Procedure
Mirroring Mode
|
Procedure
|
Port mirroring
|
- Run the system-view command to enter the system view.
- Run the interface interface-type interface-number command to enter the interface view.
- Run the port-mirroring to observe-port observe-port-index { both | inbound | outbound } command to copy the traffic received or sent by the mirrored port to a specified observing port.
|
VLAN mirroring
|
- Run the system-view command to enter the system view.
- Run the vlan vlan-id command to enter the VLAN view.
- Run the mirroring to observe-port observe-port-index inbound command to copy the traffic received by all active ports in the VLAN to a specified observing port.
|
MAC address mirroring
|
- Run the system-view command to enter the system view.
- Run the vlan vlan-id command to enter the VLAN view.
- Run the mac-mirroring mac-address to observe-port observe-port-index inbound command to copy the packets with a specified MAC address in the VLAN to a specified observing port.
|
Traffic mirroring
|
MQC-based traffic mirroring:
- Run the system-view command to enter the system view.
- Create a traffic classifier and specify the rules that mirrored traffic needs to match.
Run the traffic classifier classifier-name command to create a traffic classifier and enter the traffic classifier view.
Run the if-match command to configure matching rules in the traffic classifier.
You can configure multiple types of matching rules in a traffic classifier. For details, see "MQC Configuration - Configuring a Traffic Classifier" in the S12700 and S12700E V200R019C10 Configuration Guide - QoS Configuration.
Run the quit command to exit from the traffic classifier view.
- Create a traffic behavior and specify the action as traffic mirroring.
Run the traffic behavior behavior-name command to create a traffic behavior and enter the traffic behavior view.
Run the mirroring to observe-port observe-port-index command to copy the traffic that matches the traffic classifier to the specified observing port.
- Run the quit command to exit from the traffic behavior view.
- Create a traffic policy.
Run the traffic policy policy-name command to create a traffic policy and enter the traffic policy view.
Run the classifier classifier-name behavior behavior-name command to bind the traffic classifier configured in step 3 and traffic behavior configured in step 4 to the traffic policy.
- Run the quit command to exit from the traffic policy view.
Apply the traffic policy.
A traffic policy can be applied to the system, a VLAN, or an interface. For details, see "MQC Configuration - Applying the Traffic Policy" in the S12700 and S12700E V200R019C10 Configuration Guide - QoS Configuration. The traffic policy can be performed in multiple VLANs or interfaces to mirror specified traffic in multiple VLANs or interfaces to the same observing port.
Apply the traffic policy to the system.
Run the traffic-policy policy-name global { inbound | outbound } [ slot slot-id ] command to apply the traffic policy globally.
Apply the traffic policy in a VLAN.
Run the vlan vlan-id command to enter the VLAN view.
Run the traffic-policy policy-name { inbound | outbound } command to apply the traffic policy to the VLAN.
Apply the traffic policy to an interface.
Run the interface interface-type interface-number command to enter the interface view.
Run the traffic-policy policy-name { inbound | outbound } command to apply the traffic policy to the interface.
|
ACL-based traffic mirroring:
|
Verifying the Configuration
# Run the display port-mirroring command to view the mirroring configuration. The following is a sample command output.
<HUAWEI> display port-mirroring
----------------------------------------------------------------------
Observe-port 1 : GigabitEthernet1/0/1
Observe-port 2 : GigabitEthernet1/0/2
----------------------------------------------------------------------
Port-mirror:
----------------------------------------------------------------------
Mirror-port Direction Observe-port
----------------------------------------------------------------------
1 GigabitEthernet1/0/10 Inbound Observe-port 1
----------------------------------------------------------------------
Stream-mirror:
----------------------------------------------------------------------
Behavior Direction Observe-port
----------------------------------------------------------------------
1 b1 - Observe-port 2
----------------------------------------------------------------------