Specifications
Port Mirroring
SecureStack C3 Configuration Guide 4-33
Example
Thisexampleclearsthebroadcastthresholdlimitto14881ppsforports1through5:
C3(su)->clear port broadcast ge.1.1-5 threshold
Port Mirroring
TheSecureStackC3deviceallowsyoutomirror(orredirect)thetrafficbeingswitchedonaport
forthepurposesofnetworktrafficanalysisandconnectionassurance.Whenportmirroringis
enabled,oneportbecomesamonitorportforanotherportwithinthedevice.
Mirroring Features
TheSecureStackC3devicesupportsthefollowingmirroringfeatures:
• Mirroringcanbeconfiguredinamany‐to‐oneconfigurationsothatonetarget(destination)
portcanmonitortrafficonuptosourceports.Onlyonemirrordestinationportcanbe
configuredperstack.
•Bothtransmitandreceivetrafficwillbemirrored.
•A
mirroringsessionwhichisconfiguredtobeactive(enabled)willbeoperationallyactive
onlyifbothadestinat ionportandatleastonesourceporthavebeenconfigured.
•Adestinationportwillonlyactasamirroringportwhenthesessionisoperationallyactive.If
themirroringsessionisnotoperationally
active,thenthedestinationportwillactasanormal
portandparticipateinallnormaloperationwithrespecttotransmittingtrafficand
participatinginprotocols.
Remote Port Mirroring
Remoteportmirroringisanextensiontoportmirroringwhichfacilitatessimultaneousmirroring
ofmultiplesourceportsonmultipleswitchesacrossanetworktooneormoreremotedestination
ports.
Remoteportmirroringinvolvesconfigurationofthefollowingportmirroringrelatedparameters:
1. Configurationofnormalportmirroringsourceportsandone
destinationportonallswitches,
asdescribedabove.
2. ConfigurationofamirrorVLAN,whichisauniqueVLANonwhichmirroredpackets
traverseacrossthenetwork.ThemirrorVLANhastobeconfiguredonALLswitchesacross
thenetworkalongwhichmirroredtraffictraverses,fromtheswitchwherethesource
ports
residetotheswitchwherethemirroredpacketsaresniffedand/orcaptured.
Youmustensurethatswitchesinvolvedareproperlyconfiguredtofacilitatecorrectremoteport
mirroringoperation.Thefollowingpointsinparticularneedtobeobserved:
•Onthesourceswitch,thecorrectdestinationportmustbechosentoensure
thatthereisan
egresspathfromthatporttothedesiredremotedestination(s).
Caution: Port mirroring configuration should be performed only by personnel who are
knowledgeable about the effects of port mirroring and its impact on network operation.
Note: This functionality is not supported on SecureStack A2, B2, or C2 products.