Use the commands in this section to add or delete port mirroring for all traffic types (including SSL traffic) on a Network Security monitoring interface pair.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable port mirroring for all traffic types (including SSL traffic) on the monitoring interface.
hostname (config) # policymgr interface <interfacePair> mirror enable
where
<interfacePair>is the interface pair from which traffic will be forwarded.Save your changes.
hostname (config) # write memory
Verify the status of port mirroring for all traffic types.
hostname (config) # show policymgr interfaces Policy enabled: yes Interface A Active : yes op mode : block (enforcing) fail-safe : close policy : mixed tolerance : 1 Ports : pether3 pether4 QinQ : no QinQ-evet : 0x88a8 Mirror: Non-SSL : yes SSL : no Port : pether9 ........
The "Mirror Non-SSL" line displays "yes" if port mirroring is added for all traffic types.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Disable port mirroring for all traffic types (including SSL traffic).
hostname (config) # no policymgr interface <interfacePair> mirror enable
where
<interfacePair>is the monitoring interface pair that is forwarding traffic.Delete the mirror port from an interface.
hostname (config) # policymgr interface <interfacePair> mirror clear
where
<interfacePair>is the monitoring interface pair.Save your changes.
hostname (config) # write memory
Verify the status of port mirroring for all traffic types.
hostname (config) # show policymgr interfaces Policy enabled: yes Interface A Active : yes op mode : block (enforcing) fail-safe : close policy : mixed tolerance : 1 Ports : pether3 pether4 QinQ : no QinQ-evet : 0x88a8 Mirror: Non-SSL : no SSL : no Port : ........
The "Mirror Non-SSL" line displays "no" if port mirroring is deleted for all traffic types. The mirror port is also removed from the interface.