Allied Telesis 2.6.1 manual Port Mirroring

Page 70

70

AT-8800 Series Switch User Guide

the BCLIMIT parameter description for important information about packet rate limiting. The default value for this parameter is NONE. If packet storm protection limits are set on the switch, the PORT parameter must specify complete processing blocks.

The ability of the switch to limit packet reception rates for different classes of packets is dependent on the particular switch hardware. In particular, groups of ports may have to have the same limits set, and the same limit may be set for the different types of packets, depending on the hardware. Whenever packet rate limits are set on switches which have this type of constraint, the latest parameter values entered will supersede earlier values. When a command entered for specified ports changes the parameters for other ports, a message will indicate these changes.

The SHOW SWITCH PORT command displays the packet storm protection settings (Figure 12 on page 64).

SHOW SWITCH PORT=port-list

Port Mirroring

Port mirroring allows traffic being received and transmitted on a switch port to be sent to another switch port, the mirror port, usually for the purposes of capturing the data with a protocol analyser. This mirror port is the only switch port which belongs to no VLANs, and therefore does not participate in any other switching. Before the mirror port can be set, it must be removed from all VLANs except the default VLAN. The port cannot be part of a trunk group.

To set the mirror port (and remove it from the default VLAN) use the command:

SET SWITCH MIRROR={NONEport}

If another port was previously set as the mirror port, this command returns the previous mirror port to the default VLAN as an untagged port. Return this port to any VLANs to which it should belong, using the ADD VLAN PORT command, or set it as a tagged port using the SET VLAN PORT command if required.

Either traffic received on a port or traffic transmitted by the port, or both, can be mirrored. This setting and the source port(s) from which traffic is sent to the mirror port are specified using the command:

SET SWITCH PORT={port-listALL} MIRROR={NONERXTXBOTH}

Mirroring four or more ports may significantly reduce switch performance.

The MIRROR parameter specifies the role of these port(s) as a source of mirror traffic. If NONE is specified, no traffic received or sent on these port(s) will be mirrored. If RX is specified, all traffic received on these port(s) will be mirrored. If TX is specified, all traffic transmitted on these port(s) will be mirrored. If BOTH is specified, all traffic received and transmitted will be mirrored. Traffic will actually only be mirrored if there is a mirror port defined and if mirroring is enabled. The default is NONE.

Software Release 2.6.1 C613-02039-00 REV A

Image 70
Contents AT-8800 Series Switch Page Contents Operating the switch AT-8800 Series Switch User GuideMaintenance and Troubleshooting Page Why Read this User Guide? Introducing the AT-8800 Series SwitchChapter Where To Find More Information AT-8800 Series Switch Documentation SetOnline Technical Support Features of the AT-8800 Series SwitchIntroduction Management Features Software FeaturesSpecial Feature Licences Do if You Clear Flash Memory Completely on Getting Started with the Command Line Interface CLI This ChapterTerminal Communication Parameters Connecting a Terminal or PCParameters for terminal communication Value Logging Enter the password at the password promptGetting Started with the Command Line Interface CLI Assigning an IP AddressSetting Routes To change the IP address for an interface, enter the commandChoosing a Password Changing a PasswordTo add a static route, enter the command Using the Commands Not availableTo display the current help file, enter the command Getting Command Line HelpAliases Enabling Special Feature Licences Setting System ParametersGetting Started with the Graphical User Interface GUI Getting Started with the Graphical User Interface GUIBrowser and PC Setup What is the GUI?Accessing the Switch via the GUI Supported browsers and operating systemsHttp Proxy Servers See Option 1 Configuring the Switch before Installation on Establishing a Connection to the SwitchSee Option 3 Connecting to an Installed Switch on See Option 2 Installing the Switch into the LAN onUse this procedure if Option 1 Configuring the Switch before InstallationSee Http Proxy Servers on page 23 for more information At the login prompt, enter the user name and password Option 2 Installing the Switch into the LANDefault username is manager Plug the switch into the LANSee Secure Access on page 29 for more information Assign the vlan1 interface an IP addressSelect a PC Option 3 Connecting to an Installed SwitchFind out the IP address of the switch’s interface If necessary, bypass the Http proxy serverSecure Access Create a Security Officer user accountTo enable system security, use the command Then enter the password for CIPHER, sbr4y3To create an RSA key pair, use the command System Status System StatusUsing Configuration Pages Using the GUI Navigation and FeaturesConfiguration Menu Quality of Service and traffic filtersAn example of a configuration page with a selection table Editable Fields Management Menu Monitoring MenuChanging the Password Diagnostics MenuContext Sensitive GUI Help Combining GUI and CLI Configuration Saving Configuration Entered with the GUIConfiguring Multiple Devices Load the new file onto the switch To upgrade the GUIThen delete the GUI resource file, using the command Upgrading the GUIInstall the new file as the preferred GUI TroubleshootingPoint your web browser at the switch’s IP address Accessing the Switch via the GUI Deleting Temporary FilesTraffic Flow IP Addresses and Dhcp SolutionSolutions Time and NTPLoading Software Page Snmp and MIBs on Using Scripts onUser Accounts and Privileges A Security Officer prompt looks likeLogin To display the current operating mode, enter the command Normal Mode and Security ModeOperating the switch Specific Parameters Remote Management Storing Files in Flash MemoryUsing Scripts Example output from the Show File commandSaving the Switch’s Configuration Storing Multiple ScriptsFile Naming Conventions Loading and Uploading FilesFile extensions and file types Extension File type/function Loading Files SPATo load a patch file Configure the Loader Setting Loader DefaultsExample Load a Patch File Using Http Download the patch fileMore information Uploading Files From the SwitchExample Upload a Configuration File Using Tftp To upload a log fileUpgrading Switch Software To upgrade to a new software release Example Upgrade to a New Software Release UsingLoad the new release file onto the switch Enter licence information for the release Enter the licence password for the software releaseMake the release the default permanent release Test the releaseTo upgrade to a new patch file Example Upgrade to a new patch fileCheck that the file is successfully loaded Using the Built-in Editor Snmp and MIBsWhere interface is the name of an interface, such as vlan11 For More About Operations and FacilitiesAT-8800 Series Switch User Guide Switch Ports Enabling and Disabling Switch PortsTo enable or disable a switch port, use the commands To display information about switch ports, use the commandSTP Autonegotiation of Port Speed and Duplex Mode Port Trunking Speed 10/100Show VLAN=ALL Layer 2 Switching Packet Storm ProtectionPort Mirroring Port security Example output from the Show Switch Port Intrusion command Virtual Local Area Networks VLANsVlan Tagging TpidFormat of user priority and Vlan data in an Ethernet frame Vlan Membership using Vlan Tags Vlan Membership of Untagged Packets Vlan membership of example of a network using tagged portsMember ports Creating VLANs Vlans with untagged portsTo add tagged ports to a VLAN, use the command To destroy a VLAN, use the commandProtected VLANs Summary of Vlan tagging rulesVlan Interaction with STPs and Trunk Groups Generic Vlan Registration Protocol Gvrp Layer 2 Switching ProcessIngress Rules Learning Process Forwarding Process Layer 2 Filtering Example output from the Show Switch Filter command Quality of Service Egress RulesSpanning Tree Protocol STP Spanning Tree ModesSpanning tree port states State Meaning Spanning Tree and Rapid Spanning Tree Port StatesRapid Spanning Tree port states State Meaning Configuring STP SET STP=stpnameALL PRIORITY=0..65535 Example output from the Show STP command Do not occur Switch Max Age Parameter MeaningTo display STP port information, use the command 94AT-8800 Series Switch User Guide Example output from the Show STP Port commandTo show STP counters, use the command Transmit 96AT-8800 Series Switch User GuideReceive DiscardedInterfaces to Layer 3 Protocols Igmp SnoopingDisable Igmpsnooping Example output from the Show IP Igmp command Group ListDescription TriggersEvent ParametersLayer Internet Protocol IP Then use either of the following commandsDisplays the interfaces enabled for IP routing Figure IP MulticastingNovell IPX Routing Information Protocol RIPLayer 103 Example output from the Show IPX Circuit command AppleTalkResource Reservation Protocol Rsvp Layer 105Page Maintenance and Troubleshooting How the Switch Starts Up Switch startup messagesHow to Avoid Problems Set system territoryWatch for software updates What to Do if You Clear Flash Memory Completely If you accidentally do this, you will need toWhat to Do if the PPP Link Disconnects Regularly What to Do if Passwords are LostGetting the Most Out of Technical Support To get debugging output, enter the command Resetting Switch DefaultsChecking Connections Using Ping Maintenance and Troubleshooting 113Stop a Ping that is in progress, enter the command Troubleshooting IP ConfigurationsTo set Ping defaults, enter the command Telnet FailsYour switch is acting as a Dhcp server Troubleshooting Dhcp IP AddressesYour switch is acting as a Dhcp client Maintenance and Troubleshooting 115Local Workstations Can Not Access Remote Servers Troubleshooting IPX ConfigurationsTo check that the PPP link is active, enter the command No Routes are Visible to the Remote RouterUsing Trace Route for IP Traffic Check route tablesTo halt a trace route that is in progress, enter the command