Specifications
May 04, 2011 Page 1 of 15
Configuring Port Mirroring
Thisdocumentprovidesthe followinginformationaboutconfiguringandmonitoringport
mirroringonEnterasys
®
N‐Series,S‐Series,K‐Series,andX‐Seriesmodularswitches,A‐Series,B‐
Series,C‐Seriesstackablefixedswitches,andD‐Series,G‐Series,andI‐Seriesstandalonefixed
switches.
What Is Port Mirroring?
Portmirroring,alsoknownasportredirect,isanetworktrafficmonitoringmethod.Itforwardsa
copyofeachincomingoroutgoingframe(orboth)fromoneormoreswitchportstoanotherport
orportswherethedatacanbestudied.Oncethebitstreamfromoneormoresource
portsis
mirroredtooneormoredestinationports,youcanfurtheranalyzethecaptureddatausingan
RMONprobe,anetworksniffer,oranIntrusionDetectionSystem(IDS),withoutaffectingthe
originalportʹsnormalswitchoperation.
Why Would I Use Port Mirroring in My Network?
Portmirroringisanintegrateddiagnostictoolfortrackingnetworkperformanceandsecuritythat
isespeciallyusefulforfendingoffnetworkintrusionandattacks.Itisalow‐costalternativeto
networktapsandothersolutionsthatmayrequireadditionalhardware,maydisruptnormal
networkoperation,mayaffectclientapplications,and
mayevenintroduceanewpointoffailure
intoyournetwork.Portmirroringscalesbetterthan somealternativesandiseasiertomonitor.Itis
convenienttouseinnetworkswhereportsarescarce.
Dependingonthetypesofswitchingdevicesonwhichyouwanttoimplementit,youcanset
up
thefollowingtypesofportmirroringrelationshipsoninboundoroutboundtraffic(orboth):
•One‐to‐one(sourceporttodestinationport)
•Many‐to‐one
•One‐to‐many
For information about... Refer to page...
What Is Port Mirroring? 1
Why Would I Use Port Mirroring in My Network? 1
How Do I Implement Port Mirroring? 3
Functions and Features Supported on Enterasys Switches 3
Overview of Port Mirroring Configurations on Enterasys Switches 4
Configuring Port Mirrors 6
Example: Configuring and Monitoring Port Mirroring 11
Example: Configuring an IDS Mirror 14