Configuring Port Mirroring
•
Configuring Port Mirroring to Analyze Traffic (CLI Procedure) on page 3555
•
Configuring Port Mirroring to Analyze Traffic (J-Web Procedure) on page 3558
Configuring Port Mirroring to Analyze Traffic (CLI Procedure)
EX Series switches allow you to configure port mirroring to send copies of packets to
either a local interface for local monitoring or to a VLAN for remote monitoring. You can
use port mirroring to copy these packets:
•
Packets entering or exiting a port
•
Packets entering a VLAN on EX2200, EX3200, EX4200, or EX4500 switches
•
Packets exiting a VLAN on EX8200 switches
We recommend that you disable port mirroring when you are not using it and select
specific input interfaces in preference to using the
all
keyword. You can also limit the
amount of mirrored traffic by using a firewall filter or the
ratio
keyword to mirror only a
selection of packets.
NOTE:
If you want to create additional analyzers without deleting the existing
analyzer, first disable the existing analyzer using the disable analyzer
analyzer-name
command or the J-Web configuration page for port mirroring.
NOTE:
Interfaces used as output for a port mirror analyzer must be configured
as family ethernet-switching.
•
Configuring Port Mirroring for Local Traffic Analysis on page 3555
•
Configuring Port Mirroring for Remote Traffic Analysis on page 3556
•
Filtering the Traffic Entering an Analyzer on page 3557
Configuring Port Mirroring for Local Traffic Analysis
To mirror interface traffic or VLAN traffic on the switch to an interface on the switch:
1.
Choose a name for the port mirroring configuration—in this case,
employee-monitor
—and specify the input—in this case, packets entering
ge-0/0/0
and
ge-0/0/1
:
[edit ethernet-switching-options]
user@switch#
set
analyzer
employee-monitor
input
ingress interface ge–0/0/0.0
[edit ethernet-switching-options]
user@switch#
set analyzer employee-monitor input ingress interface ge–0/0/1.0
2.
Optionally, you can specify a statistical sampling of the packets by setting a ratio:
3555
Copyright © 2010, Juniper Networks, Inc.
Chapter 127: Port Mirroring
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...