Specifications
Configuring Port Mirrors
May 04, 2011 Page 6 of 15
VLAN Mirrors
CreatingaVLANandsettingamirrorfortheVLANallowsyoutomonitoralltraffictoyour
specifiedVLANinterface.Forexample,youcouldtrackalldatatravelinginandoutofa
confidentialgroupofworkstations,suchasaFinanceVLAN,byanalyzingonlyoneconnection
point.Considerationswhen
configuringVLANmirrorsinclude:
•Aone‐to‐manyormany‐to‐oneVLANmirrorisconsideredasingledestinationport.
•Many‐to‐onemappingallowsmultipleVLANstobesenttoonespecificdestina tion port.
• Oversubscribedtrafficwillbedropped.
Avoiding Bottlenecks
Itisespecia llyimportanttonotoversubscribeportsinamirroringconfigurationbecausethiscan
causebottlenecksandwillresultindiscardedtraffic.
If,forexample,thereare10usersinVLAN1,eachattachedtoa10Mbpsport,whenyoumirrored
VLAN1toanother10Mbpsportto
whichyoursnifferisattached,theprobeswitchwould
probablyhavetodroppacketsatthedestinationport.Sinceyourpurposeinconfiguring
mirroringistoseeallofthetrafficforVLAN1,itwouldbebetterinthisscenariotoattachthe
sniffertoa100Mbpsport.
Configuring Port Mirrors
Asstatedpreviously,porttypesandnumbersofportsyoucanconfigureforportmirroring
dependonwhatfeaturesandfunctionsyourEnterasysdevicessupport.ReferbacktoTable 1fora
listofsupportandcapacityforeachdevice.
Thissectionprovidesinstruct ions forconfiguringthefollowingswitchproducts:
• N‐Series,
S‐Series,K‐Series(page6)
• X‐Series(page8)
• Stackableand StandaloneSwitches(page10)
N-Series, S-Series, K-Series
PortmirroringconfigurationsupportdiffersslightlybetweendevicetypesintheN‐Series
platform.GoldDFEssupportmirroringofphysicalportsandvirtualports,includingLAGports.
Inadditiontotheseporttypes,DiamondandPlatinumN‐SeriesDFEs,S‐SeriesanK‐Seriesalso
supportmirroringonVLANinterfaces,and
IDSportscreatedaspartofaLAG.Alldevicesallow
youtomirrorreceiveddata,transmitteddata,orboth.
Note: This function is supported only on N-Series, S-Series, and K-Series devices.
Note: When a port mirror is created, It is automatically enabled on all platforms.