Recommendation fail to exclude Broadcast and Multicast flows
search cancel

Recommendation fail to exclude Broadcast and Multicast flows

book

Article ID: 398949

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

Recommendation job fail to exclude Broadcast and Multicast flows in SSP 

Environment

SSP 5.0
NSX releases prior to 4.2.2

Cause

Private-ip range not set under SSP instance -> Systems -> Private IP-Range;  leading to broadcast traffic flows being shown under recommendation job

Resolution

Prior to NSX 4.2.2, do mention the private IP range setting and include the exact domain in the settings i.e. xx.xx.xx.0/24
The new flows should then be tagged as broadcast. Check using visualization filters if they are being recognized as broadcast flows. If that works, then use recommendation within the time range of the IP range setting change and verify if the flows are excluded.

Other way would be to use the exclude ports option in Recommendation advanced settings to exclude those flows if they know the destination ports for such flows.


Note: - In NSX 4.2.2 &  ESX 9.0 host will be able to check for L2 MAC address used to classify the broadcast flows correctly even if private IP range is not updated to include all L2 domains.