Specifications
Configuring Port Mirroring clear port broadcast
4-52 Port Configuration
Configuring Port Mirroring
TheMatrixdeviceallowsyoutomirror(orredirect)thetrafficbeingswitchedonaportorVLAN
forthepurposesofnetworktrafficanalysisandconnectionassurance.Whenportmirroringis
enabled,oneportbecomesamonitorportforanotherportorVLANwithinthedevice.
Supported Mirrors
ThefollowingtypesofportscanparticipateinmirroringontheMatrixSeriesdevice:
•Physicalports, includingfrontpanelandFTM‐1ports
•Virtualports,includingLinkAggregationGroup(LAG)andhostports.Fordetailson
configuringportsforlinkaggregation,referto“ConfiguringLACP”onpage 4 ‐56.
•VLANports.For
detailsonconfiguring802.1QVLANs,refertoChapter 7.
•IDS(IntrusionDetectionSystem)portsconfiguredaspartofaLAG.
IDS Mirroring Considerations
AnIDSmirrorisaone‐to‐manyportmirrorthathasbeendesignedforusewithanIntrusion
DetectionSystem.ThefollowingconsiderationsmustbetakenintoaccountwhenconfiguringIDS
mirroringontheMatrixdevice:
•Asofrelease5.xx.xx,mirroringofmultiple(unlimitednumberof)sourceportstoan
IDS
destinationportissupported.
•EightdestinationportsmustbereservedforanIDSmirror.
•AllDIP/SIPpairswillbetransmittedoutthesamephysicalport.
•Allnon‐IPtrafficwillbemirroredoutthefirstphysicalportinaLAG.Thisportwillalsobe
usedforIPtraffic.
•Portfailureor
linkrecoveryinaLAGwillcauseanautomaticre‐distributionoftheDIP/SIP
conversations.
Active Destination Port Configurations
TheMatrixNSAdevicesupports64mirroringdestinationports.EachMatrixDFE‐PlatinumSeries
devicesupports16mirroringdestinationports.Theseportscanbeamixedvarietyofport,VLAN,
andIDScombinations.Anyoralldestinationportscanbeconfiguredinamany‐to‐onemirroring
configuration(thatis,many
sourcesmirroredtoonedestination).Examplesofdestinationport
configurationsonaDFE‐PlatinumSeriesmoduleinclude:
•16portmirrors
•16VLANmirrors
•8portand8VLANmirrors
•12portand4VLANmirrors
•8portand1IDSmirror(wherethedevicemirrorsto8ports)
•8VLANand1
IDSmirror(wherethedevicemirrorsto8ports)
Caution: Port mirroring configuration should be performed only by personnel who are
knowledgeable about the effects of port mirroring and its impact on network operation.