Académique Documents
Professionnel Documents
Culture Documents
HOME
Advertising With Us
HOME
TOOLS
CONTACT US
THE RADAR
CONTACT US
CND Ltd
SEARCH PRODUCTS
Search
Search
Advanced Search
LINKS TO PRODUCTS
Extreme Newer
Extreme Older v4.1
Cisco SPAN Info
Cisco 2900 3500XL
Cisco
Cisco
Cisco
Cisco
PRODUCT DIRECTORY
Directory
Cloud Security Services
Boundary Guard Products
Network Anomaly Detection
Scanning Products
Visio Stencils
Uncategorised
show mirror
(shows status of mirroring, including whether the port is up or not (!))
One thing to be careful of in the Extreme is that with mirroring (at least in this version of the O/S), you get
both IN and OUT mirroring,
which means that if you pick a VLAN as the mirror object, you may see the same frame a couple of times if it
goes in one port on the VLAN and out a different one.
SPAN Sessions
TCP Countermeasures
No Limit
No
1
Yes
2
Yes
2
Yes
5
Yes
6 (both considered 2) No
2 Rx or Both, 4 Tx
Yes
2
No
port monitor vlan is only valid for VLAN 1, and will only monitor management traffic destined to the IP
address configured as VLAN 1 on the switch port monitor, by itself, will configure the port to monitor all
ports on the switch that belong to the vlan that port is assigned to.
FOUNDRY SWITCHES
Submitted By Kevin Farnes
Information Updated: 16 Aug 2004
( From Configuration Mode )
interface Interface
port monitor interface { rx | tx | both}
The first line takes you into the interface that the mirror output should be presented on. The second line
defines those interfaces you wish to have mirrored and whether just the input, output or both are copied.
JUNIPER M OR T SERIES
Submitted By Donald Smith
Information Updated: 20 Aug 2004
Port Mirroring
Define the destination where copies of sampled packets will be sent:
[edit]
user@router# show forwarding-options
port-mirroring { input {family inet; rate <sample-rate>; run-length
<run-length>;} output {interface <interface-name> {next-hop<address>;}
no-filter-check;} }
2. Define a sampling filter to identify "interesting" traffic:
[edit]
user@router# show firewall filter mirror-sample
from {...} then {sample; accept;}
3. Apply the filter to the incoming interface
[edit]
user@router# show interface <interface-name> unit 0 family inet
filter {input mirror-sample;}
Notes:
1. Packets that pass the input filter are sampled based on the <sample-rate> and <run-length>. In each
batch of <sample-rate> packets, the first <run-length> packets are mirrored.
2. The mirror interface should not participate in any routing. The sampled packets are not in any way
encapsulated, so the raw packets are sent out the interface. Hopefully, the device on the far end is a traffic
analyzer and not another router!
3. The <address> needs to be specified when the mirror interface is a multi-access media, and is used to fil
in the MAC address.
4. Works only for IPv4 packets, and only for transit traffic.
5. You can only set up one mirror interface per router; all "sampled" traffic is mirrored.