> Source: [sk92985](https://support.checkpoint.com/results/sk/sk92985)

# sk92985 - Security Gateway in Monitor Mode does not block traffic

| Property | Value |
|----------|-------|
| Solution ID | sk92985 |
| Date Created | 2013-10-07 |
| Last Modified | 2015-08-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- Security Gateway, which in deployed in-line (i.e., connected between different networks), stopped blocking traffic after enabling '`Monitor Mode`' on an interface (even if the IPS / Anti-Virus / Anti-Bot / Application Control policy is set to "Prevent" / "Block").

## Cause

By design, the following applies when an interface on Security Gateway is configured in Monitor Mode:

* The interface in Monitor Mode (mirror port) neither enforces any security policy, nor performs any active operations (prevent/drop/reject).  
  Therefore, you can *only* use mirror port to evaluate the monitoring and detecting capabilities of the software blades.
* All duplicated packets arriving at the monitor interface of the Security Gateway are terminated and will not be forwarded in any way.
* Security Gateway in Monitor Mode does not send any traffic through the monitor interface.

## Solution

Follow ***one*** of these two options:

* **Either** disable Monitor mode on all interfaces of Security Gateway,  

* **Or** follow [sk101670 (Monitor Mode on Gaia OS and SecurePlatform OS)](http://supportcontent.checkpoint.com/solutions?id=sk101670) to correctly configure Security Gateway in Monitor mode.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
