Can Flowmon display data encapsulated in ESP protocol?





Flowmon can display ESP traffic only in special cases in which the traffic is unencrypted. However in most cases, it can't.


We think it can't show anything since it is ESP traffic, is that correct?

In Probe's monitoring port settings, ESP can be selected as the tunnel protocol decapsulation.
We assume Flowmon cannot decrypt ESP traffic, what does this check control?

There is the "ESP" decapsulation option on the monitoring port.


This option enables ESP tunnel parsing when the ESP payload is not encrypted, which is not the case here.

The decapsulation option on the monitoring port works only for the "null encryption", which means that the ESP communication isn't encrypted. It is used only in special rare cases. See the RFC:

In every other case Flowmon cannot see (decipher) ESP communication - to decipher such communication, the Flowmon appliance would effectively need to function as Man in the middle attacker, which is not the goal of the passive monitoring that Flowmon provides.


