
B-30
Monitoring and Analyzing Switch Operation
Traffic Mirroring
■
MAC addresses:
Enables mirroring on traffic selected according to a
specified source and/or destination MAC address in packet headers.
Criteria for Selecting Traffic To Mirror
On the traffic sources listed above, you can use the following criteria to select
traffic to mirror:
■
direction of traffic movement (entering or leaving the switch, or both)
■
type of IP traffic entering the switch, as defined by an ACL (Access Control
List)
■
source, destination, or both source and destination MAC addresses in
packet headers
Mirrored Traffic Operation and Options
Switches running software release K.12.xx or greater support the following:
■
four mirroring destinations configured to correspond to local mirroring
source sessions
■
32 mirroring destinations configured to correspond to remote mirroring
source sessions
■
four local or remote mirroring source sessions
Mirroring Sessions
A mirroring source can be a port or static-trunk list, mesh, VLAN, or MAC
address. A mirroring source and a mirroring destination comprise a given
mirroring session. For any session, the destination must be a single (exit) port.
(It cannot be a trunk, VLAN, or mesh.) Multiple mirroring sessions can be
mapped to the same exit port, which provides flexibility in distributing hosts
such as traffic analyzers or an IDS. On the mirroring destination switch, the
port through which the mirrored traffic for a given session enters the switch
and the exit port for that same session must belong to the same VLAN. (Refer
to “2. Configure the Remote Mirroring Session on Destination Switch” on page
B-44.)
Each of the four mirroring sessions supported at a mirroring source can have
either the same or a different destination. Destination options include an exit
port on the source (local) switch and/or on one remote ProCurve switch
configured to support remote mirroring. This offers the following benefits:
■
Mirrored traffic belonging to each session can be directed to the same
destination or to different destinations.
3500-5400-6200-8200-MCG-Jan08-K_13_01.book Page 30 Monday, January 28, 2008 10:04 AM