Monitoring and Analyzing Switch Operation

Traffic Mirroring

Depending on how many sessions are configured on the switch, you can use the same command to configure a MAC address as mirroring criteria in up to four sessions. To identify a session, you can enter either its name or number; for example: mirror 1 2 3 traffsrc4

Refer to “Mirroring-Source Restrictions” on page B-56for the restrictions on how many mirroring source criteria you can configure in the same session.

<1 - 4 >: Specifies a mirroring session by number (1 to 4), for which the configured MAC address is used to select and mirror inbound and/or outbound traffic.

[name < name-str >]: (Optional) Specifies a mirroring session by name (alphanumeric string), for which the configured MAC address is used to select and mirror inbound and/or outbound traffic. For a remote mirroring session, you must configure the same session name on both the source and destination switch.

R e s t r i c t i o n s

The following restrictions apply to MAC-based mirroring:

 

Up to 320 different MAC addresses are supported for traffic selection in

 

all mirroring sessions configured on the switch.

 

A destination MAC address is not supported as mirroring criteria for

 

routed traffic because in routed packets, the destination MAC address is

 

changed to the next-hop address when the packet is forwarded. There­

 

fore, the destination MAC address that you want to mirror will not appear

 

in routed packet headers.

 

This restriction also applies to the destination MAC address of a host that

 

is directly connected to a routing switch. (Normally, a host is connected

 

to an edge switch, which is directly connected to the router.)

 

To mirror routed traffic, it is recommended that you use classifier-based

 

policies to select IPv4 or IPv6 traffic for mirroring as described in “Select­

 

ing Inbound Traffic Using Advanced Classifier-Based Mirroring” on page

 

B-66.

 

On a switch, you can use a MAC address only once as a source MAC

 

address, and only once as a destination MAC address, to filter mirrored

 

traffic.

 

For example, after you enter the following commands:

 

monitor mac 111111-222222 src mirror 1

 

monitor mac 111111-222222 dest mirror 2

B-65