Specifications

May 04, 2011 Page 1 of 15
Configuring Port Mirroring
Thisdocumentprovidesthe followinginformationaboutconfiguringandmonitoringport
mirroringonEnterasys
®
NSeries,SSeries,KSeries,andXSeriesmodularswitches,ASeries,B
Series,CSeriesstackablefixedswitches,andDSeries,GSeries,andISeriesstandalonefixed
switches.
What Is Port Mirroring?
Portmirroring,alsoknownasportredirect,isanetworktrafficmonitoringmethod.Itforwardsa
copyofeachincomingoroutgoingframe(orboth)fromoneormoreswitchportstoanotherport
orportswherethedatacanbestudied.Oncethebitstreamfromoneormoresource
portsis
mirroredtooneormoredestinationports,youcanfurtheranalyzethecaptureddatausingan
RMONprobe,anetworksniffer,oranIntrusionDetectionSystem(IDS),withoutaffectingthe
originalportʹsnormalswitchoperation.
Why Would I Use Port Mirroring in My Network?
Portmirroringisanintegrateddiagnostictoolfortrackingnetworkperformanceandsecuritythat
isespeciallyusefulforfendingoffnetworkintrusionandattacks.Itisalowcostalternativeto
networktapsandothersolutionsthatmayrequireadditionalhardware,maydisruptnormal
networkoperation,mayaffectclientapplications,and
mayevenintroduceanewpointoffailure
intoyournetwork.Portmirroringscalesbetterthan somealternativesandiseasiertomonitor.Itis
convenienttouseinnetworkswhereportsarescarce.
Dependingonthetypesofswitchingdevicesonwhichyouwanttoimplementit,youcanset
up
thefollowingtypesofportmirroringrelationshipsoninboundoroutboundtraffic(orboth):
•Onetoone(sourceporttodestinationport)
•Manytoone
•Onetomany
For information about... Refer to page...
What Is Port Mirroring? 1
Why Would I Use Port Mirroring in My Network? 1
How Do I Implement Port Mirroring? 3
Functions and Features Supported on Enterasys Switches 3
Overview of Port Mirroring Configurations on Enterasys Switches 4
Configuring Port Mirrors 6
Example: Configuring and Monitoring Port Mirroring 11
Example: Configuring an IDS Mirror 14