I need to gather a list of connections between all pairs of Kubernetes containers over a given time. After attempting to gather this data from the Twistlock, I have some questions.
1. What is the difference between the learned connections shown in the Radar view and in the Firewalls view? The views can be found in these places:
a. Radar >> click on a connection line >> Connection info (source: learned)
b. Firewalls >> Cloud Native Network Firewall >> Container >> Allowed learned connections >> Show connections
2. Is there any way to gain visibility into the period when Radar/CNNF are (or were) in learning mode for a given container?
3. Unlike in the Radar view, I cannot see any learned connections in the CNNF view. I receive a “Failed to get learned connections” error. What would be the best way to troubleshoot this error? It does not appear in the Twistlock documentation and does not seem to correlate with any errors in the console logs.
There should be no differences between the Radar and Firewalls view. Do you mind elaborating further on this?
How do you tell when it's in learning mode? This article explains in detail
As far as failing to get learned connections goes, this could be caused by several reasons. I recommend opening a case with support about that error.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!