Hello Namal,
The host, on which the ATA Gateway VM was deployed, and all the domain controllers should be connected to the same physical switch.
On the physical switch, you need to configure the SPAN settings to copy the traffic on the ports of domain controllers, to the port of Hyper-V host.
If the VM was deployed on the Hyper-V host, please refer to the following link for configurations on Hyper-V.
https://blogs.technet.microsoft.com/networking/2015/10/16/setting-up-port-mirroring-to-capture-mirrored-traffic-on-a-hyper-v-virtual-machine/
Additional information about port mirroring for Advanced Threat Analytics, please check the link below.
https://blogs.technet.microsoft.com/pfesweplat/2015/12/23/port-mirroring-for-advanced-threat-analytics/
Regards,
Andy Liu
Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact
tnmff@microsoft.com.