IAM With Bypass Mode Only Detect One PC From Network Subnet

|
  • 133
  • 7

Issue Description

Bypass mode has been deployed in IAM, but IAM only can detect one IP traffic from 192.168.31.0.

Handling Process

  • Capture packet at eth3 (connect to mirror port), there are traffic other than 192.168.31.0, this means the configuration for core switch’s mirror port can mirror traffic to IAM’s eth3.
2. Inside the traffic can shows there are multiples network segment other than 192.168.31.0.

Root Cause

This is because theListened and Excluded IP addresses is configure to 192.168.31.0/255.255.255.0,so it only can monitor this IP segment.

Solution

1. As per confirmed requirement from customer, change the range of Listened and Excluded IP Addresses from 192.168.31.0/255.255.255.0 to 192.168.0.0/255.255.0.0.
2. After changed the configuration will reboot the IAM device, kindly prepare a downtime period during perform it.
Sangfor_Brando Lv5Posted 07 Apr 2020 09:17
  
Easy to Read and Understand
Faisal Posted 24 Aug 2020 07:48
  
Thank you very much for the information ...
Faisal Posted 20 Oct 2020 21:04
  
Nice article ...
Faisal Posted 21 Dec 2020 08:56
  
Great info ...
Ellechar Lv4Posted 21 Jan 2021 14:43
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 22 Mar 2021 08:02
  
Very informative …
Faisal Posted 07 Jun 2021 07:03
  
Nice guidance ...

I want to write a case
Doc ID: 2501
Author: Newbie1212
Updated: 2019-12-21 12:59
Version: