Port mirroring
Port mirroring allows us to copy and redirect packets to a destination monitoring device. This is useful for monitoring and analyzing specific traffic in use cases such as the following:
- Copy it to an advanced firewall (IPS/IDS) to inspect traffic
- For troubleshooting purposes, a copy of a traffic flow can be used
- Mirror traffic to a Wireshark packet capture program to analyze application or packet loss issues
Port mirroring configuration includes specifying the traffic to be monitored (referred to as the source) and determining the direction in which the traffic should be monitored–whether it’s the source, destination, or both.
Additionally, the configuration includes identifying the location to which the monitored traffic should be sent, which is typically a monitoring system. This system can be either remote or local.
There are different types of port mirroring sessions, which include Local Switch Port Analyzer (SPAN), Remote...