Wfilter is not continuously monitoring online computers.

General discussion about WFilter ICF features, problems, configuration issues etc.

Moderators: imfirewall, gengw2000

remyo
Posts: 3
Joined: Wed Dec 15, 2010 2:42 am

Wfilter is not continuously monitoring online computers.

Postby remyo » Tue Dec 28, 2010 2:07 am

Wfilter is not continuously monitoring online systems. For some reason it is not recognizing all the user accounts and if it does it happens intermittently, so employees are getting access to blocked content intermittently. It shouldn´t work like that.



I´m afraid reports are not accurate either since AD people are not showing as monitored when they should.



Basically, right now I have 55 computers checked as monitored, over 30 pcs with logged on users and no more than 20 online computers with the WFilter. Why is that happening? I´ve refreshed the screen several times and still not showing them all.



gengw2000
Posts: 281
Joined: Mon Sep 07, 2009 11:11 pm

Wfilter is not continuously monitoring online computers.

Postby gengw2000 » Tue Dec 28, 2010 2:18 am

If a computer does not show up in "online computers", it means WFilter can not detect its traffic. And there will be no report of this computer either.



This issue is related to the network topology and port mirroring settings. For example, if a computer is connected to an uplayer device of the manageable switch, it will bypass the monitoring. I guess maybe one of your switches is directly connected to the router/firewall. Can you find something in common for the un-monitored computers?(for example, maybe they are connected to a same switch)



Can you tell me more about your network topology and port mirroring settings? I need to know: network topolgy, mangeable switch model, source mirrored port and the target mirroring port.



You may check these deployment example for more about the port mirroring settings: WFilter deployment examples



And we recommend you to only set the internet port(router or firewall) as the source mirrored port. "one to one mirroring" is more efficient than "multiple to one mirroring".

remyo
Posts: 3
Joined: Wed Dec 15, 2010 2:42 am

Wfilter is not continuously monitoring online computers.

Postby remyo » Thu Dec 30, 2010 2:08 am

Please see our topology attached. I´ve mirrored port 23 which is our

internet port, with port 20. Then I connected a 2nd nic

card from my pc to this port.



Disconnected port 23 to see if there was traffic going on somewhere

else, but the internet connection was lost on all computers.



Let me know if I skipped anything.

Attached files

gengw2000
Posts: 281
Joined: Mon Sep 07, 2009 11:11 pm

Wfilter is not continuously monitoring online computers.

Postby gengw2000 » Thu Dec 30, 2010 2:41 am

I noticed you have a wireless router/AP. This might be the reason.



If it is a router with NAT service, it will translate all client computers ip addresses to its WAN ip address. In another word, all client computers of this router will be monitored as ONE computer only.



Please confirm it. If it's true, you need to disable the NAT feature of the wireless router for WFilter to monitor individual client computers of this wirless device.



There have two solutions:

1). Disable the NAT feature if the wireless router has such an option.

2). If no such an option in the router's UI, you need to leave the WAN port as disconnected, and connect one LAN port of your wireless router to the switch. By doing this, the wireless router is turned to a wireless switch, and no ip address will be translated.

For the second solution, if your wireless router provides DHCP service, you also need to narrow its DHCP ip range to avoid ip confliction.




Return to “WFilter ICF”

Who is online

Users browsing this forum: No registered users and 30 guests