Specifications

Configuring Port Mirroring clear port broadcast
4-52 Port Configuration
Configuring Port Mirroring
TheMatrixdeviceallowsyoutomirror(orredirect)thetrafficbeingswitchedonaportorVLAN
forthepurposesofnetworktrafficanalysisandconnectionassurance.Whenportmirroringis
enabled,oneportbecomesamonitorportforanotherportorVLANwithinthedevice.
Supported Mirrors
ThefollowingtypesofportscanparticipateinmirroringontheMatrixSeriesdevice:
•Physicalports, includingfrontpanelandFTM1ports
•Virtualports,includingLinkAggregationGroup(LAG)andhostports.Fordetailson
configuringportsforlinkaggregation,refertoConfiguringLACPonpage 4 56.
•VLANports.For
detailsonconfiguring802.1QVLANs,refertoChapter 7.
•IDS(IntrusionDetectionSystem)portsconfiguredaspartofaLAG.
IDS Mirroring Considerations
AnIDSmirrorisaonetomanyportmirrorthathasbeendesignedforusewithanIntrusion
DetectionSystem.ThefollowingconsiderationsmustbetakenintoaccountwhenconfiguringIDS
mirroringontheMatrixdevice:
•Asofrelease5.xx.xx,mirroringofmultiple(unlimitednumberof)sourceportstoan
IDS
destinationportissupported.
•EightdestinationportsmustbereservedforanIDSmirror.
•AllDIP/SIPpairswillbetransmittedoutthesamephysicalport.
•AllnonIPtrafficwillbemirroredoutthefirstphysicalportinaLAG.Thisportwillalsobe
usedforIPtraffic.
•Portfailureor
linkrecoveryinaLAGwillcauseanautomaticredistributionoftheDIP/SIP
conversations.
Active Destination Port Configurations
TheMatrixNSAdevicesupports64mirroringdestinationports.EachMatrixDFEPlatinumSeries
devicesupports16mirroringdestinationports.Theseportscanbeamixedvarietyofport,VLAN,
andIDScombinations.Anyoralldestinationportscanbeconfiguredinamanytoonemirroring
configuration(thatis,many
sourcesmirroredtoonedestination).Examplesofdestinationport
configurationsonaDFEPlatinumSeriesmoduleinclude:
•16portmirrors
•16VLANmirrors
•8portand8VLANmirrors
•12portand4VLANmirrors
•8portand1IDSmirror(wherethedevicemirrorsto8ports)
•8VLANand1
IDSmirror(wherethedevicemirrorsto8ports)
Caution: Port mirroring configuration should be performed only by personnel who are
knowledgeable about the effects of port mirroring and its impact on network operation.