If you suspect that the traffic monitored by your appliance contains asymmetric flows, follow these guidelines to locate the source of the asymmetric traffic.
Important
To avoid depleting system resources and degrading appliance performance, enable this feature only while you are collecting and viewing the statistics needed to investigate asymmetric flows in the network.
Check the ratio of asymmetric traffic to non-asymmetric traffic.
See Viewing the number of asymmetric flows using the CLI.
Note
On SmartVision Mode sensors, the suspicious objects that Trellix Unified Multiflow Engine (FUME) sends to the virtual machine (VM) to detect multiflow attacks are limited .exe and .dll files over SMB and SMB 2.
If the ratio is high, begin caching statistics about the asymmetric traffic flows.
See Enabling asymmetric flow statistics collection using the CLI.
Analyze the cached traffic flow statistics. Statistics for SYN‑only flows and non-SYN‑only asymmetric flows are listed separately. Within each list, statistics for the most frequently occurring flow profiles are listed first.
(Optional) If a list is at or near its capacity of 100 unique flow profiles, you can refresh the cache, enabling the appliance to collect statistics for the latest traffic.
See Refreshing the asymmetric flow statistics cache using the CLI.
IMPORTANT! When you are no longer actively investigating asymmetric flows, stop caching asymmetric traffic flow statistics.
See Disabling asymmetric flow statistics collection using the CLI.