SSP 5.1.1 fails to generate micro-segmentation recommendations for multicast or broadcast traffic (such as UDP 5353 mDNS) when using the Rec Diff workflow. This occurs even when these flows are visible as Unprotected Flows and the user has explicitly enabled the "Include Broadcast Traffic" and "Include Multicast Traffic" settings
SSP 5.1.1
In SSP 5.1.1, the Rec Diff job incorrectly handles multicast and broadcast flows. During processing, the destination is converted to an IP (multicast address), causing both source and destination to be treated as IP-based entities. Because the flow direction logic compares these against context computes and finds that neither end is mapped to a compute entity, the flows are incorrectly filtered out of the recommendation generation
Currently there is no fix. This will be fixed in an upcoming version of SSP
As a temporary solution, use the New Section recommendation workflow instead of Rec Diff, as it is not impacted by this logic error: