No SMTP traffic seen on newly installed monitor
search cancel

No SMTP traffic seen on newly installed monitor

book

Article ID: 160376

calendar_today

Updated On:

Products

Data Loss Prevention Network Monitor Data Loss Prevention

Issue/Introduction

A sniffer utility (such as Dagsnap, Wireshark, etc.) is capturing traffic but no traffic is being reported through the Monitor UI.

Resolution

Check the IP Filters.  The filtering could be set up in such a way that no messages are generated and thus no traffic is captured. Be aware that IP traffic is evaluated in order against the filter entries until an entry matches the IP parameters.

To check the IP Filters from the Enforce UI:

Global:  Administration > Settings > Protocols

Server:  Administration > Overview > <detection server>. Click Configure tab and select the protocol in question.

You can validate whether the IP filters are causing an issue by removing them and then checking to see if traffic is being reported through the monitor.

For example, a filter of +,10.67.0.0/16,*;-,*,* matches all IP traffic going to network 10.67.x.x but does not match any other traffic.

For more details on setting up IP Filters, please see KB article ID 160497:  How to set up IP filters for Vontu Network Monitor

Check any SPAN or TAP ports that are in use to be sure they are configured and working correctly.