OcNOS-RON : System Management Guide : System Management Configuration Guide : Traffic Mirroring Configuration : Port Mirroring Configuration
Port Mirroring Configuration
This example shows detailed configuration of port mirroring.
 
#configure terminal
Enter configure mode.
(config)#bridge 1 protocol mstp
Configure bridge 1 as MSTP bridge.
(config)#vlan 101-110 bridge 1 state enable
Configure VLANs.
(config)#interface xe10
Enter interface mode.
(config-if)#switchport
Configure interface as a layer 2 port.
(config-if)#bridge-group 1
Associate bridge to an interface.
(config-if)#switchport mode trunk
Configure port as a trunk.
(config-if)#switchport trunk allowed vlan add 101-110
Allow VLANs 101-110 on the interface.
(config-if)#no shutdown
Make interface admin up.
(config-if)#exit
Exit interface mode.
(config)#interface xe20
Enter interface mode.
(config-if)#switchport
Configure interface as a layer 2 port.
(config-if)#bridge-group 1
Associate bridge to an interface.
(config-if)#switchport mode trunk
Configure port as a trunk.
(config-if)#switchport trunk allowed vlan add 101-110
Allow VLANs 101-110 on the interface.
(config-if)#no shutdown
Make interface admin up.
(config-if)#exit
Exit interface mode.
(config)#interface xe5
Enter interface mode.
(config-if)#switchport
Configure interface as a layer 2 port.
(config-if)#exit
Exit interface mode.
(config)#monitor session 1 type remote
Enter monitor session configuration mode.
(config-monitor)#destination remote vlan 100 reflector-port xe5
Configure the interface as remote destination port
(config-monitor)#source interface xe10 both
Configure the source interface to mirror ingress as well as egress direction traffic.
(config-monitor)#no shut
Activate monitor session.
(config-monitor)#end
Exit monitor session configuration mode.
Validation
Enter the commands below to confirm the configurations
#show running-config monitor
!
monitor session 1 type remote
source interface xe10 both
destination remote vlan 100 reflector-port xe5
no shut
 
 
#show monitor session all
session 1
---------------
type : remote
state : up
source intf :
tx : xe10
rx : xe10
both : xe10
source VLANs :
rx :
rspan VLAN : 100
reflector ports : xe5
filter count :
 
Legend: f = forwarding enabled, l = learning enabled
VLAN and Rule Based Mirroring Configuration
This example shows detailed configuration of VLAN with rule based mirroring.
 
#configure terminal
Enter configure mode.
(config)#bridge 1 protocol mstp
Configure bridge 1 as MSTP bridge.
(config)#vlan 101-110 bridge 1 state enable
Configure VLANs.
(config)#interface xe10
Enter interface mode.
(config-if)#switchport
Configure interface as a layer 2 port.
(config-if)#bridge-group 1
Associate bridge to an interface.
(config-if)#switchport mode trunk
Configure port as a trunk.
(config-if)#switchport trunk allowed vlan add 101-110
Allow VLANs 101-110 on the interface.
(config-if)#no shutdown
Make interface admin up.
(config-if)#exit
Exit interface mode.
(config)#interface xe20
Enter interface mode.
(config-if)#switchport
Configure interface as a layer 2 port.
(config-if)#bridge-group 1
Associate bridge to an interface.
(config-if)#switchport mode trunk
Configure port as a trunk.
(config-if)#switchport trunk allowed vlan add 101-110
Allow VLANs 101-110 on the interface.
(config-if)#no shutdown
Make interface admin up.
(config-if)#exit
Exit interface mode.
(config)#interface xe5
Enter interface mode.
(config-if)#switchport
Configure interface as a layer 2 port.
(config-if)#exit
Exit interface mode.
(config)#monitor session 1 type remote
Enter monitor session configuration mode.
(config-monitor)#destination remote vlan 100 reflector-port xe5
Configure the interface as remote destination port.
(config-monitor)#source vlan 101
Configure source VLAN to be mirrored.
(config-monitor)#filter src-mac host 0000.0000.0005
Configure the rule to match the source MAC.
(config-monitor)#no shut
Activate monitor session.
(config-monitor)#end
Exit monitor session configuration mode.
Validation
Enter the commands below to confirm the configuration.
#show running-config monitor
!
monitor session 1 type remote
source vlan 101
destination remote vlan 100 reflector-port xe5
10 filter src-mac host 0000.0000.0005
no shut
 
 
#show monitor session all
session 1
---------------
type : remote
state : up
source intf :
tx :
rx :
both :
source VLANs :
rx : 101
rspan VLAN : 100
reflector ports : xe5
filter count : 1
 
Legend: f = forwarding enabled, l = learning enabled
 
 
#show monitor session 1 filter
session 1
---------------
filter count : 1
 
---------------
match set 1
---------------
source mac address : 0000.0000.0005 (host)
 
 
Last modified date: 08/28/2023