Skip to content

Blacklisted Flow Alarms #9839

@pctsa

Description

@pctsa

Environment:

  • OS name: Debian 12 Bookworm
  • OS version: 12 Bookworm
  • Architecture: amd64/8 Core/980 GB/RAM 16.8GB
  • ntopng version/revision: 6.7.251120
  • Browsere: Firefox ESR

What happened:

After the NTOPNG update on November 6, 2025, a large number of blacklisted flow alarms have appeared. This primarily affects Microsoft 365 communication with its servers. Investigations have now shown that none of these servers are blacklisted. All Windows machines with MS365 are displaying these alarms.

I cannot see this TLS issue with Wireshark.

Image Image Image

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions