Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Can SWG be configured to ignore internal traffic

Updated: 30 Nov 2011 | 12 comments
Andy G's picture
0 0 Votes
Login to vote

Morning All,

I have configured a SWG 8450 within our network and have configured the system following the documentation provided a) with the product, b) through using the technical articles on the Symantec web site.

I have noticed that the system is picking up all traffic within the internal network, which is something I want to have the system ignore (with only outbound traffic beign picked up). Is this possible within the port/span configuration?

 

Any help or guidance would be appreciated.

 

Regards,
Andy
 

Discussion Filed Under:

Comments

BenDC's picture
30
Nov
2011
1 Vote +1
Login to vote

Have internal subnets been

Have internal subnets been defined under Configuration -> Administration -> Network? If so does it include all the internal subnets used by your company?

Andy G's picture
30
Nov
2011
0 Votes 0
Login to vote

Network configuration

Under the network configuration tab in the configuration page, the subnets for the internal network have been configured. the subnets configured cover all of those used within the UK domain for the company.

 

Andy

BenDC's picture
30
Nov
2011
1 Vote +1
Login to vote

Can you provide a screenshot

Can you provide a screenshot of the report showing the internal traffic as well as the network configuration?

Andy G's picture
30
Nov
2011
0 Votes 0
Login to vote

have attached two screen

have attached two screen shots - first showing the internal and external traffic being picked up; the second showing the network configuration for the system.

picture 1.jpg Picture 2.jpg
BenDC's picture
30
Nov
2011
1 Vote +1
Login to vote

I see IP address

I see IP address 10.250.254.248 (I think that is the IP it is hard to see for sure on the screenshot as they have been scaled down). Which does not have the range listed in the internal networks. 

It appears that you are using the application monitoring feature which will see and report on the internal traffic. From your policy or policies. If you go to Application Control Categroies. Click the "Details All" Button. You can Change Directory and Authentication to Allow. This will no longer log those activities which should only be occuring internally in the network anyways.

Andy G's picture
30
Nov
2011
0 Votes 0
Login to vote

Hi, Apologies - have attached

Hi, Apologies - have attached a better image of the network configuration page. Within the policies I have enabled the Directory and Authentication to Allow, but the traffic is still showing up. Puzzling.

Picture 3.jpg
BenDC's picture
30
Nov
2011
1 Vote +1
Login to vote

After making the policy

After making the policy changes did you click save and activate changes at the Policies:Configuration page?

Are the numbers in the report still increaseing or holding steady?

Andy G's picture
30
Nov
2011
0 Votes 0
Login to vote

The policy has been in place

The policy has been in place for some time now and yes the policy was activated. However I have altered the priority of a policy in terms of the nesting capabilities in order to test the one policy affecting the whole company, and not just a sub group (Active Directory OU).

Hopefully this will give am more clearer pictur eof the traffic flow.

BenDC's picture
30
Nov
2011
1 Vote +1
Login to vote

If any of the policies still

If any of the policies still have it set to monitor it will still show up for any users/systems that it applies to. So you may need to switch it to monitor in all the policies to have it stop all together.

Andy G's picture
01
Dec
2011
0 Votes 0
Login to vote

The policies are set to

The policies are set to either allow or block for Application Control Categories, so I would naturally assume that they would not appear in the logs unless the block rule was initiated.

Does anyone know of any other setting/configuration item which may need to be set to ensure that all non-pertinent internal traffic is logged (unless picked up by the blocking rules)?

 

Mnay thanks,

Andy

fferaboli's picture
01
Dec
2011
0 Votes 0
Login to vote

Hi, I guess that in tap mode

Hi,

I guess that in tap mode SWG is going to see as much as the tap port will forward to SWG.

If the ports of the switch are "seeing" internal traffic, a copy of each of those packets will be replicated into the tap so from the SWG configuration I cannot see a way to hide that but maybe I'm wrong.

Federico

 

 

 

TSE-JDavis's picture
02
Dec
2011
1 Vote +1
Login to vote

You may have the Web Gateway

You may have the Web Gateway in the wrong place. It should be placed on the switch closest to the firewall to avoid all of this traffic hitting the Web Gateway.