Monitoring and Analyzing Switch Operation

Traffic Mirroring

 

Mirrored Traffic Destinations

 

Local Destinations

 

A local mirrored traffic destination is a port on the same switch as the source

 

of the traffic being mirrored.

 

 

C a u t i o n

Configuring a mirroring source switch with the destination and traffic selec-

 

tion criteria for a given mirroring session causes the switch to immediately

 

begin mirroring traffic to that destination.

 

Monitored Traffic Sources

 

You can configure mirroring for traffic entering or leaving the switch on:

Ports and static trunks: Provides the flexibility for mirroring on indi- vidual ports, groups of ports, and/or static port trunks.

Criteria for Selecting Mirrored Traffic

On the monitored sources listed above, you can configure the following criteria to select the traffic you want to mirror:

Direction of traffic movement (entering or leaving the switch, or both)

Source and/or destination MAC addresses in packet headers

Mirroring Sessions

A mirroring session consists of a mirroring source and destination. A mirroring source can be a port or static-trunk list. For any session, the destination must be a single (exit) port.

Multiple mirroring sessions can be mapped to the same exit port, which provides flexibility in distributing hosts such as traffic analyzers or an IDS.

Mirroring sessions can have the same or a different destination. You can configure an exit port on the local (source) switch as the destination in a mirroring session. When configuring a mirroring destination, take into account the following options:

Mirrored traffic belonging to different sessions can be directed to the same destination or to different destinations.

You can reduce the risk of oversubscribing a single exit port by directing traffic from different session sources to different exit ports.

You can segregate traffic by type, direction, or source.

B-26