
B-57
Monitoring and Analyzing Switch Operation
Traffic Mirroring
Using a MAC Address as Mirroring Criteria
Use the
monitor mac mirror
command at the global configuration level to apply
a source and/or destination MAC address as the selection criteria used in a
local or remote mirroring session.
While ACL-based mirroring allows you to mirror traffic using an ACL to specify
IP addresses as selection criteria, MAC-based mirroring allows you monitor
switch traffic using a source and/or destination MAC address. You can apply
MAC-based mirroring in one or more mirroring sessions on the switch to
monitor:
■
Inbound traffic
■
Outbound traffic
■
Both inbound and outbound traffic
MAC-based mirroring is useful in ProCurve Network Immunity security solu-
tions that provide detection and response to malicious traffic at the network
edge. After isolating a malicious MAC address, a security administrator can
mirror all traffic sent to, and received from, the suspicious address for
troubleshooting and traffic analysis.
— Continued from Previous Page—
mirror < 1 - 4 | <
name-str
>
:
Assigns the traffic defined by the
interface to a session by number or (if configured) by name.
(The session must have been previously configured. Refer
to “3. Configure the Mirroring Session on the Source
Switch” on page B-46.) Depending on how many sessions
are already configured, you can use the same command to
assign the specified source to up to four numeric or
alphanumeric identifiers. For example,
1 2 test-
mirror
. For limits on configuring mirroring sources to a
given session, see “Mirroring Source Limits” on page B-49.
< 1 - 4 >
:
Assigns a numeric session identifier to
associate with the traffic selected for mirroring.
[ name < name-str >]:
Optional; uses a previously
configured alphanumeric identifier to associate the
traffic source with the mirroring session. The string
can be used interchangeably with the mirroring
session number when using this command to assign
a mirroring source to a session. To configure an
alphanumeric name for a mirroring session refer to
the command description under “Configuring a
Source Switch for a Mirroring Destination on a
Remote Switch” on page B-47.
3500-5400-6200-8200-MCG-Jan08-K_13_01.book Page 57 Monday, January 28, 2008 10:04 AM