VPC Traffic Mirroring, as the name implies, allows you to duplicate network traffic from elastic network interfaces (ENIs) attached to instances, so that the duplicated traffic can then be sent to third-party tools and services for traffic analysis and inspection.Â
When configured, the duplicated traffic is sent to a target; this could be a network load balancer, using UDP as a listener, that sits in front of a fleet of appliances dedicated to network analysis. Alternatively, you could simply use another EC2 instance as a target, pointing it to the ENIÂ of the instance. If required, these targets could also be in a different VPC for additional management.
Traffic Mirroring is a great addition to Flow Logs, as it provides a deeper investigative insight into network traffic. This helps you dissect packets more effectively, leading to a quicker root-cause analysis for both performance issues and security incidents. Reverse-engineering how a security threat...