Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Checking the Threat Discovery Appliance (TDA) mirror packet traffic

    • Updated:
    • 2 Feb 2016
    • Product/Version:
    • Threat Discovery Appliance 2.0
    • Threat Discovery Appliance 2.5
    • Platform:
    • N/A N/A
Summary

Use this article to check whether or not the TDA mirror packet traffic is two-way.

Details
Public

Do the following:

  1. Using Wireshark, open the pcap file from the TDA console.
  2. Look for the TCP traffic (HTTP, SMTP). Right-click on the TCP traffic and then select Follow TCP Stream.

    Follow TCP Stream

Wireshark will only show the selected traffic session content.

One-Way Traffic

The image below shows the Source IP, 198.8.1.189, and the Destination IP, 192.168.33.102. This means that TDA received one-way traffic and that it cannot analyze this kind of traffic.

TDA One-Way Traffic

Two-Way Traffic

Two-way traffic information is similar to the screenshot below. The source field has Source and Destination IPs.

TDA Two-Way Traffic

Premium
Internal
Rating:
Category:
Troubleshoot
Solution Id:
1060172
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.