Use the commands in this section to configure port mirroring. The interface pair that serves as the mirror port must be configured in tap mode. The monitoring interface pair can be configured in inline mode (monitor or block mode) or tap mode. In inline block mode, all traffic is forwarded to the other analysis device.
For details about how to forward traffic from a mirror port, see the Network Security System Administration Guide.
Note
If the monitoring interface pair is configured in tap mode, the mirroring of SSL decrypted traffic cannot be enabled.
Prerequisites
Administrator or Operator access to the Network Security appliance
A minimum of two interface pairs on the Network Security appliance
Mirror port interface pair configured in tap mode
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
View the interface configuration settings.
hostname (config) # show policymgr interfaces
Specify the monitoring interface pair and the mirror port.
hostname (config) # policymgr interface <interfacePair> mirror port <portName>
where
<interfacePair>is the interface pair from which traffic will be forwarded, and<portName>is the port that will receive the mirrored traffic.Verify your changes.
In the following example, the "
Mirror Port:" line of the command output displays "pether9" to show that a mirror port is configured for Interface A.hostname (config) # show policymgr interfaces Policy enabled: yes Interface A Active : yes op mode : block (enforcing) fail-safe : close policy : mixed tolerance : 1 Ports : pether3 pether4 QinQ : no QinQ-evet : 0x88a8 Mirror: Non-SSL : no SSL : no Port : pether9 .........
Note
Use the
policymgr interface <interfacePair> mirror enablecommand if you want to enable port mirroring for all traffic types (including SSL encrypted traffic) on the monitoring interface. For details about how to enable port mirroring for all traffic types, see Adding or deleting port mirroring for all traffic using the CLI.Save your changes.
hostname (config) # write memory
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Clear the mirror port from an interface.
hostname (config) # policymgr interface <interfacePair> mirror clear
where
<interfacePair>is the interface pair from which traffic will be forwarded.Verify your changes.
In the following example, the "
Mirror Port:" line of the command output is cleared.hostname (config) # show policymgr interfaces Policy enabled: yes Interface A Active : yes op mode : block (enforcing) fail-safe : close policy : mixed tolerance : 1 Ports : pether3 pether4 QinQ : no QinQ-evet : 0x88a8 Mirror: Non-SSL : no SSL : no Port : .........