Specifications

Overview of Port Mirroring Configurations on Enterasys Switches
May 04, 2011 Page 5 of 15
RefertotheLinkAggregationsectionofyourdevice’sConfigurationGuideorCLIReferenceformore
information.
Whenusedasasourceportinamirror,LAGportsactidenticallytoasinglephysicalport.Either
dynamicorstaticLAGscanbeusedassourceports.Whenusedasadestination
portinamirror,
themirrorisconfiguredasanIDSmirrorasdescribedinthenextsection.OnlystaticLAGscanbe
usedasdestinationports.
IDS Mirrors
SinceIDSdevicesarenormallybandwidthlimited,theybenefitfromdistributionofmirroreddata
acrossmultipleports(forexample,aGigabitportmirroredtomultiple FastEthernetports).
AnIDSmirrorisaonetomanyportmirrorthathasbeendesignedforusewithanIntrusion
DetectionSystem.Thetarget
(destination)portofanIDSmirrormustbeavirtualLAGportthat
youadministrativelysetcalledastaticLAG.Onceconfigured,anIDSmirrorloadsharestraffic
amongalldestinationportsintheLAGyousetastheportmirror.
Thesystemhashesthesourceportconversationbasedonsource
anddestinationIP(SIP/DIP)
addresspairsandsendsthesamepairsoutthesamephysicalportinthedestinationmirror. This
way,eachIDSdevicewillseealloftheconversationsbetween aDIP/SIPandwillnotduplicatethe
sameinformationoutmultipledestinationports.WhenIDSmirroringisenabled,the
system
performsaLayer3lookupforallframes.AllnonIPtraffic(includingcontrolframes)issenttoan
arbitrary,“designated”physicaloutport.ThisportisincludedintheDIP/SIPhashlist.Ifthe
switchdetectsafailureofanyofthephysicalportsintheLAG,it
willautomaticallyredistribute
theDIP/SIPconversationsamongtheremainingportsinthe LAG.WithIDSmirroring,source
trafficisloadsharedamongalldestinationportstoensurenopacketloss.
WhenconfiguringIDSmirroringonyourNSeriesDiamondorPlatinu m ,SSeries,orKSeries
device,youmusttakeinto
considerationthefollowing:
•OnlyoneIDSmirrorisallowedperchassis.
•Asofrelease5.xx.xx,mirroringofmultiple(unlimitednumberof)sourceportstoanIDS
destinationportissupported.
•TendestinationportsmustbereservedforanIDSmirror.
•AllDIP/SIPpairswillbetransmittedoutthesamephysicalport.
•Allnon
IPtrafficwillbemirroredoutthefirstphysicalportinaLAG.Thisportwillalsobe
usedforIPtraffic.
•PortfailureorlinkrecoveryinaLAGwillcauseanautomaticredistributionoftheDIP/SIP
conversations.
RefertoExample:ConfiguringanIDSMirroronpage 14formore
information.
Note: This function is supported only on N-Series Platinum and Diamond, S-Series, and K-Series
switches.