Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Packets Dropped for Legitimate Traffic and Generated Alerts
This section provides troubleshooting procedures when the Gateway IDS/IPS traffic inspection engine drops data packets for legitimate traffic and generates alerts. For example, you try to access your email account in a web browser and notice that the page does not load as expected. This issue generates an alert for the threat event type. One of the reasons could be because some data packets are dropped by the traffic inspection engine.
To troubleshoot this scenario, complete the following steps:
- To allow blocked traffic to flow, Gateway IDS/IPS allows you to move a threat signature to the in the following ways:
- To move a threat signature to from the page, complete the following steps:
- In the WebUI, complete one of the following steps:
- To configure a Branch Gateway group, complete the following steps:
- Set the filter to a group containing at least one Branch Gateway that supports Gateway IDS/IPS.
The dashboard context for a group is displayed. - Click .
- Click the icon to view the Branch Gateway group configuration dashboard.
- Set the filter to a group containing at least one Branch Gateway that supports Gateway IDS/IPS.
- To configure a Branch Gateway, complete the following steps:
- Set the filter to or a group containing at least one Branch Gateway that supports Gateway IDS/IPS.
- Under , click > .
A list of gateways is displayed in the List view. - Click a gateway under .
The dashboard context for the gateway is displayed.
- To configure a Branch Gateway group, complete the following steps:
- Under , click > .
- Click the
icon to view the table. -
Select a threat and click icon (
).The window is displayed.
-
Click .
The threat is moved to .
- In the WebUI, complete one of the following steps:
- To move a threat signature to from the page, complete the following steps:
- In the WebUI, complete one of the following steps:
- To configure a Branch Gateway group, complete the following steps:
- Set the filter to a group containing at least one Branch Gateway that supports Gateway IDS/IPS.
The dashboard context for a group is displayed. - Click .
- Click the icon to view the Branch Gateway group configuration dashboard.
- Set the filter to a group containing at least one Branch Gateway that supports Gateway IDS/IPS.
- To configure a Branch Gateway, complete the following steps:
- Set the filter to or a group containing at least one Branch Gateway that supports Gateway IDS/IPS.
- Under , click > .
A list of gateways is displayed in the List view. - Click a gateway under .
The dashboard context for the gateway is displayed.
- To configure a Branch Gateway group, complete the following steps:
- Under , click >.
- Click the icon to view the configuration page.
- Click the tab, and select a policy to view the policy details.
- In the table, select a row and click the
icon. The window is displayed.
To move multiple rules to Allow List, select the rows and click
In the table, use the
icon in the column to filter the signatures that you want to move to . - Click .
The rules might take up to 10 minutes to take effect after the traffic flow stops.
- In the WebUI, complete one of the following steps:
- To move a threat signature to from the page, complete the following steps:
- After moving the threat signatures to , contact Technical Support for further assistance.
