
B-53
Monitoring and Analyzing Switch Operation
Traffic Mirroring
Using ACL Assignment and Traffic Direction
To Select the Traffic To Mirror from a Source Switch
Use the commands in this section to apply ACL criteria for either local or
remote mirroring.
ACL Operation for Mirroring Applications.
Using the ACL (Access Con-
trol List) mirroring option requires configuration of an ACL. For ACL config-
uration and operating details, refer to the chapter titled “Access Control Lists
(ACLs)” in the latest
Access Security Guide
for your switch.
ACLs used for selecting traffic to mirror are configured in the same way as
ACLs for traffic filtering. This means that an ACL applied as a static port ACL,
VLAN ACL (VACL), or routed ACL (RACL) can be applied to mirroring. (An
ACL used for mirroring does not filter traffic.)
When an ACL is applied to mirroring, the
permit
and
deny
statements in the
ACL take on a different role than in ACL traffic filtering. That is, a packet
matching a
permit
statement will be mirrored, and a packet matching a
deny
statement (including the explicit
deny
at the end of every ACL) will not be
mirrored. Any
log
keywords in ACL deny statements are ignored by the
mirroring function. If both a mirrored ACL and a statically-configured ACL are
applied to the same interface, and a packet matches a
permit
statement in the
mirrored ACL and a
deny
statement in statically-configured ACL, the packet
will be mirrored and dropped. Note that each mirrored ACL applied to an
interface uses shared switch resources. The rules applicable for adding,
removing, replacing, or modifying a traffic-filtering ACL also apply to an ACL
used for mirroring.
— Continued from Preceding Page—
[ name < name-str >]:
Optional; uses a previously
configured alphanumeric identifier to associate the
traffic source with the mirroring session. The string
can be used interchangeably with the mirroring
session number when using this command to assign
a mirroring source to a session. To configure an
alphanumeric name for a mirroring session refer to
the command description under “Configuring a
Source Switch for a Mirroring Destination on a
Remote Switch” on page B-47.
3500-5400-6200-8200-MCG-Jan08-K_13_01.book Page 53 Monday, January 28, 2008 10:04 AM