Specifications
Overview of Port Mirroring Configurations on Enterasys Switches
May 04, 2011 Page 5 of 15
RefertotheLinkAggregationsectionofyourdevice’sConfigurationGuideorCLIReferenceformore
information.
Whenusedasasourceportinamirror,LAGportsactidenticallytoasinglephysicalport.Either
dynamicorstaticLAGscanbeusedassourceports.Whenusedasadestination
portinamirror,
themirrorisconfiguredasanIDSmirrorasdescribedinthenextsection.OnlystaticLAGscanbe
usedasdestinationports.
IDS Mirrors
SinceIDSdevicesarenormallybandwidthlimited,theybenefitfromdistributionofmirroreddata
acrossmultipleports(forexample,aGigabitportmirroredtomultiple FastEthernetports).
AnIDSmirrorisaone‐to‐manyportmirrorthathasbeendesignedforusewithanIntrusion
DetectionSystem.Thetarget
(destination)portofanIDSmirrormustbeavirtualLAGportthat
youadministrativelysetcalledastaticLAG.Onceconfigured,anIDSmirrorload‐sharestraffic
amongalldestinationportsintheLAGyousetastheportmirror.
Thesystemhashesthesourceportconversationbasedonsource
anddestinationIP(SIP/DIP)
addresspairsandsendsthesamepairsoutthesamephysicalportinthedestinationmirror. This
way,eachIDSdevicewillseealloftheconversationsbetween aDIP/SIPandwillnotduplicatethe
sameinformationoutmultipledestinationports.WhenIDSmirroringisenabled,the
system
performsaLayer3lookupforallframes.Allnon‐IPtraffic(includingcontrolframes)issenttoan
arbitrary,“designated”physicalout‐port.ThisportisincludedintheDIP/SIPhashlist.Ifthe
switchdetectsafailureofanyofthephysicalportsintheLAG,it
willautomaticallyredistribute
theDIP/SIPconversationsamongtheremainingportsinthe LAG.WithIDSmirroring,source
trafficisload‐sharedamongalldestinationportstoensurenopacketloss.
WhenconfiguringIDSmirroringonyourN‐SeriesDiamondorPlatinu m ,S‐Series,orK‐Series
device,youmusttakeinto
considerationthefollowing:
•OnlyoneIDSmirrorisallowedperchassis.
•Asofrelease5.xx.xx,mirroringofmultiple(unlimitednumberof)sourceportstoanIDS
destinationportissupported.
•TendestinationportsmustbereservedforanIDSmirror.
•AllDIP/SIPpairswillbetransmittedoutthesamephysicalport.
•Allnon‐
IPtrafficwillbemirroredoutthefirstphysicalportinaLAG.Thisportwillalsobe
usedforIPtraffic.
•PortfailureorlinkrecoveryinaLAGwillcauseanautomaticre‐distributionoftheDIP/SIP
conversations.
Referto“Example:ConfiguringanIDSMirror”onpage 14formore
information.
Note: This function is supported only on N-Series Platinum and Diamond, S-Series, and K-Series
switches.