The port mirror in cisco is easy as a piece of cake :)
What you have to do is to check whether the port mirroring is supported in your type of switch or not
What you have to do is to check whether the port mirroring is supported in your type of switch or not
Solution 1:
Monitoring the Interface:
Configure a mirror on port 2 like this.
ABC_Switch(config)# monitor session 1 source interface Fa0/2 both
ABC_Switch(config)# monitor session 1 destination interface Fa0/9
ABC_Switch(config)# monitor session 1 destination interface Fa0/9
both refers to in and out.
Cisco also allows you to specify multiple sources to a single port or a single source to multiple destinations.
ABC_Switch(config)# monitor session 2 source interface Fa0/2 both
ABC_Switch(config)# monitor session 2 destination interface Fa0/11
ABC_Switch(config)# monitor session 2 destination interface Fa0/12
ABC_Switch(config)# monitor session 2 destination interface Fa0/11
ABC_Switch(config)# monitor session 2 destination interface Fa0/12
Monitoring the Vlan:
Cisco switches also allows you to create a vlan mirror that extracts traffic from the entire vlan or vlans and sends it to a destination port for monitoring.
ABC_Switch(config)# monitor session 1 source vlan 12 rx
ABC_Switch(config)# monitor session 1 destination interface Gi1/1
ABC_Switch(config)# monitor session 1 destination interface Gi1/1
Specifying both in the source command would create duplicate packets as packets go in and out of the vlan, so only specify receive or transmit with the tx or rx
Commands to Remember:
ABC_Switch>show monitor
Mirrors can be disabled two ways:
Disabling the monitor session:
ABC_Switch(config)# no monitor session 1
This command will only remove session 1.
ABC_Switch(config)# no monitor
The no monitor command will remove all monitors on the switch.
Solution 2:
ABC_Switch> enable
ABC_Switch# configure terminal
ABC_Switch(config)#
Choose which interface you want your traffic mirrored to. Remember in case of vlan mirroring the interface must be in the same vlan.
e.g if we want to mirror the traffic to the destination fa 0/19
ABC_Switch(config)#int fa0/19
For mirroring the interface:
ABC_Switch(config-if)#port monitor fa0/2
For mirroring the multiple interfaces:
ABC_Switch(config-if)#port monitor fa0/2
ABC_Switch(config-if)#port monitor fa0/3
ABC_Switch(config-if)#port monitor fa0/4
For mirroring the Vlan:
ABC_Switch(config-if)#port monitor Vlan80
* In all cases do remember to save the configurations.
ABC_Switch# wr
Type "wr" to save your current running configuration as your startup config so you don't lose all your changes made after a reboot.