Port Mirroring
SecureStack C2 Configuration Guide 7-33
Port Mirroring
TheSecureStackC2deviceallowsyoutomirror(orredirect)thetrafficbeingswitchedonaport
forthepurposesofnetworktrafficanalysisandconnectionassurance.Whenportmirroring is
enabled,oneportbecomesa monitorportforanotherportwithinthedevice.
Mirroring Features
TheSecureStackC2devicesupportsthefollowingmirroringfeatures:
• Mirroringcanbeconfiguredinamany‐to‐oneconfigurationsothatonetarget(destination)
portcanmonitortrafficonupto8sourceports.Onlyonemirrordestinationportcanbe
configuredperstack,ifapplicable.
•Bothtransmitandreceivetrafficwill
bemirrored.
•Adestinationportwillonlyactasamirroringportwhenthesessionisoperationallyactive.
•Whenaportmirroriscreated,themirrordestinationportisremovedfromtheegresslistof
VLAN1afterareboot.
•MACaddresseswillbelearnedforpacketstaggedwiththemirrorVLAN
ID.Thiswill
preventtheabilitytosnooptrafficacrossmultiplehops.
Configuring SMON MIB Port Mirroring
Overview
SMONportmirroringsupportonEnterasysSecureStackB2,B3,C2andC3devicesallowsyouto
redirecttrafficonportsremotelyusingSMONMIBs.Thisisusefulfortroubleshootingorproblem
solvingwhennetworkmanagementthroughtheconsoleport,telnet,orSSHisnotfeasible.
Procedures
PerformthefollowingstepstoconfigureandmonitorportmirroringusingSMONMIB objects.
Tocreat eandenableaportmirroringinstance:
1. OpenaMIBbrowser,suchasNetsightMIBTools
2. IntheMIBdirectorytree,navigatetotheportCopyEntryfolderandexpandit.
3. SelecttheportCopyStatusMIB.
4. Enteradesiredsource
andtargetportintheInstancefieldusingtheformatsource.target.
Forexample,3.2wouldcreatearelationshipwheresourceportge.1.3wouldbemirroredto
targetportge.1.2.
Caution: Port mirroring configuration should be performed only by personnel who are
knowledgeable about the effects of port mirroring and its impact on network operation.
Caution: Traffic mirrored to a VLAN may contain control traffic. This may be interpreted by the
downstream neighbor as legal control frames. It is recommended that you disable any protocols
(such as Spanning Tree) on inter-switch connections that might be affected .
Note: In order to configure a port mirroring relationship, both source and destination interfaces must
be enabled and operational (up).