Virtual Secure Web Gateway

 View Only
Expand all | Collapse all

Nothing capturing on web gateway

  • 1.  Nothing capturing on web gateway

    Posted May 04, 2012 04:09 PM

    I have the symantec virtual appliance deployed right now and it is currently in port/tap mode. Both the management and monitor ports are up, but I am still unable to see traffic on appear on the gateway or any of the web destinations. I went to configure a policy but I don't see much for monitoring web traffic. What is the cause of this exactly?



  • 2.  RE: Nothing capturing on web gateway

    Broadcom Employee
    Posted May 04, 2012 04:37 PM

    The main things that cause this are correctly setting your internal network, having a policy in place effecting the users you want to monitor and ensuring that the switch you have hooked the monitor port to is sending all of the data it sees to that port.

     

    As an example, if a client's IP address is 192.168.23.5, you need to set the list of internal networks to include the 192.168.23.0 network. You would need a policy set up to monitor the category of the website they access for their IP range or All Computers. Finally, their traffic out to the web needs to flow through the switch or router you have connected the Web Gateway to and the switch or router needs to be configured to mirror the traffic it sees to the span port you have connected the monitor port to.



  • 3.  RE: Nothing capturing on web gateway

    Posted May 04, 2012 05:06 PM

    Hi Davis,

     

    The web gateway is hooked up via the vSwitch on my esxi server so how owuld I get the span port to work? Under administration I configured the internal network and even included a static route for it. 



  • 4.  RE: Nothing capturing on web gateway

    Broadcom Employee
    Posted May 04, 2012 05:28 PM

    I have no idea how your switch works, so I cannot help you there. There is typically a setting for this in the management utility you used to set it up. The bottom line is that the traffic has to be directed our way for us to be able to see it. We have no way to pull that data in from your network.

    The static route is helpful for us to be able to send block pages to the client, but that has nothing to do with us seeing which web pages your users are requesting.



  • 5.  RE: Nothing capturing on web gateway

    Posted May 04, 2012 06:52 PM

    Pretty much a general break down is we have a router and then a switch.

    Then I have my hypervisor (vmware server) which connects to a switch port on the switch. The virtual machines connect to a virtual switch on which allows the traffic to be sent to the main switch and routed out through the router. 


    Is there any documentation of how to re-direct the traffic to the web gateway? I can do it on the router, but that would actually cause an outage. 



  • 6.  RE: Nothing capturing on web gateway

    Broadcom Employee
    Posted May 04, 2012 07:05 PM

    From what you described, it sounds like your VM host machine only has one NIC. You need to have at least two physical NICs for the Web Gateway. You need to turn on a tap port on your router and the cable from that port would need to connect to the virtual host's physical NIC that is connected to the virtual switch that the virtual NIC for the Monitor port is connected to.

    Since there are so many brands of routers and switches, we do not provide those instructions. You should contact the manufacturer of your router to find out how to set one of the ports as a tap port.



  • 7.  RE: Nothing capturing on web gateway

    Posted May 08, 2012 12:47 PM

    Hi Davis,

    I actually have a span port setup on the switch now. Now when I go onto the web gateway and go to policies I only see things in regards spyware but nothing about monitoring the web destinations.



  • 8.  RE: Nothing capturing on web gateway

    Posted May 08, 2012 03:24 PM

    Are the counters on the excutitive summary page showing any data?

    Have any policies been configured to monitor traffic?

    Is the virtual switch for the span port set to permit promiscious mode?



  • 9.  RE: Nothing capturing on web gateway

    Posted May 08, 2012 03:36 PM

    I actually see in the executive summary where it says URLs inspected that it says 36. And this is after I switched the physical adapter on the vmware card to accept promiscious mode. And I configured one policy and its set to monitor all, but I do not see how I can view the urls.



  • 10.  RE: Nothing capturing on web gateway

    Broadcom Employee
    Posted May 08, 2012 04:22 PM

    Have you tested from a client by going to http://testwebgateway.com and clicking on the items that should be blocked? Once you get a block, it should record these in the Custom Reports section.

    From what you have described, it doesn't sound like you have purchased the content filtering license. This is required to gain access to the categories you can filter normal web taraffic with. Otherwise we will just be looking for spyware activity and malware sites.



  • 11.  RE: Nothing capturing on web gateway

    Posted May 08, 2012 05:17 PM

    I actually got it up I gave it a separate IP address and all seems to well. But just to confirm so I cannot view the inspected URLs?



  • 12.  RE: Nothing capturing on web gateway

    Broadcom Employee
    Posted May 08, 2012 11:54 PM

    Without the content filtering license, you would need to manually put a URL into a category using the Blacklist. You can test this by adding a site such as facebook.com or google.com into the blacklist under a category such as Spyware. You would then add that category to your policy and set it to Monitor. Then browse that site from one of your clients and you should see it recorded.



  • 13.  RE: Nothing capturing on web gateway

    Posted May 09, 2012 12:13 PM

    Good and bad news traffic is coming through and some sites are being seen. For instance I went on msnbc.com on my endpoint server and it shows it doing that. However, other machines don't show the sites still. And I have a ton of uncatergorized urls which are to my endpoint server.



  • 14.  RE: Nothing capturing on web gateway

    Broadcom Employee
    Posted May 09, 2012 12:23 PM

    We are far from categorizing everything, mostly due to the constant changing of URLs purposes, what they post, new domains popping up every day, etc.

    You will still need to make sure the other clients' IPs are in the internal network subnet(s) you told us about, the policy covers them and that their web traffic flows through the router we are tapped into. As long as all three of these are satisfied, the Web Gateway will monitor their traffic and record it.



  • 15.  RE: Nothing capturing on web gateway

    Posted May 10, 2012 09:44 AM

    What is the current database version/date seen under administration -> updates?

     



  • 16.  RE: Nothing capturing on web gateway

    Posted May 10, 2012 10:13 AM

    Current DB is

    Current Version 5.0.0.380 (installed at 05/09/12 17:59:55)