The Network Security appliance supports two types of port mirroring—port mirroring for all traffic types (including SSL encrypted traffic) and SSL decryption mirroring. In both types of port mirroring, the Network Security monitoring interface pair mirrors the traffic to a mirror port, and the mirror port forwards a copy of the traffic to another analysis device. You configure and enable each feature separately.
Port mirroring for all traffic
The port mirroring for traffic feature allows the Network Security appliance to mirror the traffic that has been seen on the appliance to a third-party device through a TAP or SPAN port. You can configure the Network Security monitoring interface pair to forward a copy of the network traffic it processes to another port on the same appliance that is configured as a dedicated SPAN (or mirror) port. The mirror port is connected to another analysis device, which receives the traffic from the Network Security mirror port to perform further analysis. The feature is disabled by default and must be configured and enabled.
For details about how to forward traffic from a mirror port, see “Configuring the to Forward Traffic from a Mirror Port” in the Network Security System Administration Guide.
SSL decryption mirroring
Note
The SSL decryption mirroring feature is supported on the Classic product edition of the NX 2500, NX 2550, NX 3500, NX 4500, NX 5500, and NX 6500 models.
The SSL decryption mirroring feature allows the Network Security monitoring interface pair to forward a copy of the decrypted HTTPS traffic it processes to another port on the same appliance that is configured as a mirror port. The mirror port is connected to a trusted external device or raw packet capture tool, which receives the traffic from the Network Security mirror port to perform further inspection or analysis. If you want the appliance to mirror or track SSL decrypted traffic to an external device, you must enable SSL interception on a network port pair. For details about how enable SSL interception, see Enabling or disabling SSL Interception. You can benefit from using SSL decryption mirroring for deeper analysis about the involved threats and data capture for further forensic analysis. The feature is disabled by default and must be configured and enabled.
Note
If an interface pair is configured in tap mode, the mirroring of SSL decrypted traffic cannot be enabled.
Task list for managing port mirroring options
Complete the steps for managing port mirroring options in the following order:
Configure a minimum of two interface pairs on the Network Security appliance.
Configure one interface pair as the monitoring port pair and the other as the mirror port. For details about how to configure the mirror port on an interface, see Configuring the Network Security appliance to forward traffic to a mirror port using the CLI.
Verify that the monitoring interface pair is configured in inline mode (monitor or block mode) for SSL decryption mirroring and the mirror port is in tap mode by using the
show policymgr interfacescommand. For details about how to configure inline operational modes, see Configuring inline operational modes.Add port mirroring for all traffic types (including SSL encrypted traffic) to the monitoring interface pair. For details, see Adding or deleting port mirroring for all traffic using the Web UI or Adding or deleting port mirroring for all traffic using the CLI.
Add mirroring of SSL decrypted traffic to at least one monitoring interface pair. For details about how to add mirroring of SSL decrypted traffic, see Adding or deleting SSL decryption mirroring using the Web UI or Adding or deleting SSL decryption mirroring using the CLI.