search cancel

No SMTP traffic seen on newly installed monitor


Article ID: 160376


Updated On:


Data Loss Prevention Network Monitor


A sniffer utility (such as Dagsnap, Wireshark, etc.) is capturing traffic but no traffic is being reported through the Monitor UI.


  1. Check the IP Filters.  The filtering could be set up in such a way that no messages are generated and thus no traffic is captured. Be aware that IP traffic is evaluated in order against the filter entries until an entry matches the IP parameters.

To check the IP Filters from the Enforce UI:

Global:  Administration > Settings > Protocols

Server:  Administration > Overview > <detection server>. Click Configure tab and select protocol in question.

You can validate whether the IP filters are causing an issue by removing them and then check to see if traffic is being reported through the monitor.

For example, a filter of +,,*;-,*,* matches all IP traffic going to network 10.67.x.x but does not match any other traffic.

For more details on setting up IP Filters, please see KB TECH221378:  How to set up IP filters for Vontu Network Monitor

  1. If you have an Endace card, check that it is working properly.

For more information see TECH218779:  Endace Card is Not Recognized


  1. Check any SPAN or TAP ports that may be in use to be sure they are configured and working correctly.