Hi,
when double checking the afcd and its classification as advised by Kai using afcd -S -f -r I found that the output of this debug mode and what is displayed in the Flow Monitor varies significantly.
A few of my findings:
- CIFS is not detected properly from the sole dump file, however it is shown correctly in the flow monitor
- Many other kinds of traffic - most significantly Google traffic and Skype are shown as "unknown" in the flow monitor, however they get correctly classified with the afcd debug mode.
Is this a known error? How should I proceed in terms of information providing to help you fix this problem?
Christian