 2.1 Included Accessories ● DB9 to RJ45 serial cable ● (2) Front-mounting ears with (8) screws ● (2) Rear-mounting ears ●...
2.3 Ports Description 2.3.1 Console Port This serial port is intended to be used for local configuration and administration of the X3 device with Command Line Interface (CLI). Port parameters: RJ45, RS232, 115200, N, 8, 1 Default username and password for serial connection: ●...
2.5.2 Replacing PSU X3 power tray contains two PSU modules. If a PSU module fails, you should replace it, however X3 will function with one failed PSU module. You can remove individual PSU module using the following procedure: 1. Disconnect the power cord from the PSU (#17) to be replaced; 2.
TLS v1.3, which enforces Ephemeral Diffie-Hellman key exchange protocols. Profitap X3-Series In-Line SSL/TLS decryption device is capable of performing passive in-line decryption. Passive In-Line Decryption Passive in-line decryption creates a simple chain between the decryption and encryption engine, mirroring out the duplicated packets to one monitoring device.
Page 8
Overview of the communication between the client, X3 device, and server.
3.3.2 Configuration The client-server configuration is done via the following command: /profitap/x3-ssl -f do_configure [options] The configuration options can be provided as CLI arguments, or as environment variables. Environment variables can be set with e.g.: export X3_INTERFACE_CLIENT="1" The available options and the relative environment variables are the following:...
Page 10
TLS string versions used TLSv1.3 by the X3 SSL/TLS interface to the client. Example: /profitap/x3-ssl.sh -f do_configure --interface-client 1 --interface-client-speed 1000 --interface-client-ip 10.10.10.30 --client-ip 10.10.10.20-interface-server 2 -interface-server-speed 1000 --interface-server-ip 20.20.20.30 --server-ip 20.20.20.40 --server-ip-mask 20.20.20.40/24 --https-server-port 443 --interface-tool-1 25 --interface-tool-1-speed 1000 --tls-versions TLSv1.3 When the configuration is submitted to the device, it is applied immediately, and is saved to automatically be reapplied on device reboot.
Using the X3-Series CLI, it is possible to monitor the state of the device interfaces and traffic counters. The ports status is available via the following command: /profitap/x3-ssl -f do_get_ports_status This will output, for instance: Ports statistics are available via the following command:...
Need help?
Do you have a question about the X3 Series and is the answer not in the manual?
Questions and answers