Port Mirroring Profile

The Port Mirroring Profile allows administrators to mirror ingress, egress, or combined traffic on selected interfaces. The mirrored traffic is forwarded to a designated destination where it can be captured and analyzed for monitoring, security inspection, or troubleshooting purposes.

The destination can be directly connected to the same device or located remotely. A remote destination can be another device or client capable of receiving and decapsulating GRE-tunneled mirrored traffic, allowing traffic analysis even when the monitoring system is not physically connected to the source device.

Mirroring traffic enables:

  • Monitoring: For example, sending mirrored traffic to a firewall or intrusion detection system.

  • Troubleshooting: For example, directing mirrored traffic to a device performing packet capture.

Creating a Port Mirroring Profile

To create a Port Mirroring Profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, under Device Groups, select a device group.

  3. From the Device Function drop-down list, select one of the following switch device functions:

    • Access Switch

    • Aggregation Switch

    • Core Switch

  4. On the Interfaces card, click Port Mirroring Profile.
    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Port Mirroring Profile card, click Manage.

    The Port Mirroring Profile list view is displayed.

  5. Click Create Profile.
    The Create Profile side panel is displayed.

  6. Enter the Port Mirroring Profile parameters:

    • Name—Enter the name of the Port Mirroring Profile.

    • Description—Enter the description for the Port Mirroring Profile.

    • Enable Mirroring—Select the checkbox to enable port mirroring.

  7. Under Port Mirroring, select one of the following options:

    • Local—Mirrors traffic from one or more switch ports, LAGs, or VLANs to a designated switch port, LAG, or VLAN for monitoring and analysis. The destination must be a local interface or LAG directly connected to the switch.

    • Remote Switch—Mirrors traffic over a GRE tunnel when the destination device supports tunneling. The network terminates the GRE tunnel and forwards the unencapsulated traffic to the destination device for analysis.

    • Remote Client—Mirrors traffic to a destination that is not directly connected to the switch (for example, a VM on a different subnet). The switch encapsulates the mirrored traffic in a GRE tunnel so it can be sent over Layer 3 to the remote destination. At the destination, another device unencapsulates the GRE-tunneled traffic and captures and analyzes it.

    Note:

    If you select Remote Switch or Remote Client, additional tunnel configuration options are displayed, such as Source IP Address, Destination Switch, Destination IP Address, VRF, and UDP Port.

  8. Configure the Session ID by selecting the mirror session identifier from the drop-down list. Range: 1 to 4.

  9. Under Source, configure the following parameters:

    • Source Switch—Select the source switch from the drop-down list for the mirrored traffic.

    • Source IP Address— Specify the source IP address for the mirrored traffic. This parameter is required for remote mirroring sessions.

    • VRF—Select the VRF associated with the source IP address. This parameter is required for remote mirroring sessions. If the VRF is not selected, the default VRF will be applied.

    • Port—Select one or more source interface type from the following options and select the corresponding port, LAG, or VLAN from the drop-down list.

      • Port—Select an individual switch port.

      • LAG—Select a Link Aggregation Group.

      • VLAN— Select a VLAN interface.

    • Direction—Select the traffic direction to be mirrored from the following options:

      • Both—Mirrors traffic in both directions (receive and transmit).

      • Receive—Mirrors only inbound traffic received on the source interface.

      • Transmit—Mirrors only outbound traffic transmitted from the source interface.

  10. Under Destination, configure the parameters based on the selected mirror type:

    • Local

      • Port—Select an individual switch port.

      • LAG—Select a Link Aggregation Group.

    • Remote Switch

      • Destination Switch—Select the destination switch for the mirrored traffic.

      • Destination IP Address—Specify the destination IP address for the mirrored traffic.

      • VRF—Select the VRF associated with the destination IP address.

      • Port—Select the source interface type from the following options and select the corresponding port, LAG, or VLAN from the drop-down list.

        • Port—Select an individual switch port.

        • LAG—Select a Link Aggregation Group.

      • UDP Port—Specify the UDP port number used for encapsulating mirrored traffic.

    • Remote Client

      • Client IP Address—Specify the IP address of the remote client.

      • UDP Port—Specify the UDP port number used for encapsulating mirrored traffic.

  11. Click Create.

    The newly created profile is displayed in the Port Mirroring Profile list.

  12. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view.

      The Edit Profile view is displayed in the side panel.

    2. Edit the required parameters.

    3. Click Update.

  13. To delete a profile, hover on the profile name, and click the delete icon.

  14. To search for a profile, type the profile name in the search bar. The search bar displays dynamic results as soon as you start typing.

Sample Configurations

The following are the sample configurations that get applied to the switch:

Local - Port Mirroring

mirror session 1     comment LOCAL_mirror-localport_mirror_1     destination interface 1/1/3     source interface 1/1/1 both     enable

Remote Client - Port Mirroring

 Mirror Session: 1  Admin Status: enable  Operation Status: src_is_MTP_in_another_mirror_session  Comment: REMOTESWITCH_remote-client1_mirror_1 TW13KM0011_to_  Source: interface 1/1/11 both  Source: interface rx-filter none  Destination: tunnel 2.2.2.2 source 1.1.1.1 dscp 0 vrf default  Output Packets:  Output Bytes:

Remote Switch - Port Mirroring

 Mirror Session: 1  Admin Status: enable  Operation Status: enabled  Comment: REMOTESWITCH_remote-switch1_mirror_1 SG1ZKRS151_to_SG4ZLX7321  Source: vlan rx none  Source: vlan tx none  Source: interface 1/1/48 both  Destination: tunnel 2.2.2.2 source 1.1.1.1 dscp 0 vrf default  Output Packets: 68  Output Bytes: 12510